Axios Compromise on npm Introduces Hidden Malicious Package

A newly discovered software supply chain attack targeting the npm ecosystem briefly compromised one of the most widely used JavaScript libraries in the world ...
Grounded Intelligence Is Key to Safe AI Software Development at Scale

Grounded Intelligence Is Key to Safe AI Software Development at Scale

One experience has become nearly universal as AI systems move deeper into software development, their confidence when they're wrong ...
Compromised litellm PyPI Package Delivers Multi-Stage Credential Stealer

Compromised litellm PyPI Package Delivers Multi-Stage Credential Stealer

This morning, the widely used Python package litellm, a popular abstraction layer for interacting with large language models (LLMs), was compromised and two malicious versions released (1.82.7 and 1.82.8) ...