12 place 0 fresh

22 Valid certificates, stolen accounts: how attackers broke npm's last trust signal

VentureBeat
VentureBeat 1 place · today 18:21 EDT

On May 19, 633 malicious npm package versions passed Sigstore provenance verification. They were cleared by the system because the attacker had generated valid signing certificates from a compromised maintainer account.Sigstore worked exactly as designed: it verified the package was built in a CI environment, confirmed a valid certificate was issued, and recorded everything in the transparency log. What it cannot do is determine whether the person holding the credentials authorized the publish — and that ga

To see detailed statistics for the news please log in »

Read the original

Add your comment
You must be logged in with Facebook to read and write comments.

A newsletter a day!

You may get 10 most important news around midday in daily newsletter. Press the button and we will send you the most important news only, no spam attached.

or register

LIKE us on Facebook so you won't miss the most important news of the day!

News from the same source
VentureBeat VentureBeat
Silicon Valley
George Avalos @ Silicon Valley 1 place · 02/07/2106 01:28 EDT

Newark apartment complex bought for much less than prior value

An East Bay apartment complex has been bought at a price that's well below its prior value. Read more ›

0

🔮
22.05.2026 ♌︎ Dear Lions! Today promises to be a rich and vibrant day in the realm of... Read more ›
Silicon Valley
George Avalos @ Silicon Valley 2 place · 02/07/2106 01:28 EDT

PG&E buys San Jose building to bolster South Bay operations

A PG&E Corp. unit has bought a San Jose building in a move to bolster the utility's South Bay operations. Read more ›

0

Slashdot
BeauHD @ Slashdot 1 place · today 20:30 EDT

SpaceX's Upgraded Starship V3 Launches For First Time

SpaceX's upgraded Starship V3 launched today from Starbase, Texas, for the first time, successfully deploying 22 dummy Starlink satellites and completing a planned fiery splashdown in the Indian Ocean. Reuters reports: The towering vehicle, consisting of the upper-stage Starship astronaut vessel stacked atop a Super Heavy booster rocket, blasted off at about 5:30 p.m. CT on Friday (2230 GMT) from SpaceX facilities in Starbase, Texas, on the Gulf of Mexico... Read more ›

0 newcommer

BetaKit
Douglas Soltys @ BetaKit 1 place · today 20:28 EDT

How Toronto Tech Week became Canada’s largest grassroots tech event

Co-directors Julia Konefal and Mell Truong explain how TTW went from experiment to 600 events in just two years. Read more ›

0 newcommer

GSMArena.com
GSMArena.com 1 place · today 20:02 EDT

Xiaomi 17 Max gets disassembled on video

Yesterday, Xiaomi announced the 17 Max, and today there's already a full teardown / disassembly video on YouTube showing all of its insides, courtesy of the Chinese channel WekiHome. While the video is in Chinese, we find YouTube's English language captions very good, so make sure you turn them on if you don't speak Chinese. The Xiaomi 17 Max is a rather surprising arrival, since it's the first Max in... Read more ›

0 fresh

The Information
Theo Wayt @ The Information 1 place · today 19:49 EDT

SpaceX held the first launch of the new version of its Starship spacecraft on Friday, successfully sending the craft from its Starbase Texas headquarters to space, where it deployed 22 test satellites. While the launch had some hitches, including an engine failure and an uncontrolled landing of ... Read more ›

0 fresh

SlashGear
SlashGear 1 place · today 19:45 EDT

Only 2 Of These US Fighter Jets Were Ever Built

Specialized aircraft is nothing new when it comes to military aviation, but this particular variant of an otherwise common plane only produced two aircraft. Read more ›

0 fresh

MacRumors
Eric Slivka @ MacRumors 1 place · today 19:26 EDT

New Apple or Beats Over-Ear Headphones Appear in FCC Database

The U.S. Federal Communications Commission has just published documents related to an apparently unreleased Apple product with model number A3577, with the product described as "Bluetooth over-ear headphones." These headphones do not appear to be the AirPods Max 2, which carry a model number of A3454, and there is little other information to go on, so it is unclear what these headphones are. Most of the documents that would reveal... Read more ›

0 fresh

CNET
Tyler Lacoma @ CNET 1 place · today 19:00 EDT

My Top Tricks for Installing Your First DIY Home Security System

My guide will show you how to plan, where to start and common mistakes to avoid with your security sensors. Read more ›

0 newcommer

TechRadar
TechRadar 3 place · today 19:00 EDT

NYT Connections hints and answers for Saturday, May 23 (game #1077)

Looking for NYT Connections answers and hints? Here's all you need to know to solve today's game, plus my commentary on the puzzles. Read more ›

0 fresh

TechRadar
TechRadar · today 19:00 EDT

NYT Strands hints and answers for Saturday, May 23 (game #811)

Looking for NYT Strands answers and hints? Here's all you need to know to solve today's game, including the spangram. Read more ›

0 fresh

Slashdot
BeauHD @ Slashdot 2 place · today 19:00 EDT

Google API Keys Remain Active After Deletion

Aikido Security found that deleted Google API keys can continue authenticating for a median of about 16 minutes and as long as 23 minutes, despite Google Cloud's UI claiming that once a key is deleted it can no longer make API requests. Dark Reading reports: Joe Leon, researcher at Belgian startup Aikido Security, recently analyzed the revocation window -- the time between a key's deletion and its last successful authentication... Read more ›

0 fresh

Business Insider
Katherine Tangalakis-Lippert @ Business Insider 1 place · today 18:44 EDT

Trump admin says new green card enforcement likely won't apply to those who provide an 'economic benefit'

A USCIS official said immigrants who provide an "economic benefit" are likely able to apply for a green card without returning to their home country. Read more ›

