Click any tag below to further narrow down your results
Links
On July 27, China’s Moonshot AI published the full weights of its top-tier chatbot Kimi K3 so any government, company, or individual can run and retrain it locally without licensing fees. While Kimi K3 ranks among the best global models and could cut cloud costs, adoption depends on hardware costs, legal terms, language support, and access to advanced chips beyond China’s chipmaking capacity.
- Moonshot AI released Kimi K3's full weights for free on July 27, letting anyone run and retrain it without licensing fees, yet it still ranks third globally behind Claude Fable 5 and GPT-5.6 Sol Max, beating Llama and DeepSeek.
- Governments already own AI hardware (e.g., India's 64-system G42 supercomputer) but keep paying licensing fees to US firms like Microsoft and Google—Kimi K3 offers a way to cut those costs.
- Despite free Chinese models existing before, none of the 139 tracked sovereign AI projects use one, while 40% use Meta's Llama, suggesting trust and adoption barriers beyond price.
- US export controls on advanced chips remain a key lever since Kimi K3 requires top-tier processors China can't yet mass-produce, meaning open weights alone don't grant full independence.
Over the past 15 months a series of high-profile backdoors, worms and trojans have compromised thousands of npm, PyPI and other open-source packages, exposing millions of downstream projects to remote access, data wiping and credential theft. The article traces incidents from the xz-utils backdoor to self-propagating npm worms, explains how deep dependency trees magnify risk, and outlines immediate steps—pinning versions, auditing dependencies and funding maintainers—to stem the threat.
- The Jia Tan xz-utils backdoor took two years of patient, legitimate-looking contributions to slip in, and was only caught by accident when an engineer noticed a slight SSH slowdown.
- Supply-chain attacks have escalated fast: Shai-Hulud went from hijacking 500 npm packages to infecting 25,000 GitHub repos two months later, complete with a dead-man's-switch data wiper.
- Nation-state actors are now directly involved—North Korea's Sapphire Sleet poisoned Axios (70M weekly downloads) with a RAT, and 1,700 malicious packages across npm, PyPI, Go and Rust have been tied to North Korean groups.
- A typical Node.js app pulls in 800–1,500 transitive dependencies (vs. 40 direct ones), meaning most compromises hit projects three or four layers deep where developers have zero visibility.