Bonsai 27B fits on a phone. But does it run well?
PrismML compressed a 27B-class model into a phone-sized package, but kernels, memory overhead, and real device performance still determine whether it is practical.
npm 12 blocked --ignore-scripts bypasses. Jscrambler's compromise found another way in three days
A compromised Jscrambler npm release ran an infostealer from a preinstall hook, then moved the same payload into normal package code once npm 12 disabled scripts by default.
Claude Sonnet 5 launches as Anthropic restores Fable 5 and Mythos 5 after export controls are lifted
"Anthropic released Claude Sonnet 5 with steep introductory pricing, opened a Linux beta of Claude Desktop, launched Claude Science for researchers, and confirmed the Commerce Department has lifted export controls on Fable 5 and Mythos 5. Here's what each move means and why the timing matters.
How EU Chat Control turns child safety into surveillance infrastructure
The EU's fifth and final Chat Control trilogue is happening today, June 29. Here's what the encrypted messaging fight actually means for developers — and why age verification may be the part that sticks around longest.
Who gets to use GPT-5.6? That's now a government decision
GPT-5.6 and Mythos 5 both launched this week under government-coordinated access controls. What the new approval-first model means for teams building on frontier AI.
How Reddit trolls poisoned DuckDuckGo's AI search results
DuckDuckGo's AI answered a false-premise query about Trump dying of rabies. Here's how Reddit fiction became fake local news, became retrieval material, and landed as a confident AI answer.
LastPass confirms another customer data breach. Developers react: “Again?”
LastPass confirmed attackers accessed customer names, contact details, and CRM records after compromising Klue, a third-party sales intelligence tool. The vault is safe. Developers don't care.
An XSS in a low-priority app can compromise your entire Auth0 tenant
A cross-site scripting flaw in a minor internal app can chain with Auth0's default grant settings to reach other applications and APIs across the same tenant. Here's what the attack looks like and what to fix.