
npm has implemented a new security feature to protect high-impact accounts from potential takeover attacks. When changes like email updates or 2FA recovery code usage are detected, these accounts are temporarily placed in a 72-hour read-only mode. This measure prevents unauthorized actions such as publishing malicious packages. Users can still access and download packages during this period, ensuring continued availability. The account automatically returns to normal after the safeguard period, enhancing security without requiring user intervention.
Read original
© GitHub ChangelogGitHub's Copilot code review has become more efficient with the integration of built-in file exploration tools from the Copilot CLI and SDK. This update reduces review costs by about 20% without altering existing workflows, thanks to the use of tools like grep and rg. Additionally, users in the Medium analysis depth public preview can now benefit from improved configurability and visibility of review depth. Organizations can set default review levels, enhancing control over the review process. These changes make Copilot's code review more focused and cost-effective.
© GitHub Changelog
© WIRED AIAnthropic is navigating a complex path as both a leader in AI development and a proponent of AI safety. The company believes that by staying at the forefront of AI technology, it can better influence the safe deployment of AI systems. This dual approach is rooted in the belief that AI is an inevitable and transformative force, and Anthropic aims to be a responsible steward in this transition. Despite internal debates and external scrutiny, Anthropic maintains that its mission-driven approach is essential for managing AI's potential risks and benefits.
© TechCrunch AIGitHub has introduced a new feature for enterprises using Copilot CLI and VS Code, allowing them to enforce stricter control over plugin installations. By adding 'strictKnownMarketplaces' to the enterprise-managed settings, organizations can ensure that only plugins from approved marketplaces are installed. This move enhances security by preventing the installation of potentially untrusted plugins, aligning with enterprise governance strategies. This update is now in public preview, offering businesses a more secure and controlled development environment.
OpenAI's latest model, GPT 5.6, is being released under unusual circumstances due to pressure from the Trump administration. Instead of a public launch, the model will initially be shared only with select partners, with the government approving access on a case-by-case basis. This cautious approach mirrors Anthropic's strategy with its Claude Mythos model, reflecting growing concerns over the potential misuse of powerful AI technologies. The administration's involvement marks a shift towards more federal oversight in AI development, highlighting the delicate balance between innovation and safety.