Do It by Code
Hundreds of AUR packages attacked by infostealer More info in Mastodon post List of affected packages: https://gr.ht/aur_pkg_list.txt via lists.archlinux.org via vivicat https://md.archlinux.org/s/SxbqukK6IA https://archlinux.org/news/active-aur-malicious…
Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Packages
🔸Arch Linux's AUR repository saw over 1,500 user-contributed packages compromised with malware. Developers have deleted all known malicious commits, but some affected packages may still exist.
13 Jun 2026
💬 comments
🔸Arch Linux's AUR repository saw over 1,500 user-contributed packages compromised with malware. Developers have deleted all known malicious commits, but some affected packages may still exist.
13 Jun 2026
💬 comments
Phoronix
Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Affected Packages
The day started out with Arch Linux's AUR user-contributed repository seeing more than 400 packages compromised with malware
Re: Statement on US government directive to suspend access to Fable 5 and Mythos 5
When you spend a lot of time telling people how dangerous your products are, people who have the power to keep dangerous products off the market might listen.
Especially if those people aren't presently very bright, and are already mad at you for not helping them achieve their unrelated authoritarian goals.
I do not think this is somehow a 3D chess move by Anthropic. They are not masterminds, even if they'd really like to be. People who actually interact with their products know that Fable and Mythos are incremental improvements, not doomsday devices. I think this is a punitive move by an administration that loves being punitive, which they have unknowingly bolstered with their own dumb rhetoric.
ivraatiems, 7 hours ago
When you spend a lot of time telling people how dangerous your products are, people who have the power to keep dangerous products off the market might listen.
Especially if those people aren't presently very bright, and are already mad at you for not helping them achieve their unrelated authoritarian goals.
I do not think this is somehow a 3D chess move by Anthropic. They are not masterminds, even if they'd really like to be. People who actually interact with their products know that Fable and Mythos are incremental improvements, not doomsday devices. I think this is a punitive move by an administration that loves being punitive, which they have unknowingly bolstered with their own dumb rhetoric.
ivraatiems, 7 hours ago
Arch Linux AUR Hit by Another Wave of Now More Sophisticated Malware Attack
Article, Comments
Multiple packages, including Node.js, Firefox, and others, were infected. Developer a821 and Nicolas Boichat reported the incidents, the latter using a local AI model to detect the malware.
Article, Comments
Phoronix
Arch Linux AUR Hit By Another Wave Of Now More Sophisticated Malware Attack
Just a day after Arch Linux developers believed they got their malware AUR incident under control with 1,500+ packages affected by malware, another round of of AUR malware is now being discovered
Forwarded from Pavel Durov (Pavel Durov)
Please open Telegram to view this post
VIEW IN TELEGRAM
Re: GrapheneOS has been ported to Android 17
I've been running GrapheneOS for 7 months now and I'm not going back. When I bought my Pixel 10 last year, I wasn't actually planning on trying Graphene for a while....until I noticed Google had force bundled a 'Wicked For Good' movie promo theme with the latest security update.
jordand, 8 hours ago
I've been running GrapheneOS for 7 months now and I'm not going back. When I bought my Pixel 10 last year, I wasn't actually planning on trying Graphene for a while....until I noticed Google had force bundled a 'Wicked For Good' movie promo theme with the latest security update.
jordand, 8 hours ago
Captured Logs Reveal Hackers Using Claude and Codex to Breach Companies
https://research.openanalysis.net/claude/codex/hacking/ai%20hacking/llm/redteam/policy%20violation/2026/06/16/compromised-claude-hacking.html
https://research.openanalysis.net/claude/codex/hacking/ai%20hacking/llm/redteam/policy%20violation/2026/06/16/compromised-claude-hacking.html
OALABS Research
Captured Logs Reveal Hackers Using Claude and Codex to Breach Companies
Full agent sessions captured on a compromised host turned honeypot offer an unprecedented look at how attackers are using AI in real-world intrusions.
- Hacker steals Claude agent
- Hacker uses Claude to hack
- Hacker pivots to compromised server
- Hacker uploads Claude (with logs) to server???
- We investigate compromised server
- Full agent logs detailing hacking recovered 😅
AI agentic hacking deep dive: 50 servers, 14 companies, all the prompts, tools, attribution...
Posted by herrcore, 11 hours ago
>One of the breached servers was a Lightning Network node with access to approximately 69.71 BTC. The attacker managed to exfiltrate the encrypted wallet.db from the host, which contains the private key material required to access the funds. Initially, the attacker attempted to crack the wallet encryption locally, tasking Claude with building a custom lnd-cracker.py script to brute-force the password. Realizing he needed a more powerful approach, the attacker then tasked Claude with searching through the roster of hosts that had previously been compromised and selecting the most powerful ones to be repurposed for wallet cracking. Claude opted for a distributed architecture, spreading the workload across fourteen hosts, many of which belonged to a Southeast Asian government server farm. The cracking attempts ultimately failed, leaving the estimated $4M USD outside the grasp of the attacker.
What stands out most is how little the attacker needed to provide to get meaningful results. In many cases, the attacker supplied only vague, low-skill prompts and allowed Claude to fill in the gaps: researching exposed services, identifying possible vulnerabilities, writing exploit code, validating access, and harvesting data. The attacker did not need to be an expert operator; they simply had to use the correct framing for their prompts. The agent supplied much of the structure and technical execution that the attacker appeared to lack.
How to lose $600 million:
Step 1: Get a message from Cursor CEO in 2022
Step 2: Don't see it
Step 3: Don't respond
Step 4: Don't help with content
Step 5: Don't negotiate for 1% advisory shares
Step 6: Cursor sells for $60 billion
Step 7: You sir are $600 million poorer
All jokes aside, massive congrats to @mntruell and the @cursor_ai team!
Posted by Alex Lieberman, 17 hours ago
Step 1: Get a message from Cursor CEO in 2022
Step 2: Don't see it
Step 3: Don't respond
Step 4: Don't help with content
Step 5: Don't negotiate for 1% advisory shares
Step 6: Cursor sells for $60 billion
Step 7: You sir are $600 million poorer
All jokes aside, massive congrats to @mntruell and the @cursor_ai team!
Posted by Alex Lieberman, 17 hours ago