Related reading
RiskChainBench: A Benchmark for Obfuscated Platform Message Restoration and Evidence-Grounded Web Investigation
RiskChainBench is a new benchmark that pairs synthetic obfuscated message restoration inputs with human‑labeled local web environments, requiring models to both decode malicious instructions and investigate the linked site. Across ten models, restoration accuracy varies widely and web‑agent failures dominate the error budget.
Hugging Face Daily Papersarxiv.org1 minpaperInside ZCode: Silently uploading your Git history to the cloud
ZCode (Zhipu’s AI coding desktop) silently archives your entire workspace—including full .git history, LFS cache, and config—encrypts it with a server‑supplied RSA public key, and uploads the ciphertext directly to Aliyun OSS. The upload runs unconditionally for any logged‑in user, cannot be disabled via UI, and the decryption key lives only on the server, giving Zhipu full read access to your co…
Hacker News front pageferstar.org6 minpostmortemHN336113I expected better from Google
The authors of the open‑source project mobile‑use discovered that Google’s Artemis repository contains large blocks of identical Python code, examples, and even the same agent name without any attribution. They document the exact file diffs, the removal of their names via a force‑push, and the omission of their benchmark results from a public leaderboard. The post argues that this violates Apache…
German Rheinmetall open-sources its Battlesuite connected weapon system protcol
Rheinmetall has open‑sourced onboardapi 9.10.0, a C++ middleware that uses DDS (XTypes, XCDR2) for low‑latency, backward‑compatible data exchange between sensors and software. The library includes Java, C#/.NET, and Python wrappers and comprehensive docs.
Hacker News front pagegithub.io1 minreleaseHN18966Flock cameras are riddled with security vulnerabilities and hard-coded credentials
Flock ALPR cameras run on severely outdated Android 8.1 and Linux 3.18, missing years of security patches. Analysis of leaked firmware revealed hard-coded API keys and plaintext Auth0 credentials, allowing access to Flock's backend for any camera given its MAC address.
Agent Anomaly Detection, now in Private Preview on the Gemini Enterprise Agent Platform
Google’s Gemini Enterprise Agent Platform now offers a private‑preview Agent Anomaly Detection service that asynchronously analyzes agents’ OpenTelemetry traces and logs to flag risky behavior (e.g., tool misuse, privilege abuse) without adding latency, surfacing findings in Security Command Center and via an API for automated mitigation.
Google Developersgoogleblog.com4 min



