Link Sharing

Link Sharing

56872 bookmarks
Newest
HashiCorp Ships Public Beta of Vault Kubernetes Key Management
HashiCorp Ships Public Beta of Vault Kubernetes Key Management
HashiCorp has released a public beta of Vault Kubernetes key management, a KMS v2-compatible plugin that lets the Kubernetes API server delegate envelope encryption to Vault Enterprise, moving the key encryption keys that protect etcd data out of the cluster and into a separately governed trust domain.
·infoq.com·
HashiCorp Ships Public Beta of Vault Kubernetes Key Management
The OpenAI Hack Shows the Genie Is Out of the Bottle - Schneier on Security
The OpenAI Hack Shows the Genie Is Out of the Bottle - Schneier on Security
This essay originally appeared in Foreign Policy. Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild. OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unreleased model that is almost certainly GPT-6. In particular, it was running the ExploitGym benchmark, which measures how good a model is at turning security vulnerabilities into working exploits: basically, offensive cyberattacks. Since these were internal tests, OpenAI locked those models in a secure sandbox that denied them access to the internet. But it was running the models without any safety filters that would prevent them from offensive cyber-actions. That meant that there was nothing to prevent the models from trying to ...
·schneier.com·
The OpenAI Hack Shows the Genie Is Out of the Bottle - Schneier on Security
SQLite Critical CVEs or LLM Slop? - JFrog Security Research
SQLite Critical CVEs or LLM Slop? - JFrog Security Research
The JFrog security research team recently identified a supply chain attack targeting the `xinference` package on PyPI. Versions 2.6.0, 2.6.1, and 2.6.2 were compromised and yanked by maintainers after users reported suspicious behavior. If you installed or imported these versions, you must assume your environment is compromised.
·research.jfrog.com·
SQLite Critical CVEs or LLM Slop? - JFrog Security Research
How Agentic Coding Is Reshaping the Software Development Lifecycle - Battery Ventures
How Agentic Coding Is Reshaping the Software Development Lifecycle - Battery Ventures
Software development has emerged as the killer use case for generative AI today, with half of all tokens consumed on OpenRouter being used for code generation. Cursor, for example, has ramped from $100M to $4B of ARR in the last 12 months. We’re in the first innings of the biggest shift in the history of… Continue reading How Agentic Coding Is Reshaping the Software Development Lifecycle
·battery.com·
How Agentic Coding Is Reshaping the Software Development Lifecycle - Battery Ventures