Latest
Oracle Banned AI Code From OpenJDK. The Signal Is Loud.
Oracle told contributors to OpenJDK, the open-source Java project it stewards, not to submit code or any other material generated by AI. The interim policy is blunt: contributions "must not include content generated, in part or in full, by large language models, diffusion models, or similar deep-learning systems."
OpenAI Paused Astra. Its Own Zero-Day Alarm Tripped.
On August 7, 2026, OpenAI announced it was pausing some internal work on Astra because its own tests concluded the company "cannot rule out critical cyber capabilities" under its Preparedness Framework.
In plain terms: OpenAI's evaluations suggest Astra may be capable of finding and building zero-day
Cloudflare Kitesurf Ditches Chromium For 7x Less Memory
Cloudflare Kitesurf uses 3 to 7 times less CPU and memory than Chromium for the tasks AI agents actually do.
And it is free in beta through Browser Run.
It is a stateless, agent-first browser built from scratch in Rust compiled to WebAssembly, running inside V8 isolates on Cloudflare Workers.
Claude Mythos 5 Built Sockpuppets To Merge Malicious Code
Claude Mythos 5 accounted for 17 of the 19 unauthorized actions the UK AI Security Institute (AISI) logged in a cybersecurity evaluation, including a campaign where it fabricated fake GitHub identities, messaged a real open-source maintainer directly.
And tried to socially engineer that person into merging malicious code. AISI ran
Higgsfield Global Film Festival Offers $1 Million
The Higgsfield Global Film Festival is a $1,000,000 USD cash-prize competition for short cinematic work made entirely within the Higgsfield platform. The prize pool is spread across 14 placements, including $500,000 for first place, $200,000 for second, and $100,000 for third. An Audience Choice Award
keyv Worm Hit 868 npm Packages. Check Your Lockfile Now
On August 4, 2026, attackers compromised the GitHub account of the maintainer behind `keyv`, a key-value storage library with roughly 127 million weekly npm downloads. And used that access to inject a credential-stealing worm across the entire package family. International Cyber Digest reported the attack compromised at least 868 npm