2026-06-02 00:26:37
A suspected North Korean hacker has hijacked and modified a popular open source software development tool
to deliver malware that could put millions of developers at risk of being compromised.
On Monday, a hacker pushed malicious versions of the widely used JavaScript library called Axios,
which developers rely on to allow their software to connect to the internet.
The affected library was hosted on npm, a software repository that stores code for open source projects…
So Anthropic employees are using Claude Code to contribute AI-generated code to open source repositories and hiding the fact using their own internal “undercover mode”.
Totally trustworthy people.
(Any open source project that at the very least requires disclosure of AI-authored contributions should immediately ban Anthropic employees on principle.)
#AI
"H&M Foundation launches open-source toolkit to cut textiles emissions"
#Clothes #Fashion #Emissions
Chinese AI developer MiniMax launches M3, a new coding model that it says rivals Opus 4.7, costing $0.12 per 1M input tokens, compared with $5 for Opus 4.7 (Juro Osawa/The Information)
https://www.theinformation.com/briefings/chin…
Claude Code source leak reveals how much info Anthropic can hoover up about you and your system
"Anthropic's Claude Code lacks the persistent kernel access of a rootkit. But an analysis of its code shows that the agent can exercise far more control over people's computers than even the most clear-eyed reader of contractual terms might suspect. It retains lots of your data and is even willing to hide its authorship from open-source projects that reject AI."
Google Threat Intelligence Group (GTIG) has linked the recent axios NPM supply chain attack to a suspected North Korean threat actor, UNC1069 (and not TeamPCP).
https://techcrunch.com/2026/03/31/hacker-hijacks-axios-open-source-proj…
It feels obvious that llm's have no place in free and open source software. Apparently it isn't, at least not to everyone. I recently became interested in exploring the scope of the problem after finding out that both Vim and Neovim not only don't have policies banning llm contribution, but already contain fairly significant amounts of llm generated code.
What is the maximum amount of value destruction that could be wrought on the big centralized commercial AI vendors, and the maximum amount of acceleration of the ecosystem of open source and community-led
alternatives, using the knowledge gained from the leak of the Claude Code source code?
“they stole my apes, Odo” — Still relevant
“I SEEM TO RECALL YOU TAKING GREAT GLEE IN EXPLAINING THAT CENTRALISED PLATFORMS WERE OBSOLETE THANKS TO NFT'S.”
“WELL-”
“BUT NOW YOU WANT THE AUTHORITIES HELP IN POLICING THE SALE OF THESE…THINGS.”
https://mastodon.social/@Wraithe/11159
SCOTUS hears birthright citizenship arguments
https://open.substack.com/pub/anntelnaes/p/scotus-hears-birthright-citizenship?utm_source=direct&utm_campaign=post-expanded-sha…
Boosted in Reddit: <https://www.reddit.com/r/freebsd/comments/1tu5ezw/open_source_organisations_weigh_in_on_age/>
– and BSD Cafe Billboard <
I knew it was this way but it's really hitting me today how much the Open Source movement and copyright maximalism supplanted the idea of free software, and again how much the Free Software movement turned from a close ideological cousin of the remix and open culture movement into a culture of legalism. At the same time, copyright law itself has been extended to be near-immortal copyrights rather than brief monopolies to spur creation by enabling profit from creating works.
Google attributes the supply chain attack on HTTP client Axios to a suspected North Korean threat actor it calls UNC1069 (Lorenzo Franceschi-Bicchierai/TechCrunch)
https://techcrunch.com/2026/03/31/hacker-hijacks-axios-open-source-…
"Using Open Source Tools to Capture Closed Captions and Timecode": guest post by Morgan Morel of the National Audio-Visual Conservation Center at the Library of Congress @ the LoC's blog "The Signal"
https://blogs.loc.gov/thesignal/2026/03/…
Anthropic, I’ll make you a deal:
Re-train your model without a single line of my open source contributions as input, and I will gladly refrain from ever copying or sharing the code •you• generated by (in part) using •mine•.
And here is a first try on the snippet for open vs. closed source. Honestly, it doesn't look as good, as the first one. Maybe because, the flag colors are missing?
