
npm has announced a security update that restricts the use of granular access tokens configured to bypass two-factor authentication (2FA). These tokens will no longer be able to perform sensitive actions such as account management or package configuration without an interactive 2FA challenge. This change addresses a major security vulnerability that allowed attackers to exploit leaked tokens. By January 2027, these tokens will also lose direct publishing capabilities, requiring 2FA approval for actions. This update is part of npm's ongoing efforts to enhance security and reduce credential-based attack risks.
Read originalEarlier coverage that leads up to this article, and what followed. Lines connect each piece to the closest one after it, converging here.
GitHub Changelog · July 8, 2026 · Same story
GitHub Changelog · September 18, 2026 · Same story
© GitHub ChangelogGitHub quietly expanded its secret scanning partnership program to include Lovable Labs, Pydantic Services, and Supabase. This update means credentials from these popular development platforms are now automatically detected in public repositories, allowing the providers to revoke or rotate compromised keys before abuse occurs. For developers using Supabase or Lovable, this adds a critical layer of automated security hygiene without requiring manual configuration. It reflects GitHub's ongoing effort to integrate directly with the modern AI and database tooling stack that dominates current development workflows.
© GitHub ChangelogGitHub finally exposes Copilot code review to external automation via REST and GraphQL APIs, moving it from a manual UI action to an integrable pipeline step. This allows developers to trigger reviews directly from scripts or internal tools rather than relying on the web interface. Simultaneously, the default effort level shifts to Balanced, striking a middle ground between speed and depth for most repositories. While Lite remains available for those prioritizing raw throughput, the API access is the real win here, enabling true CI/CD integration for automated code quality checks.
© GitHub Changelognpm is tightening security on its trusted publishing feature by imposing a strict 48-hour expiration window for unvalidated configurations. This change directly targets supply chain risks where repository ownership changes could hijack trust relationships before they are fully vetted. Once a configuration successfully publishes, it becomes permanent, but any shift in project identity forces a fresh validation cycle. Additionally, tokens from GitHub Actions issue_comment events are now blocked, pushing developers toward safer triggers like push or release. This is a necessary hardening of the npm ecosystem that prioritizes security over convenience.
Healthcare remains the final frontier for voice AI, and Vocca’s $20 million raise signals serious capital flowing into automating high-stakes phone interactions. Unlike generic assistants, this funding targets the messy reality of patient scheduling and triage, where accuracy and empathy are non-negotiable. It marks a shift from experimental chatbots to deployed voice agents handling critical administrative workflows. The market is watching to see if specialized vertical models can outperform generalist APIs in regulated environments.
Hadrian has secured $40 million to defend against the rising tide of AI-powered cyberattacks. This funding signals a critical pivot in cybersecurity: as attackers leverage generative models to craft sophisticated phishing and malware, defenders must adopt equally advanced AI tools to keep pace. The investment validates the urgent need for automated, intelligent threat detection systems that can operate at machine speed. For security teams, this means the era of manual rule-based defense is ending, replaced by adaptive AI counters.
© The Verge AIOpenAI’s aggressive push into mathematics has triggered a severe reputational crisis within the academic community. After claiming solutions to major problems like Navier-Stokes using massive agent swarms, researchers accused the lab of unethical data practices and scooping peers. The company’s response—a new advisory panel—has been met with skepticism rather than relief. This exposes a fundamental clash between Silicon Valley’s speed-first culture and academia’s norms of transparency and collaboration. The real story isn't just the math; it's the institutional friction caused by AI labs treating research as a race. KleidiAI on Apple Silicon now compiles in default, meaning every M-series machine gets ARM-tuned GEMM kernels for free. ROCm 7.2 added as a default build narrows the AMD/CUDA gap visibly. There's no new model and no new quantization here — just llama.cpp quietly becoming the inference runtime for everyone who isn't on NVIDIA.