🇺🇦 #NowPlaying on KEXP's #Roadhouse
Melissa Carper:
🎵 Hit or Miss
#MelissaCarper
https://melissacarper.bandcamp.com/track/hit-or-miss
https://open.spotify.com/track/4NBFOjDwZFntQgLBWIRLEY
GitHub confirms breach of 3,800 repos via malicious VSCode extension
https://www.bleepingcomputer.com/news/security/github-confirms-breach-of-3-800-repos-via-malicious-vscode-extension/
Two teeny-tiny Seagull hatchlings were walking around on the road in front of where I live. Far too young to have left the nest, so perhaps the nest has been disrupted and they have fallen out? I was shooing them away from the traffic and you should have seen the malicious looks the ugly middle-aged men in their "hickmobiles" (extra giant SUVs) were giving me, for being IN THEIR WAY.
Do not romanticise "rural". The people are monstrous outside of cities, they are sti…
Siri (Beta) is really interesting.
On one hand, I don't have to trust any new parties with my data. Apple already has it since they have my mobile devices, so if they were going to maliciously steal (e.g.) my email contents, they could already do that. This opens the door to a whole bunch of LLM data based interrogation that I wouldn't trust with other providers.
…on the other hand, the "on-device only" Siri falls over immediately when disabling the internet c…
RE: https://cyberplace.social/@GossiTheDog/116811143622632586
More like this.
I am not a pacifist. Malicious hackers working for state actors have abdicated their right to peace and safety.
packet_delays: Internet packet delays (2002)
A network representing the difference in delay observed by packet probes sent from a computer at Rice University to similar machines at different universities, in c.2002. The edge weight denotes the difference in delay of the packet in milliseconds.
This network has 10 nodes and 9567 edges.
Tags: Technological, Communication, Weighted
GitHub has confirmed that around 3,800 internal repositories were breached after one of its employees installed a malicious VS Code extension: https://www.bleepingcomputer.com/news/security/github-confirms-breach-of-3-800-repos-v…
IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests
Ankur Singh, Jinqiu Yang, Tse-Hsun Chen
https://arxiv.org/abs/2607.20759 https://arxiv.org/pdf/2607.20759 https://arxiv.org/html/2607.20759
arXiv:2607.20759v1 Announce Type: new
Abstract: AI coding agents powered by LLMs are increasingly integrated into real-world software development, where they generate, edit, and execute code with autonomous access to local files and tools. Coding agents inherit security risks from both the LLM backbone, where adversarial prompts, poisoned training data, and backdoor triggers can cause models to emit insecure or attacker-chosen code, and their agentic architecture, where tool-using autonomy enables induced misuse of external APIs, data exfiltration, and persistent compromise of development environments. This paper presents a systematic evaluation of malicious issue requests against state-of-the-art coding agents (Cursor, Claude Code, and Codex Desktop), powered by two major model families (OpenAI GPT-5.3 Codex/GPT-5.4 and Anthropic Sonnet 4.6). Our novel benchmark IssueTrojanBench contains malicious issues that are constructed based on four novel attack categories (i.e., embedded as malicious instructions in issues), six delivery vectors (e.g., PDF, or issue comment), and further augmented by perturbations. Our results reveal critical vulnerabilities in the as-deployed modern coding agents, i.e., 66.5% of the malicious issues from IssueTrojanBench penetrate all the guardrails (agent- and LLM-level) of coding agents. Our further analysis shows that rejection is almost entirely from LLMs rather than the agent frameworks, with GPT models broadly vulnerable and Sonnet 4.6 exhibiting more selective, risk-aware blocking of high-impact actions. Our evaluation also highlights that the current agent-level defense strategy offers limited additional protection for coding agents. Our findings highlight the urgent need for stronger agent- and model-level safety mechanisms to protect AI coding agents.
toXiv_bot_toot
🇺🇦 #NowPlaying on KEXP's #VarietyMix
Laura Groves:
🎵 Any Day Now
#LauraGroves
https://lauragroves.bandcamp.com/track/any-day-now
https://open.spotify.com/track/1y6kvoqmlAjwjc7xIgQVpJ
packet_delays: Internet packet delays (2002)
A network representing the difference in delay observed by packet probes sent from a computer at Rice University to similar machines at different universities, in c.2002. The edge weight denotes the difference in delay of the packet in milliseconds.
This network has 10 nodes and 9567 edges.
Tags: Technological, Communication, Weighted