Any other ideas?
https://fingolas.eu/OpenClosed/
Keep hearing about NAM in the guitar modelling world. This seems like an interesting development. Who doesn't love #FOSS #GuitarModeling taking the top spot?
#guitar
Open source isn’t free. We’re just not paying for it: Who maintains the maintainers?
A lot of things don’t add up in the world of software. The skills gap remains stubbornly wide, with IT and data skills the hardest to recruit for five consecutive years. Yet, at the same time, entry level roles are declining as employers redeploy existing employees rather than hiring new ones.
🧑💻
Something for the US #TTRPG bubble:
https://open.substack.com/pub/exeuntpress/p/im-teaching-free-game-design-cl…
"Something happened a month ago, and the world switched. Now we have real reports." It's not just Linux, he continued. "All open source projects have real reports that are made with AI, but they're good, and they're real."
https://www.theregister.com/2026/03/26/gre…
Zwischen Markt und Regulierung: Streit um Open Access
Open Access ist Konsens im Glasfasermarkt. Aber wie weit reicht die Pflicht zur Netzöffnung? Da gehen die Meinungen auseinander.
https://www.
Bitte petition unterzeichnen und teilen.
Erhaltet den open #basketball court am Rütlicampus in #Neukölln #Berlin
Why Hardened Images are Suddenly Everywhere
#docker
We casually crack open million-year-old fossils but stress about opening a bag of chips at a party.
Why?
Because we bet future tech won't learn more than we can right now. We bet progress slows from here.
But with AI, we bet the opposite. We bet it speeds up AND slows down at the same time.
Which eternity do we actually value? Our own or everyone's?
Read more
Several years ago, a street medic described a system like this and wanted to know if it could be built.
https://hackaday.com/2022/09/08/the-tak-ecosystem-military-coordination-goes-open-source/
Back then there was just no way to make it happen. Hardware was too expensive. We couldn't really ever get it cheap enough, per medic, to deploy. Best I could put together was a bunch of burner phones.
But now it's starting to really make sense. LoRa is cheap, and possibly cheaper in bulk. And it wouldn't be necessary to build everything since ATAK-CIV exists and has several open source implementations. It can even tie in to drones (which are illegal to bring to protests in at least a few states).
This has a lot of potential applications for street medic coordination, protest marshal coordination, and for airsoft teams...
A whistleblower alleges Delve pitched a modified copy of open-source no-code tool SimStudio as its own, a practice that could violate the software's license (Julie Bort/TechCrunch)
https://techcrunch.com/2026/04/01/the-reputation-of-tr…
L'industria europea dell'open source è pronta. La domanda è: lo è l'Europa? 🇪🇺
@…
🕝 In meno di 48 ore, la Commissione europea dovrebbe pubblicare il Pacchetto per la SovranitŠ Tecnologica dell'UE - un momento chiave per il futuro digitale dell'Europa.
Quello che è iniziato con 15 CEO che si impegnavano direttamente…
Off the coast of California, dozens of marine protected areas have been established in recent decades.
These patches of the open ocean either prohibit or tightly restrict commercial and recreational fishing.
Off the coast of Santa Barbara, we set sail with members of the environmental group Santa Barbara Channelkeeper to learn about what's being done to protect our marine habitat.
LocalSend allows you to "AirDrop" files between any two devices on the same Wi-Fi network. It supports most real operating systems (i.e. Linux/Android), plus Windows, macOS, and iOS. (Sorry to BSD users, but I'm sure you can just UUCP the file or something.) https://localsend.org/
So Openvibe decided to go paid without any prior warning (at least none I got) so I'll say again, that proprietary software really is inferior to open source software and this was the last time I give a dev team the benefit of the doubt.
Taking money for your software is okay with me, I'm just annoyed by how they handled it.
