Yep. I really didn’t expect it to be that serious! Then I saw the vulnerability this morning… wild.
CYBERSECURITY
-

AI Review Bots Superior to Human Security Review
By
–
this customer got notified 45 mins after attack, 1.5 hours before announcement of the attack. Generalist coding agent is also a better security reviewer than you! there is basically 0 reason not to have a Review bot enabled for all the things. it’s not just a security thing,
-

Axios v1.14.1 distributes malware: urgent security alert
By
–
STOP. DO NOT DEPLOY. "We don't even use Axios" Think again. As one of npm's most depended-on packages, Axios is almost certainly lurking in your nested dependencies. v1.14.1 is actively distributing malware (plain-crypto-js). Pin versions or wait until this is resolved ↓
-
Scaling Speed and Trust: AI Governance in the Modern Era
By
–
How do we build systems where speed and trust can scale together?
— Helen Yu (@YuHelenYu) 31 mars 2026
I explored this with @MichaelLeland, field CTO of #island at RSA and it’s the challenge of the AI era.
AI is now an actor. Fast, boundaryless, and creating risks most orgs don’t yet see (hello, shadow AI +… pic.twitter.com/1WfASpKGtKHow do we build systems where speed and trust can scale together? I explored this with @MichaelLeland, field CTO of #island at RSA and it’s the challenge of the AI era. AI is now an actor. Fast, boundaryless, and creating risks most orgs don’t yet see (hello, shadow AI + agents). We unpack: • AI governance where work happens • “No” → “Yes, but” security • AI-first architecture 👉 Watch: piped.video/GT5M1CQ4J54 Check out demos of Island's new AI products here: island.io/ai/?utm_medium=pai… #RSAC #Cybersecurity #AI #Governance #IslandPartner #RiskManagement
→ View original post on X — @yuhelenyu, 2026-03-31 06:34 UTC
-
Package Installation Security Risks in LLM Workflows
By
–
exactly, I can't feel like I'm playing russian roulette with each `pip install` or `npm install` (which LLMs also run liberally on my behalf).
-

AetheroSpace Launches Phobos Satellite for Orbital Intelligence
By
–
Congrats to our friends @AetheroSpace on their (literal) launch! 🚀🛰️ https://t.co/8vyM7te7is
— Gill Verdon (@GillVerd) 31 mars 2026Congrats to our friends @AetheroSpace on their (literal) launch! 🚀🛰️ Edward (@somefoundersalt) Proud to announce that Phobos, the second @AetheroSpace satellite, was successfully launched to orbit earlier this morning We’re partnered with @BoozAllen on this mission to demonstrate capabilities for adaptive event detection using high-fidelity Earth observation data collected on orbit This will enable satellites to achieve faster, smarter, decision-making on orbit, and is a major step towards building the orbital intelligence layer for defense needs! — https://nitter.net/somefoundersalt/status/2038788178002522343#m
→ View original post on X — @bobgourley, 2026-03-31 05:05 UTC
-
NVIDIA Team Hardens AI Security Against Advisory Overload
By
–
We have a whole team from @nvidia helping sifting through the onslaught of slop AI security advisories (and the occasional important ones) and harden in every release.
-
NPM Axios Package Supply Chain Attack Security Alert
By
–
If you have NPM package axios in your dependencies you need to make sure it's pinned to a known safe version, sounds like there's another supply chain attack in play
-
Anthropic Launches Claude Security for Enterprise Users
By
–
That’s the one I am still finalizing, hopefully will have emails sent tomorrow for attaching proofs and a few days after will have a randomly picked name announced
-
Railway data breach causes customer loss notification needed
By
–
We have actively lost customers today because of this and found out FROM them! We’re lucky, none of the data was that sensitive—but it sounds like other customers of Railway are in a very tough spot right now. We need something , written in plain English, we can send to users