korrents

On the map

Tap a claim on the ring to put it at the centre.

← A malicious or broken package is typically caught and pulled or patched within about a week of being published.

9 connected korrents · 8 moments from 18 Jan 2026 to 17 Sept 2026.

Everything filed under cybersecurity cybersecurity Everything filed under open source open source Same subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subject Read this korrent: A malicious or broken package is typically caught and pulled or patched within about a week of being published. A malicious or broken package is typicallycaught and pulled or patched within abouta week of being published. Last stated 8 months ago 18 Jan 2026 IS Ivan Santos — holds since 2026-01-18 — tap for who they are Same subject: A years-old unfixed default in GitHub Actions is the root cause of a wave of software supply-chain attacks. — tap to centre the map on it A years-old unfixed default inGitHub Actions is the root cause ofa wave of software supply-chainattacks. Last stated 4 months ago 22 May 2026 TC Tyler Cipriani — holds since 2026-05-22 — tap for who they are Same subject: Any software that depends on open source has a network of humans with package publishing rights who are potential attack vectors. — tap to centre the map on it Any software that depends on opensource has a network of humans withpackage publishing rights who arepotential attack vectors. Last stated 2 weeks ago 17 Sept 2026 SW Simon Willison — holds since 2026-09-17 — tap for who they are Same subject: By 2027, open-weight AI models more powerful than today's frontier systems will be downloadable by any country or well-resourced non-state group. — tap to centre the map on it By 2027, open-weight AI models morepowerful than today's frontiersystems will be downloadable by anycountry or well-resourced non-stategroup. Last stated a month ago 19 Aug 2026 DT Derek Thompson — holds since 2026-08-19 — tap for who they are Same subject: Dependency cooldowns are currently the best defense against supply chain attacks via compromised package publishers. — tap to centre the map on it Dependency cooldowns are currentlythe best defense against supplychain attacks via compromisedpackage publishers. Last stated 2 weeks ago 17 Sept 2026 SW Simon Willison — holds since 2026-09-17 — tap for who they are Same subject: Most security reports an open-source project receives are agent-generated and untested, and the defence is publishing what you guarantee and what lies outside your security boundary. — tap to centre the map on it Most security reports an open-sourceproject receives are agent-generatedand untested, and the defence ispublishing what you guarantee andwhat lies outside your securityboundary. Last stated 2 months ago 10 Aug 2026 PS Peter Steinberger — holds since 2026-08-10 — tap for who they are Same subject: The delay imposed by a dependency cooldown gives registries and security researchers time to catch and remove malicious packages before they reach downstream users. — tap to centre the map on it The delay imposed by a dependencycooldown gives registries andsecurity researchers time to catchand remove malicious packages beforethey reach downstream users. Last stated 8 months ago 18 Jan 2026 IS Ivan Santos — holds since 2026-01-18 — tap for who they are Same subject: At any given moment the frontier systems are the ones worth worrying about, because by the time open models can do what these agents did, frontier models will be doing something far worse. — tap to centre the map on it At any given moment the frontiersystems are the ones worth worryingabout, because by the time openmodels can do what these agents did,frontier models will be doingsomething far worse. Last stated a month ago 1 Sept 2026 AC Ajeya Cotra — holds since 2026-09-01 — tap for who they are Same subject: Frontier AI labs such as Anthropic likely have had internal security incidents similar to OpenAI's HuggingFace attack that were never publicly disclosed. — tap to centre the map on it Frontier AI labs such as Anthropiclikely have had internal securityincidents similar to OpenAI'sHuggingFace attack that were neverpublicly disclosed. Last stated a month ago 31 Aug 2026 ZM Zvi Mowshowitz — holds since 2026-08-31 — tap for who they are Same subject: OpenAI either could not find their agents' RubyGems attack in their logs after other incidents or knew and chose not to tell RubyGems, and both are bad. — tap to centre the map on it OpenAI either could not find theiragents' RubyGems attack in theirlogs after other incidents or knewand chose not to tell RubyGems, andboth are bad. Last stated 3 weeks ago 12 Sept 2026 SW Simon Willison — holds since 2026-09-12 — tap for who they are
a cloud: claims about one subject, named for itbar: when it was last stated, on a scale from 2015 to today — full is todaya face: someone who holds the claim — tap it for who they are

At the centre A malicious or broken package is typically caught and pulled or patched within about a week of being published. Last stated 18 Jan 2026 · 8 months ago Holds Ivan Santos Read this korrent →