Gonna swap to Flare ✌🏻
On my first time mentoring #WordPress Credits students, the hardest part wasn't technical! I wrote about this wonderful experience. 🎓
https://josvelasco.com/heres-what-ive-…
Microsoft releases ASSERT, an open-source framework that lets developers generate and run AI behavior tests using natural-language descriptions (Ram Iyer/TechCrunch)
https://techcrunch.com/2026/06/02/new-microsoft-tool-lets-de…
it's always "supply chain attack" and never "companies too cheap to officially adopt an open source library”
Ich verstehe das Fediverse als ein Open Source Projekt, an dem alle im Rahmen ihrer Möglichkeiten teilhaben und in dem Sinne auch weiterentwickeln können. Man kann Dinge neu machen, man kann Dinge kopieren und man kann sie anders machen, man kann anderen Leuten Geld geben, damit sie Dinge machen können, die man selber nicht machen kann. Alles in allem kann man hier sehr viel aus eigener Kraft für die eigenen Wünsche erreichen. Man kann das egoistisch oder gemeinschaftlich machen.
Something for the US #TTRPG bubble:
https://open.substack.com/pub/exeuntpress/p/im-teaching-free-game-design-cl…
RE: https://dice.camp/@realms/116459545804565917
I'd argue that "AI"-based development creates a bigger attack surface on closed source/proprietary software than open source software:
1. It's more likely that internal software development uses LLMs as they're most affordable to companies; leaving them more vulnerable to prompt injection and other types of attacks targeting LLM use.
2. It's more likely that internal commits aren't vetted as much (or even purely vibe-coded) as ones in open source projects.
3. It's more likely that attacks on open source projects are discovered quicker.
Also a reminder that the "Mythos" thing—like all the other doomerist things coming out of "AI" companies—is a marketing stunt to get Anthropic free press coverage.
The Internet Was Weeks Away From Disaster and No One Knew
https://youtube.com/watch?v=aoag03mSuXQ
This is a superb dive into the XZ hack, the history of open source, the challenges of relying on volunteers, encryption, and a bunch more. An hour absolutely worth your time.
This tangled.org GitHub alternative built on top of ATproto, open source, with self hosting capabilities and the ability to run your own CI sure seems like a gift of the gods.
2026 On Track for Warmest Year
https://open.substack.com/pub/jimehansen/p/2026-on-track-for-warmest-year?utm_source=share&utm_medium=android&r=e4myx
> James Hansen
2026 ist ein spannendes Jubiläumsjahr für mich.
40 Jahre Führerschein
30 Jahre Linux
30 Jahre Engagement für Open-Source-Software
25 Jahre rauchfrei
Several years ago, a street medic described a system like this and wanted to know if it could be built.
https://hackaday.com/2022/09/08/the-tak-ecosystem-military-coordination-goes-open-source/
Back then there was just no way to make it happen. Hardware was too expensive. We couldn't really ever get it cheap enough, per medic, to deploy. Best I could put together was a bunch of burner phones.
But now it's starting to really make sense. LoRa is cheap, and possibly cheaper in bulk. And it wouldn't be necessary to build everything since ATAK-CIV exists and has several open source implementations. It can even tie in to drones (which are illegal to bring to protests in at least a few states).
This has a lot of potential applications for street medic coordination, protest marshal coordination, and for airsoft teams...
#EchoSight: an open-source mobile application and framework for real-time visual-audio sensory substitution https://eppro02.ativ.me/web/page.php?n
Y2K38 kommt. Milliarden Systeme sind betroffen.
Open Source wird kritisiert – dabei entstehen die Lösungen oft genau dort.
Das Problem ist nicht der Code.
Das Problem ist, wie wir damit umgehen.
👉 Wer zahlt am Ende die Rechnung?
https://y2k38.ch/y2k38-open-source-suende…
This is how open my tech is:
OS PC/Laptop: ⛓️💥 🔒
OS Smartphone: 🔒
Browser: ⛓️💥
Messaging: ⛓️💥 🔒
E-Mail: 🔒
Microblogging: ⛓️💥 ⛓️💥 ⛓️💥
Office Software: ⛓️💥
Cloud: ⛓️💥
Open Source: 67%
⛓️💥⛓️💥⛓️💥⛓️💥⛓️💥⛓️💥⛓️💥🔒🔒🔒
Created @ fingolas.eu/OpenClosed
Open Source in der Verwaltung rechtlich gestärkt
https://www.linux-magazin.de/news/open-source-in-der-verwaltung-rechtlich-gestaerkt/
"Software-Beschaffung für öffentliche Verwaltungsbehörden sind durch die EVB-IT geregelt. Dank aktu…
from my link log —
Gecko: a fast GLR parser with automatic syntax error recovery.
https://vnmakarov.github.io/parsing/compilers/c/open-source/2026/04/22/gecko-glr.html
saved 2026-04-23
Den Windows-Klassiker Notepad gibts jetzt auch nativ für macOS. Ein Community-Fork ohne Wine, Crossover, etc.
