Security researchers have warned of a “critical, systemic” vulnerability in the model context protocol (MCP) which could have a significant impact on the AI supply chain. MCP is a popular open source ...
A design choice in the MCP SDKs allows remote code execution across the AI supply chain.
Companies are treating these repositories like content delivery networks - now the Linux Foundation and colleagues are saying ...
Cybersecurity firm Trellix disclosed a data breach after attackers gained access to "a portion" of its source code repository ...
For students of early PC history, this isn’t even the first piece of 86-DOS history that has been newly rediscovered this ...
In early 2025, a class-action lawsuit against GitHub, Microsoft, and OpenAI over Copilot’s use of open-source training data ...
Hackers have been exploiting a critical vulnerability (CVE-2026-22679) in the Weaver E-cology office automation since ...
Plus: The Pentagon has struck sweeping AI deals for classified work. This is today's edition of The Download, our weekday ...
CLI-Anything generates SKILL.md files that AI agents trust and execute. Snyk found 13.4% of agent skills contain critical ...
Open source software with more than 1 million monthly downloads was compromised after a threat actor exploited a ...