Wednesday, August 27, 2025
Top story
s1ngularity: supply chain attack in Nx packages
A sophisticated supply chain attack exploited stolen npm credentials to inject malicious code that used LLMs to exfiltrate developer secrets. This signals a new class of AI-enabled threats targeting the infrastructure developers rely on—and exposes how AI tooling (Claude, Gemini, Q CLIs) can become attack surface in build pipelines.
The briefs
Cross-lab safety collaboration between two AI leaders sets a governance precedent and reveals real-world model vulnerabilities—critical for boards weighing AI deployment risk and regulatory compliance.
Vercel's new @vercel/slack-bolt adapter removes a critical technical barrier to building production Slack agents, enabling developers to deploy AI-powered workflows that were previously infeasible on serverless platforms.
OpenAI is systematizing AI alignment through public input, signaling a shift toward democratizing AI governance decisions and embedding diverse human values into model defaults—a strategic move that positions the company as addressing safety and legitimacy concerns while setting industry precedent for 'collective alignment' practices.