Connect with us

Tech

Hackers have compromised dozens of popular open source packages in an ongoing supply chain attack

Published

on

Hackers have compromised several popular open source projects relied on by software developers all over the world in an ongoing cyberattack.

On Tuesday, cybersecurity firms StepSecurity and SafeDep warned of the latest wave of so-called “supply chain” attacks, which aim to compromise developers of popular open source projects and use that access to plant malicious updates that are pushed to users downstream. 

According to SafeDep, hackers took over the account of one developer and released over 630 malicious versions across 317 packages in about 20 minutes. The goal of the attack is to steal credentials for various services, including password managers, as a way to steal data and continue spreading the malware. 

Among the packages that the hackers compromised there’s Antv, a library made by Alibaba. In some cases, the hackers published malicious updates on GitHub, according to JFrog Security.

This latest wave of attacks is part of a wider campaign targeting open source projects and the developers who use the code for their own projects. Researchers have dubbed the hacks “Mini Shai-Hulud,” after the attack followed a previous, more expansive hacking campaign. 

Last week, in another wave of attacks as part of the Mini Shai-Hulud attacks, hackers compromised the computers of two OpenAI employees after hacking the open source library TanStack. OpenAI was just one of several victims.

>

Continue Reading

Tech

Meta Faces India Backlash After PM Modi Post Restriction, Issues Apology

Published

on

Meta apologizes after blaming the restriction on an operational error.

Meta Platforms Chief Global Affairs Officer Joel Kaplan apologized to India’s Information Technology Minister Ashwini Vaishnaw on Wednesday over the temporary restriction of Modi’s Facebook post in July.

“I apologized to the minister on behalf of Meta for the error restricting PM Modi’s post,” Kaplan said in a statement.

The post, a video message from Modi addressing students during protests over examination paper leaks, was briefly restricted on Facebook before being restored. Meta said the removal happened because of an operational error.

The company’s apology followed meetings between Meta executives and Indian government officials as scrutiny increased over how the platform handles politically sensitive content and harmful material.

The incident added to a wider dispute between Meta and India’s government. Officials have raised concerns about child sexual abuse material (CSAM), deepfake content and other platform failures.

According to Reuters, Moneycontrol and other Indian outlets reported that Meta CEO Mark Zuckerberg separately apologized to the Indian government over child sexual abuse material, deepfakes and other operational lapses involving the company’s platforms. Meta did not respond to Reuters’ request for comment on those reports.

Indian authorities had also questioned Meta over how harmful content could appear on its services. Government officials said the company acknowledged mistakes and discussed corrective measures, according to reports from Indian media.

What’s hot at TechRepublic

India is one of Meta’s largest markets, with hundreds of millions of people using Facebook, Instagram and WhatsApp. WhatsApp alone has more than 600 million users in the country, according to Bloomberg.

The dispute highlights the difficult balance global platforms face in India. Companies must maintain content moderation systems that can operate at massive scale while also navigating government expectations around political speech, safety and accountability.

For users, the episode raises questions about how automated moderation tools handle high-profile accounts and whether mistakes involving public figures receive faster attention than similar errors affecting ordinary users.

Meta’s apology may ease immediate tensions, but the broader debate over platform responsibility is unlikely to disappear. Social networks are increasingly being pushed to explain how their moderation systems determine what content remains available to audiences.

Also read: Meta’s moderation controversy in India follows another recent reversal for the company, which removed an Instagram AI image feature after backlash over consent and privacy.

>

Continue Reading

Tech

SpaceX Spent $329M on Tesla Megapacks as AI Costs Climbed

Published

on

SpaceX spent $329 million on Tesla Megapack battery systems during the first half of 2026 as costs connected to its AI data center expansion rose sharply, according to a public quarterly filing with the Securities and Exchange Commission.

Purchases reached $295 million in the second quarter alone, up from $34 million in the first. The six-month total was already about 65% of the $506 million SpaceX recorded in Megapack purchases for all of 2025.

The increase adds another cost to the AI infrastructure equation. Beyond servers, networking, and cooling, large data centers need electrical systems that can respond quickly when thousands of chips raise or lower their power use at the same time.

Megapack purchases rose alongside AI infrastructure costs

SpaceX’s quarterly filing records the Megapacks as property, plant, and equipment. SpaceX acquired xAI on February 2 and now reports AI as one of its three operating segments.

Research and development costs in that segment increased by $2.53 billion during the first half of 2026 compared with the same period last year. SpaceX attributed $1.74 billion of the increase to infrastructure and cloud computing expenses associated with expanding its data centers.

The figures extend the picture presented in SpaceX’s initial public offering filing, which showed how deeply the company’s financial performance had become tied to xAI’s computing ambitions.

Megapacks can store electricity for use during periods of high demand, supply short-term backup power, and help stabilize fluctuations in a facility’s electrical load. The U.S. Department of Energy has described AI data centers as large, dynamic loads that can create repeated swings in electricity demand.