0 fresh

Business Insider
Katherine Li @ Business Insider 2 place · today 18:33 EDT

Google 'disregard' right now if you want to see where AI overviews fall short

Google's AI Overview is coming up with strange, chatbot-like responses to single-word searches instead of surfacing definitions. Read more ›

0 fresh

SlashGear
SlashGear 2 place · today 18:30 EDT

5 Tech Brands That Got Bought Up By Apple (And What Happened When They Did)

Apple may not own a stable of other companies, but that doesn't mean it avoids making acquisitions. The company's made some huge purchases over the years. Read more ›

0 fresh

The most popular news from the same source for the last week
VentureBeat VentureBeat
VentureBeat
VentureBeat 2 place · 05/16/2026 17:05 EDT

For AI systems to keep improving in knowledge work, they need either a reliable mechanism for autonomous self-improvement or human evaluators capable of catching errors and generating high-quality feedback. The industry has invested enormously in the first. It's giving almost no thought to what's happening to the second.I’d argue that we need to treat the human evaluation problem with just as much rigor and investment as we put into building... Read more ›

0

VentureBeat
VentureBeat 2 place · 05/17/2026 14:00 EDT

Retrieval-augmented generation (RAG) has become the de facto standard for grounding large language models (LLMs) in private data. The standard architecture — chunking documents, embedding them into a vector database, and retrieving top-k results via cosine similarity — is effective for unstructured semantic search.However, for enterprise domains characterized by highly interconnected data (supply chain, financial compliance, fraud detection), vector-only RAG often fails. It captures similarity but misses st Read more ›

0

VentureBeat
VentureBeat 3 place · 05/18/2026 12:23 EDT

Enterprises building and deploying agents have a problem: it’s taking their engineers too long to find out that an agent made a mistake, and the loop has continued to perpetuate, especially without a human at every step. LangSmith, the monitoring and evaluation platform from LangChain, launched a new capability in public beta that could make that issue more manageable. LangSmith Engine automates the entire chain by detecting production failures, diagnosing... Read more ›

0

VentureBeat
VentureBeat 2 place · 05/18/2026 13:16 EDT

Four supply-chain incidents hit OpenAI, Anthropic and Meta in 50 days: three adversary-driven attacks and one self-inflicted packaging failure. None targeted the model, and all four exposed the same gap: release pipelines, dependency hooks, CI runners, and packaging gates that no system card, AISI evaluation, or Gray Swan red-team exercise has ever scoped.On May 11, 2026, a self-propagating worm called Mini Shai-Hulud published 84 malicious package versions across 42 @tanstack/*... Read more ›

0

VentureBeat
VentureBeat · 05/18/2026 19:17 EDT

Redis built its name as the caching layer that kept web applications from collapsing under load. The problem it is targeting now has the same structure but is harder to solve: production AI agents failing not because the models are wrong, but because the data underneath them is scattered, stale and structured for humans rather than machines. Retrieval pipelines built for single queries cannot absorb the volume agents generate.The gap... Read more ›

0

VentureBeat
VentureBeat · 05/19/2026 12:20 EDT

Andrej Karpathy, the influential 39-year-old Slovak-Canadian AI researcher and one of the original 11 co-founders of OpenAI, and former head of Tesla's AI division, announced on Tuesday, May 19 that he's joining rival lab Anthropic.As Karpathy posted from his account on the social network X: "Personal update: I've joined Anthropic. I think the next few years at the frontier of LLMs will be especially formative. I am very excited to... Read more ›

0

VentureBeat
VentureBeat · 05/19/2026 13:37 EDT

Although it was already discovered by intrepid AI power users weeks ahead of the official unveiling today at Google's annual I/O developer conference, the company's new Gemini Omni model marks a significantly new paradigm in the wider AI and tech marketplace.That's because as its "omni" (from the Latin omne — meaning "all") prefix would suggest, this is Google's first truly native, multimodal model, that is "a model that can create... Read more ›

0

VentureBeat
VentureBeat · 05/19/2026 13:45 EDT

Google unveiled Gemini 3.5 Flash at its annual I/O developer conference on Tuesday, a new artificial intelligence model that the company says shatters what had become a seemingly iron law of the AI industry: that the smartest models must also be the slowest and most expensive to run.The model sits at the center of a sweeping set of announcements — from a video-generating "world model" called Gemini Omni to a... Read more ›

0

VentureBeat
VentureBeat · 05/19/2026 13:45 EDT

Google on Tuesday unveiled Gemini Spark, a personal AI agent designed to work around the clock — drafting emails, assembling documents, monitoring inboxes, and eventually making purchases — even when a user's laptop is closed and their phone is locked.The announcement, made at Google I/O 2026, is the company's most ambitious attempt yet to transform its AI assistant from a tool that answers questions into one that autonomously completes tasks.... Read more ›

0

VentureBeat
VentureBeat · 05/19/2026 13:45 EDT

For a quarter century, the Google search box has been one of the most recognizable interfaces in computing: a thin white rectangle, a blinking cursor, a few typed words, and a list of blue links. On Tuesday, Google will formally retire that paradigm.At its annual I/O developer conference, Google announced a sweeping redesign of the search box itself — the literal text field where billions of queries begin every day... Read more ›

0

Most popular sources

  • You see 718 news out of 718.
  • Sources 61 out of 61.
Tech Wire Asia 0%
The Fintech Times 0%
ReadWrite 0%
Vox 0%
Ubergizmo 0%
View sources »

LIKE us on Facebook so you won't miss the most important news of the day!

22.05.2026 20:41
Last update: 20:35 EDT.
News rating updated: 03:31.

What is Times42?

Times42 brings you the most popular news from tech news portals in real-time chart.
Read about us in FAQ section.


Times42 © 2026