#notepadplusplus
I just published The Open Contributions Descriptor format as an IETF Internet-Draft.
#opensource #opendata #openstandard
RE: https://mastodon.social/@Edent/116499146658427751
The idea of closing currently-open-source software "for security reasons" makes no sense whatsoever; at best, it's closing the barn door after the animals have all left. At worst, it prevents accessibilit…
I like to think this is due to the single email I sent to my state representative.
https://ostechnix.com/colorado-california-age-verification-law-open-source-exempt/
Keine Alterskontrolle für Linux
Gesetze, die eine Altersverifikation in Betriebssystemen vorsehen, nehmen zumindest in Kalifornien und Colorado wohl Open-Source aus.
https://www.heise.de/news/Keine-Alterskont…
An interesting juxtaposition of 2 articles in Apple News. One’s about the dev who added code to an open source app he’d developed, that would delete code in an app that was vibe coded. He’s getting death threats.
Other one’s about a guy suing an employer for not accommodating his phobia of rainbow flags and “trans pronouns” (sic). He claimed to be a devout Catholic and feared all those “gay” symbols were a threat to his soul.
Wie informieren Solawis ihre Mitglieder digital über den Inhalt und die Verwendung des Ernteanteils?
Wie können Ernteteilende ihren Anteil online anpassen oder pausieren?
Wir stellen beim Online-Stammtisch im Juni Open Source Web-Apps vor, die Solawis nutzen können.
🗓️ 17.06., 19:30 Uhr | ohne Anmeldung
Replaced article(s) found for cs.CL. https://arxiv.org/list/cs.CL/new
[3/5]:
- Can Small Language Models Handle Context-Summarized Multi-Turn Customer-Service QA? A Synthetic D...
Lakshan Cooray, Deshan Sumanathilaka, Pattigadapa Venkatesh Raju
https://arxiv.org/abs/2602.00665 https://mastoxiv.page/@arXiv_csCL_bot/116006686092324902
- SEAD: Self-Evolving Agent for Multi-Turn Service Dialogue
Dai, Gao, Zhang, Wang, Luo, Wang, Wang, Wu, Wang
https://arxiv.org/abs/2602.03548
- OmniRAG-Agent: Agentic Omnimodal Reasoning for Low-Resource Long Audio-Video Question Answering
Yifan Zhu, Xinyu Mu, Tao Feng, Zhonghong Ou, Yuning Gong, Haoran Luo
https://arxiv.org/abs/2602.03707
- GreekMMLU: A Native-Sourced Multitask Benchmark for Evaluating Language Models in Greek
Zhang, Konomi, Xypolopoulos, Divriotis, Skianis, Nikolentzos, Stamou, Shang, Vazirgiannis
https://arxiv.org/abs/2602.05150
- Using LLMs for Knowledge Component-level Correctness Labeling in Open-ended Coding Problems
Zhangqi Duan, Arnav Kankaria, Dhruv Kartik, Andrew Lan
https://arxiv.org/abs/2602.17542 https://mastoxiv.page/@arXiv_csCL_bot/116102514058414603
- MetaState: Persistent Working Memory Enhances Reasoning in Discrete Diffusion Language Models
Kejing Xia, Mingzhe Li, Lixuan Wei, Zhenbang Du, Xiangchi Yuan, Dachuan Shi, Qirui Jin, Wenke Lee
https://arxiv.org/abs/2603.01331 https://mastoxiv.page/@arXiv_csCL_bot/116165314672421581
- A Browser-based Open Source Assistant for Multimodal Content Verification
Milner, Foster, Karmakharm, Razuvayevskaya, Roberts, Porcellini, Teyssou, Bontcheva
https://arxiv.org/abs/2603.02842 https://mastoxiv.page/@arXiv_csCL_bot/116170368271004704
- Nw\=ach\=a Mun\=a: A Devanagari Speech Corpus and Proximal Transfer Benchmark for Nepal Bhasha ASR
Sharma, Shrestha, Poudel, Tiwari, Shrestha, Ghimire, Bal
https://arxiv.org/abs/2603.07554 https://mastoxiv.page/@arXiv_csCL_bot/116204797995674104
- Model Merging in the Era of Large Language Models: Methods, Applications, and Future Directions
Mingyang Song, Mao Zheng
https://arxiv.org/abs/2603.09938 https://mastoxiv.page/@arXiv_csCL_bot/116210189810004206
- AgentDrift: Unsafe Recommendation Drift Under Tool Corruption Hidden by Ranking Metrics in LLM Ag...
