The Bureau of Industry and Security approved ten Chinese firms — Alibaba, Tencent, ByteDance among them — to buy NVIDIA's H200.
On July 14, an attacker opened thirty-six pull requests against the AsyncAPI generator repository.
At 9:00 UTC on August 4, a single GitHub account—jaredwray, the maintainer behind the keyv caching library—pushed a commit that looked like a routine release.
Spot-market H100 instances dropped below $1.20 an hour in June.
On July 11, a stolen npm publishing token gave an attacker control of jscrambler — a JavaScript obfuscation package with 15,800 weekly downloads.
The promise of SLSA provenance is straightforward — cryptographic proof that a package was built by a known pipeline from known source code.
GDDR6 spot prices tripled since autumn 2025. From roughly 2.
On July 1, AWS raised its EC2 Capacity Block prices for GPU instances by 20%. This was the second hike in 2026 — a 15% bump landed earlier in the year.
Intel Foundry posted a $2.5 billion operating loss last quarter.
Novee Security scanned 30,000 repositories and found that 300 of them — including repos owned by Microsoft, Google, Apache, Cloudflare, and the Python Software...
The Hades campaign dropped a string into its payload that tells you everything about where supply chain attacks are heading: DontRevokeOrItGoesBoom.
Somewhere around late May, an attacker pointed a browser at a SimpleHelp server, submitted a self-signed JWT to the OIDC callback endpoint, and walked away...
The math on GPU ownership used to be simple.
Most supply chain attacks are fire-and-forget: plant a malicious package, wait for installs, harvest credentials. Shai-Hulud broke that model.
Cursor just proved something uncomfortable: you don't need to train a frontier model from scratch to compete with one.
The GPU market finally loosened up. H100 spot prices dropped to $1.
The next Google Pixel might ship with 12GB of RAM instead of 16.
Thirty-four packages. Three registries.
Pick up an NVIDIA B200 and trace where the roughly 6,400 manufacturing cost actually goes.
On Sunday morning, someone pushed 404 malicious package versions to npm and PyPI in under five hours.