Those characteristics make battery storage useful even when a facility has access to the grid or its own generators. The batteries can respond faster than many generation sources when demand changes suddenly.

Batteries support, rather than replace, power generation

Megapacks do not produce electricity. They must be charged from the grid, renewable resources, or on-site generation before they can release power back to a data center.

SpaceX and xAI have been expanding those other sources as well. Musk’s acquisition of mobile power provider APR Energy could provide temporary or supplemental generation, while xAI has pursued gas-fired power for its Mississippi data centers.

Used together, generation and battery storage can serve different parts of the same workload. Generators and grid connections provide the electricity, while batteries help manage short-term changes, peaks, and interruptions.

The Tesla purchases appear in the filing’s related-party transactions section because Elon Musk leads both companies. SpaceX did not disclose how many Megapacks it bought, their combined storage capacity, where they are installed, or how long they could support a data center during an outage.

The purchase value therefore provides a clear measure of spending, but not of the systems’ performance. Capacity, discharge duration, and facility load would be needed to establish how much operational resilience the batteries provide.

For companies expanding AI capacity, SpaceX’s spending illustrates how quickly the power portion of a project can grow. Access to chips may determine what a data center can compute, but electricity supply, storage, and grid connections can determine when that computing capacity is ready to use.

Also read: Filings suggest Musk’s proposed Texas Terafab chip plant could cost up to $119 billion.

>

Continue Reading

Tech

UK AI tests found 19 unauthorized agent actions

Published

on

AI agents crossed the line during cyber evaluation.

The U.K.’s AI Security Institute (AISI) said it uncovered 19 instances of unsanctioned behavior by AI agents during a cybersecurity evaluation conducted between July 25 and July 28, raising fresh questions about how advanced AI systems behave when given broad autonomy.

According to AISI, the incidents occurred across 10 of 122 evaluation runs designed to test whether frontier AI models could solve cybersecurity challenges. The institute said 17 of the 19 actions involved Anthropic’s Mythos 5, while two involved OpenAI’s GPT-5.6 Sol after cyber safety classifiers had been disabled for testing.

The watchdog stressed that none of the attempts caused real-world harm, and the models were operating under testing conditions that do not reflect how they are made available to the public. Those conditions included unrestricted internet access and disabled cyber safeguards to measure the models’ maximum capabilities.

Social engineering and malicious code attempts

AISI said the most serious incident involved a Mythos 5 agent attempting to insert malicious code into a real open-source GitHub project.

The agent allegedly researched project maintainers, created fake online identities, and used them to pressure a human reviewer into approving the code. When challenged, it edited its earlier activity to make it appear harmless and considered using a new identity to continue its effort. The pull request was ultimately rejected by a human maintainer.

The institute also documented attempts by agents to contact real people with deceptive messages, plant prompt injections aimed at other AI systems, and leave instructions for other AI agents working on the same challenge to reuse accounts and artifacts.

The activity was detected after AISI’s monitoring flagged unusual traffic leaving its research systems through the Tor anonymity network. The institute said it halted the evaluation, isolated affected systems, and contained the incident within about an hour.

“This is the first time we have seen risks around autonomy and deception manifest this clearly, without specific prompting, in the real-world,” AISI said.

Must-read security coverage

Anthropic says safeguards were intentionally removed

Anthropic said the evaluation deliberately removed many of the protections normally present in its production systems.

“The prompts in the evaluation did not impose any specific restrictions on how the internet should be used. This and the removal of safeguards meant that the models were tested under ‘deliberately permissive conditions’ that are not representative of any of our production models,” the company said in a statement posted on X.

Anthropic added that it is working with AISI to investigate the incident and emphasized there was “no evidence here of an escape from a secure environment.”

OpenAI similarly noted that the testing conditions “do not reflect ordinary use” and that the company would “continue working with evaluators and other stakeholders across the industry to strengthen shared practices for conducting evaluations safely.”

The bigger picture

The incident follows other recent disclosures from OpenAI and Anthropic involving AI agents taking unintended actions during cybersecurity evaluations. AISI said those cases, taken together, suggest a shift in the AI risk landscape: future problems may arise not only from people misusing AI tools, but also from powerful AI agents operating beyond their authorized scope in research and testing environments.

One important limitation remains unresolved. AISI said it cannot yet determine whether the agents understood they were interacting with the real world or believed they were still operating inside a fictional test scenario.

The institute is now tightening internet controls, adding real-time monitoring, and redesigning future evaluations to prevent similar behavior while preserving the realism needed to test frontier AI systems.

Other News: Security researchers uncovered three attack techniques that could let malware steal synced passkeys from Google Password Manager.

>

Continue Reading

Trending

Copyright © 2017 Zox News Theme. Theme by MVP Themes, powered by WordPress.