Zekun Wu, Adriano Koshiyama, Sahan Bulathwela, Maria Perez-Ortiz
https://arxiv.org/abs/2603.12564 https://mastoxiv.page/@arXiv_csCL_bot/116237800898328349
- GhanaNLP Parallel Corpora: Comprehensive Multilingual Resources for Low-Resource Ghanaian Languages
Gyamfi, Azunre, Moore, Budu, Asare, Owusu, Asiamah
https://arxiv.org/abs/2603.13793 https://mastoxiv.page/@arXiv_csCL_bot/116243544688031749
- sebis at ArchEHR-QA 2026: How Much Can You Do Locally? Evaluating Grounded EHR QA on a Single Not...
Ibrahim Ebrar Yurt, Fabian Karl, Tejaswi Choppa, Florian Matthes
https://arxiv.org/abs/2603.13962 https://mastoxiv.page/@arXiv_csCL_bot/116243646346563497
- ExPosST: Explicit Positioning with Adaptive Masking for LLM-Based Simultaneous Machine Translation
Yuzhe Shang, Pengzhi Gao, Yazheng Yang, Jiayao Ma, Wei Liu, Jian Luan, Jinsong Su
https://arxiv.org/abs/2603.14903 https://mastoxiv.page/@arXiv_csCL_bot/116243711232778054
- BanglaSocialBench: A Benchmark for Evaluating Sociopragmatic and Cultural Alignment of LLMs in Ba...
Tanvir Ahmed Sijan, S. M Golam Rifat, Pankaj Chowdhury Partha, Md. Tanjeed Islam, Md. Musfique Anwar
https://arxiv.org/abs/2603.15949 https://mastoxiv.page/@arXiv_csCL_bot/116249122231759766
- EngGPT2: Sovereign, Efficient and Open Intelligence
G. Ciarfaglia, et al.
https://arxiv.org/abs/2603.16430 https://mastoxiv.page/@arXiv_csCL_bot/116249228411487178
- HypeLoRA: Hyper-Network-Generated LoRA Adapters for Calibrated Language Model Fine-Tuning
Bartosz Trojan, Filip G\k{e}bala
https://arxiv.org/abs/2603.19278 https://mastoxiv.page/@arXiv_csCL_bot/116277612915482857
- Automatic Analysis of Collaboration Through Human Conversational Data Resources: A Review
Yi Yu, Maria Boritchev, Chlo\'e Clavel
https://arxiv.org/abs/2603.19292 https://mastoxiv.page/@arXiv_csCL_bot/116277620779254916
- Alignment Whack-a-Mole : Finetuning Activates Verbatim Recall of Copyrighted Books in Large Langu...
Xinyue Liu, Niloofar Mireshghallah, Jane C. Ginsburg, Tuhin Chakrabarty
https://arxiv.org/abs/2603.20957 https://mastoxiv.page/@arXiv_csCL_bot/116283538317671552
- KG-Hopper: Empowering Compact Open LLMs with Knowledge Graph Reasoning via Reinforcement Learning
Shuai Wang, Yinan Yu
https://arxiv.org/abs/2603.21440 https://mastoxiv.page/@arXiv_csCL_bot/116283595007808076
toXiv_bot_toot
#superproductivity app is great. There aren't many apps I can run on my locked down computer at work. But this one is possible to sync via webdav so I installed a minimal webdav just to syncronize the json and md file the app generates. It work flawlessly! I have finally found a way to take my todo's between work and home.
