ChainDrop worm crawls into npm supply chain, evades standard defenses Researchers at Phylum have identified a new npm supply chain worm, dubbed ChainDrop, that evades standard defenses by using a multi-stage attack chain. The worm spreads through malicious packages and has been observed targeting developers, potentially compromising their systems and stealing credentials. MOST POPULAR AI https://beta.theregister.com/tag/ai - ai and ml Anthropic says text watermarking scheme relies on inconsequential words 'Shall I compare thee to a summer's afternoon' is the sort of thing this will make, and others look likely to adopt it - AI and ML DeepSeek's innovative harness treats everything as a plug-in Chinese AI labs keep moving forward while US labs play defense - SECURITY Autonomous AI attacks pose 'clear and present danger' to critical infrastructure Weaponized agents could turn digital intrusions into kinetic disasters, experts warn - off-prem Rent-a-GPU outfit Nebius promises rapid 1 GW powerup plan isn't nebulous And it'll jump through every financial hoop it can to get there - AI and ML Modular's Mojo programming language hits 1.0 milestone Developers await open source compiler release to dispel uncertainty following Qualcomm acquisition Infosec https://beta.theregister.com/security - Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more - Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more - Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included - Security EQT buys majority share in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified - Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career FOSS https://beta.theregister.com/tag/FOSS - FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash another Word up - GNOME can look like Windows – and Flashback can do it without extensions New 'Simple-taskbar' is an option, but there's a simpler, stabler way - A moment of silence, please, for the final release of Debian on x86-32 New Debian versions hit FOSSland in the form of 13.6 and 12.15 - Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websites Flaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide - Frame: A new X11 server – implemented directly in assembly Joins yserver, Phoenix, and of course XLibre – and outlier Arcan - Cinnamon 6.8 will support Wayland – if you want it Next version of Linux Mint’s desktop has both kinds of display server