GitHub’s open-source security agent found 24 Android vulnerabilities
GitHub Security Lab used its open-source Taskflow Agent and reusable audit workflows to find 24 Android vulnerabilities, while documenting limits and false positives.
GitHub Security Lab used its open-source Taskflow Agent and reusable audit workflows to find 24 Android vulnerabilities, while documenting limits and false positives.
Malicious MemOS npm and PyPI releases carried the sckit credential stealer. Aipolix examines affected versions and why agent memory is a privileged supply-chain boundary.
DeepSeek Harness 0.1.7 makes agent capabilities more dynamically composable. Aipolix examines the benefits and the new operational risks.
What Plugin4Shell changes about Git-pinned plugins in Claude Code, Codex, Copilot and Gemini CLI, with qualified patch status and an audit plan.
Qwen Code 0.24.1 ships per-subagent tool allowlists and a browser SDK. What is usable now, what remains unfinished, and how developers can verify the boundaries.
Colibrì 1.11.0 adds native DeepSeek V4.1 Flash support, showing how disk-tiered inference trades memory capacity for I/O and latency.
The RubyGems campaign shows why agent security must model package publishing, build automation and other indirect write paths as part of the execution surface.
NASA and IBM released an open lunar foundation model, datasets and fine-tuning tools, while the public repository excludes the pretraining code.
DeepSeek releases V4.1 Flash with native multimodality, open weights and new API routing that changes how older Flash and V4 Pro identifiers resolve.
Mastra Factory enters beta with configurable human and agent gates across issue intake, planning, coding and review, plus self-hosting options and caveats.