Age makes remembering things more and more tr…
Open source has become critical digital infrastructure over the past 25 years, but its future depends on human resilience as much as code. Contributor burnout, funding gaps, and new regulations are real challenges, and Ruth has spent nearly two decades at the heart of open source communities working through exactly these kinds of problems. It's a session to look forward to!
Join us for Berlin Buzzwords on June 7-9 at Kulturbrauerei or online. Get your tickets! https://2026.berlinbuzzwords.de/
The levels of victimhood demonstrated by the "strudel studio" author charging $49 per year for the free/open source @… project, wrapped in their closed source editor plugin and abusing the (unregistered) strudel trademark with zero prior engagement with the community.
At this point if I looked I'd probably find many more similar projects an…
Open Slopware
“Free/Open Source Software tainted by LLM developers/developed by genAI boosters, along with alternatives.”
#AI
👥 This isn't just open source for show. Nearly 1M developers told the #Warp team: "If you open this up, we will help you build it." Five years after the initial preview — and with a working business model in place — they finally made it happen. #opensource
Several years ago, a street medic described a system like this and wanted to know if it could be built.
https://hackaday.com/2022/09/08/the-tak-ecosystem-military-coordination-goes-open-source/
Back then there was just no way to make it happen. Hardware was too expensive. We couldn't really ever get it cheap enough, per medic, to deploy. Best I could put together was a bunch of burner phones.
But now it's starting to really make sense. LoRa is cheap, and possibly cheaper in bulk. And it wouldn't be necessary to build everything since ATAK-CIV exists and has several open source implementations. It can even tie in to drones (which are illegal to bring to protests in at least a few states).
This has a lot of potential applications for street medic coordination, protest marshal coordination, and for airsoft teams...
Microsoft announces the Agent Control Specification, an open-source standard that aims to provide granular, consistent governance over AI agent behavior (Ram Iyer/TechCrunch)
https://techcrunch.com/2026/06/02/microsoft-offers-devs-a-better-w…
This has been on my mind for *weeks*. I've been saying for a long time that it's possible to have an AI that only uses consensually-gathered content, is open source open weights, runs on your own machine, and is designed to empower creators instead of exploit them. Well, we've finally got one. https://www.
#SpringBoot Done Right: Lessons From a 400-Module Codebase
https://medium.com/all-things-software/spring-boot-done-right-lessons-fro…
How a small German state's bid to replace Microsoft with open-source alternatives like Linux and Kamailio faces issues, as the EU pushes "digital sovereignty" (Laura Pitel/Financial Times)
https://www.ft.com/content/95bd87c8-a112-49a5-9b80-c280a6bb4283
«Zum 45. Geburtstag — Microsoft stellt MS-DOS 1.0 als #OpenSource bereit:
Zum 45. Jahrestag des Betriebssystems hat Microsoft den Quellcode der allerersten MS-DOS-Version für den #IBM PC freigegeben. Dieses wurde zum Zeitpunkt seines Erscheinens offiziell noch als 86-DOS 1.00 bezeichnet und
SenseTime releases SenseNova-U1, an open-source image model that it says can "read" images without translating them to text, reducing computing power needs (Zeyi Yang/Wired)
https://www.wired.com/story/chinese-ai-giant-sensetime-is-…
from my link log —
Open access to standards documents.
https://discourse.llvm.org/t/rfc-open-access-to-standards-documents/90856
saved 2026-05-21
When, in 2024, Chinese scientists reported developing an artificial-intelligence tool to design conotoxins, it raised eyebrows in some quarters.
In an e-mail to a private AI and biotechnology discussion group seen by Nature, a senior US government employee flagged the study as a possible biosecurity risk.
The employee, who asked not to be named because of concerns for their job, felt it was especially concerning that the conotoxin AI is based on an open-source protein language …
➡️ Scrapy - Open-source framework for efficient web scraping and data extraction
#bookmarks
As I've said, I want to make a version of my "My Tech"-site, but this time not for country of Origin, but Open vs. Closed Source.
