#security #LLM #way
Researchers at JFrog analyzed 55 vulnerability reports regarding #SQLite that were recently published. Based on the data from these reports, MITRE assigned #CVE identifiers to all of the issues. Three issues were classified as critical, and Red Hat assigned the most dangerous vulnerability (CVE-2026-51302) a severity score of 10 out of 10 in its databases, while SUSE rated it 9.8 out of 10. A detailed analysis of the reported vulnerabilities revealed that 54 of the 55 vulnerabilities, including the one marked as critical, are fictitious and caused by hallucinations from the AI model:
https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/
#postmortem #GitHub
On August 17, 2026, from 13:28–21:15 UTC (7h 47m), GitHub.com experienced elevated errors and latency across Issues, Pull Requests, APIs, Actions, and Copilot. At peak, web/API error rates were approximately 20%, while archive and raw-content downloads reached approximately 50%. SAML/OIDC authentication, SCIM, and Team Sync were also affected, as well as Actions workflows in GHEC with Data Residency that depend on public workflow step definitions hosted on GitHub.com. Most services recovered by 16:36 UTC as our Central US datacenter recovered; Actions was degraded until approximately 18:03 UTC; and Copilot Token Service fully recovered by 21:02.
Some of the failing traffic was moved from Central US to Northern Virginia where it was served successfully until the network failure in Central US was debugged and resolved. Delayed replies to a single internal endpoint triggered a latent retry bug in VS Code that amplified traffic by approximately 10x and caused delayed recovery for the Copilot Token Service.
The immediate cause of the failure was network saturation on load balancers in Central US due to a new peak in traffic. Originally this was caused by an Istio sidecar pod reaching its concurrency limits and failing to auto scale correctly because of a misconfigured policy that watched host service but not sidecar limits. One failure cascaded to more and eventually four HAProxy nodes exhausted their flow limits, degrading the gateway auth path and causing widespread authentication latency and failures. The problem was worsened by optimistic retry logic which overloaded internal load balancers. Pausing HAProxy on those nodes simultaneously produced immediate broad recovery.
The retry storm in Northern VA was fixed by 1) temporarily reducing gateway retry logic with a PR and 2) blocking inbound Copilot Token Service token requests at the load balancers with a 403, and then gradually ramping back up traffic per-site to allow callers to succeed.
Re: CEO fired developers to make room for AI. Developers create open source AI CEO
To be fair I think its far easier to automate leadership jobs despite how they believe in greater self-worth. As a developer I keep running into problems that require some measure of creativity to solve or workaround. And regardless of how many years I've been in the industry I'm not running out of issues. They just keep getting more obscure. On the other hand leadership communication and problem resolution seem like the exact opposite of creativity and innovation. Its all about time proven, reliable solutions. Same layoff notices, recommendations, design everywhere. Repetitive, boring, politically correct and therefore easy to automate. Accountability will likely become reason n1 for keeping leadership roles intact that is until people become accustomed to AIs everywhere. After all what's the difference between a bot showing a layoff notice at 5am or an AI generated message/video from a human doing the very same thing.
crnkofe, 1 day ago
#DPRK #way
The DPRK built its cyber capability as a deliberate extension of its asymmetric deterrence doctrine, treating cyber operations as a cheap, deniable "all-purpose sword" alongside nuclear weapons to ensure regime survival against better-resourced adversaries and circumvent international sanctions.
* From roughly 2014 onward, cyber operations evolved from espionage and sabotage into a load-bearing revenue stream, bank heists, ransomware, and cryptocurrency theft, financing the very weapons programmes that international sanctions were designed to constrain.
* Even as the GRIB (ex-RGB) and NIA (ex-MSS) consistently lead DPRK cyber offensive operations, the units and bureaus beneath them are subject to constant reorganization, a deliberate control mechanism that keeps agencies competing for Kim Jong-un's favor, prevents consolidation of independent power, and complicates the attribution and sanctions-designation efforts of foreign governments.
* DPRK offensive cyber operations are distributed across APT clusters, with the former Lazarus umbrella now decomposed by Sekoia and Kudelski Security into six distinct sub-clusters, nearly all of which conduct lucrative operations, whether as their primary mandate or to self-fund espionage and sabotage campaigns.
* These APT intrusion sets are complemented by thousands of IT workers operating under false identities worldwide, who serve a dual function: remitting salaries to the regime and leveraging their insider access within contracted organizations to conduct further operations, with proceeds laundered through centralized exchanges, decentralized exchanges (DEXs), and P2P platform.
* The DPRK has constructed a complex network of educational and private intermediaries to enable its cyber operations, spanning academic institutions that both train operatives and function as operational nodes. This parallel web of third-country relays often extends to allies like China and Russia, as well as countries in Africa and
❗️ Amazon is giving its delivery drivers smart glasses that snap photos almost constantly to help its AI map neighbourhoods, capturing people and private property across potentially several thousand images per shift.
Asked whether customers can opt out, Amazon's Viraj Chatterjee said, "We haven't thought about that."
Amazon wants 20,000+ pairs on routes by end-2027 and confirmed the images can be obtained with a warrant.