Tap a claim on the ring to put it at the centre.
← A malicious or broken package is typically caught and pulled or patched within about a week of being published.
9 connected korrents · 8 moments from 18 Jan 2026 to 17 Sept 2026.
Everything filed under cybersecurity
cybersecurity
Everything filed under open source
open source
Same subject Same subject Same subject Same subject Same subject Same subject Same subject Same subject Same subject
Read this korrent: A malicious or broken package is typically caught and pulled or patched within about a week of being published.
A malicious or broken package is typically caught and pulled or patched within about a week of being published.
Last stated 8 months ago
18 Jan 2026
IS
Ivan Santos — holds since 2026-01-18 — tap for who they are
Same subject: A years-old unfixed default in GitHub Actions is the root cause of a wave of software supply-chain attacks. — tap to centre the map on it
A years-old unfixed default in GitHub Actions is the root cause of a wave of software supply-chain attacks.
Last stated 4 months ago
22 May 2026
TC
Tyler Cipriani — holds since 2026-05-22 — tap for who they are
Same subject: Any software that depends on open source has a network of humans with package publishing rights who are potential attack vectors. — tap to centre the map on it
Any software that depends on open source has a network of humans with package publishing rights who are potential attack vectors.
Last stated 2 weeks ago
17 Sept 2026
SW
Simon Willison — holds since 2026-09-17 — tap for who they are
Same subject: By 2027, open-weight AI models more powerful than today's frontier systems will be downloadable by any country or well-resourced non-state group. — tap to centre the map on it
By 2027, open-weight AI models more powerful than today's frontier systems will be downloadable by any country or well-resourced non-state group.
Last stated a month ago
19 Aug 2026
DT
Derek Thompson — holds since 2026-08-19 — tap for who they are
Same subject: Dependency cooldowns are currently the best defense against supply chain attacks via compromised package publishers. — tap to centre the map on it
Dependency cooldowns are currently the best defense against supply chain attacks via compromised package publishers.
Last stated 2 weeks ago
17 Sept 2026
SW
Simon Willison — holds since 2026-09-17 — tap for who they are
Same subject: Most security reports an open-source project receives are agent-generated and untested, and the defence is publishing what you guarantee and what lies outside your security boundary. — tap to centre the map on it
Most security reports an open-source project receives are agent-generated and untested, and the defence is publishing what you guarantee and what lies outside your security boundary.
Last stated 2 months ago
10 Aug 2026
PS
Peter Steinberger — holds since 2026-08-10 — tap for who they are
Same subject: The delay imposed by a dependency cooldown gives registries and security researchers time to catch and remove malicious packages before they reach downstream users. — tap to centre the map on it
The delay imposed by a dependency cooldown gives registries and security researchers time to catch and remove malicious packages before they reach downstream users.
Last stated 8 months ago
18 Jan 2026
IS
Ivan Santos — holds since 2026-01-18 — tap for who they are
Same subject: At any given moment the frontier systems are the ones worth worrying about, because by the time open models can do what these agents did, frontier models will be doing something far worse. — tap to centre the map on it
At any given moment the frontier systems are the ones worth worrying about, because by the time open models can do what these agents did, frontier models will be doing something far worse.
Last stated a month ago
1 Sept 2026
AC
Ajeya Cotra — holds since 2026-09-01 — tap for who they are
Same subject: Frontier AI labs such as Anthropic likely have had internal security incidents similar to OpenAI's HuggingFace attack that were never publicly disclosed. — tap to centre the map on it
Frontier AI labs such as Anthropic likely have had internal security incidents similar to OpenAI's HuggingFace attack that were never publicly disclosed.
Last stated a month ago
31 Aug 2026
ZM
Zvi Mowshowitz — holds since 2026-08-31 — tap for who they are
Same subject: OpenAI either could not find their agents' RubyGems attack in their logs after other incidents or knew and chose not to tell RubyGems, and both are bad. — tap to centre the map on it
OpenAI either could not find their agents' RubyGems attack in their logs after other incidents or knew and chose not to tell RubyGems, and both are bad.
Last stated 3 weeks ago
12 Sept 2026
SW
Simon Willison — holds since 2026-09-12 — tap for who they are
a cloud: claims about one subject, named for it bar: when it was last stated, on a scale from 2015 to today — full is today a face: someone who holds the claim — tap it for who they are