But before I start, I need two emojis for both. Any ideas? I really think the emojis are important and they should be easily recognizable. What can I use for #OpenSource and what for
OpenAI releases Symphony, an open-source spec for agent orchestration that turns a project-management board like Linear into a control plane for coding agents (OpenAI)
https://openai.com/index/open-source-codex-orchestration-symphony
RE: https://podcasts.social/@engkiosk/116602083827417740
Bitte unterzeichnen & teilen! Es ist schon schlimm genug, dass die Arbeit vieler Open Source Projekte hauptsächlich von Dritten kommerzialisiert wird, tausenden von Unternehmen bereits gewaltige…
Meta: Neue KI-Modelle sollen teils Open-Source werden
Meta plant, neue KI-Modelle zu veröffentlichen. Die sollen in Teilen unter Open-Source-Lizenzen herausgegeben werden.
https://www.heis…
RE: https://infosec.exchange/@hex_m_hell/116671066403398988
This is another one for folks employed in the security industry. If you're close to "leadership," this may help you think about what your program looks like. But even if you're not, there are still things here that may help you think about what you do and how you do it.
I'm focused on my own paid work, but this should also be helpful to open source projects or other groups producing things that need security support.
Since his first years as a top player, Jannik Sinner has long had one major weakness.
The hotter it is, the more vulnerable he becomes.
It nearly toppled him at January’s Australian Open, before Novak Djokovic did the job instead.
On Thursday, with temperatures climbing toward the 90s at Roland Garros, Sinner could not endure.
In the second round of the French Open, the world No. 1 fell victim to Juan Manuel Cerúndolo of Argentina, the world No. 56.
He grew dizzy…
Starlette, an open-source Python framework underpinning FastAPI, has a vulnerability, called BadHost, that can allow hackers to bypass authorization (Dan Goodin/Ars Technica)
https://arstechnica.com/information-te
Noch ein paar der zuletzt hier besonders häufig geteilten #News:
Münchens IT-Wende: Open Source ist für die neue Koalition der Normalfall
Mistral launches Voxtral TTS, an open-source enterprise text-to-speech model that supports nine languages, including Hindi and Arabic, based on Ministral 3B (Ivan Mehta/TechCrunch)
https://techcrunch.com/2026/03/26/mistral-releases-a-new-open…
Cohere launches Transcribe, its first voice model; the 2B-parameter, open-source speech recognition model handles tasks like notetaking and speech analysis (Ivan Mehta/TechCrunch)
https://techcrunch.com/2026/03/26/cohere-launches-a…
Xiaomi open sources MiMo-V2.5 and MiMo-V2.5-Pro under the MIT License, saying both models are among the most efficient available for agentic "claw" tasks (Carl Franzen/VentureBeat)
https://venturebeat.com/ai/open-source…
How tech companies are using open source initiatives to achieve critical strategic goals and how such efforts are reshaping industries like AI, AVs, and more (Bill Gurley/Bill's Substack)
https://p3institute.substack.com/p/from-open-source-software-to-open…
OpenAI releases a set of prompts designed to be used with its open-weight safety model gpt-oss-safeguard that lets developers make their apps safer for teens (Amanda Silberling/TechCrunch)
https://techcrunch.com/2026/03/24/openai-adds…
Cal.com, which provides scheduling software, is moving its core open-source codebase to a closed repository, citing the dangers of AI hacking its open code (Steven Vaughan-Nichols/ZDNET)
https://www.zdnet.com/article/ai-security-worries-force-company-t…
After EV maker Fisker's collapse, ~4,000 car owners formed a nonprofit to keep their cars working by reverse-engineering software and building open-source tools (Fred Lambert/Electrek)
https://electrek.co/2026/05/16/fisker-ocean-open-source-ev-story-aft…
Moonshot introduces Kimi K2.6, an open-weight model that it says shows strong improvements in long-horizon coding tasks, available under a modified MIT License (Kimi AI)
https://www.kimi.com/blog/kimi-k2-6