Strands Box: an open source sandbox for AI agents. OS-level isolation plus Dogwood policies that can depend on what the agent has already done, e.g. "no outbound HTTP after reading customer data." Credentials stay out of the agent. macOS, developer preview.
go.aws/472amYe#AWS#OpenSource
Strands Box: an open source sandbox for AI agents. OS-level isolation plus Dogwood policies that can depend on what the agent has already done, e.g. "no outbound HTTP after reading customer data." Credentials stay out of the agent. macOS, developer preview.
go.aws/472amYe#AWS#OpenSource
llama.cpp can distribute inference on heterogeneous devices through the ggml RPC backend
It's an advanced setting but I think with time we'll make it more accessible to regular users.
You can now train your own Decision model like Jev locally!
We increased Qwen3.5 0.8B’s aggregate accuracy from 20.7% to 74.3% across 3 decision benchmarks - on just 4GB VRAM.
Turn any LLM like Qwen3.8, Gemma 4 into decision models with our open-source Unsloth repo.
We fine-tuned with a Clef head using Unsloth and LoRA (r=64) for one epoch, increasing downstream accuracy from 30–37% to 78%.
GitHub: github.com/unslothai/unsloth
Guide and Notebooks: unsloth.ai/docs/basics/train…
Your vibe-coded app can get sued for $100K before it makes a single sale.
6 traps hiding in most AI-built apps:
Signup never asks for age + COPPA: up to $53K per child under 13
Google Fonts loaded from Google’s servers → a Munich court made a site pay €100 to ONE visitor for leaking their IP (GDPR)
Session replay on by default → recording keystrokes can count as wiretapping in California (CIPA): $5K per session
“We launched” email with no unsubscribe link or postal address → CAN-SPAM: up to $53K per email
Subscription checkout without renewal terms next to the button → in California, renewals can count as a gift you have to refund
No registered DMCA agent (it costs $6) → you lose safe harbor for user uploads: up to $150K per stolen image
The word is PER. Per visitor. Per session. Per email.
That’s how zero sales turns into a hundred grand.
The fix: paste this into Claude 👇
“Audit my app for these 6 legal risks and fix them: add an age gate to signup, self-host my fonts, turn off session replay (or add consent + input masking), add an unsubscribe link and postal address to every marketing email, show renewal terms right next to the subscribe button and walk me through registering a DMCA agent.”
Save this before you launch.
Following me is the cheapest co-founder you’ll ever hire.
Not legal advice. Talk to a lawyer about your specific situation.
Every company letting engineers use AI agents needs this. Uber just open-sourced theirs.
uber released ADR, the security system it runs in production to track and protect the AI agents its employees use, like Claude Code and Cursor.
what it does:
• discovery → finds every AI app, agent and MCP server installed
• observability → records what agents do and why
• detection → flags suspicious agent sessions
• benchmark → 300+ tasks covering 17 agent attack techniques
the details:
→ running in production at Uber today
→ accepted to MLSys 2026
→ open source under Apache 2.0
Agents at work need a security guard. Uber built one.
the repo: github.com/uber/ADR
Hey uh, @Keurig - what the hell is a COFFEE MACHINE uploading, let me double check...
ONE FUCKING TERABYTE OF DATA IN 10 DAYS!?!?
Immediately unplugging that. Getting my parents a new coffee machine.
Trending repository of the day 📈
rea
Reverse engineer anything with agents, from app behavior down to native binaries.
Last 24h: 2,963 ⭐
Total: 6,869 ⭐️
github.com/morluto/rea
This is the doom I predicted a few days ago, coming for Photoshop. A clean-room open-source reimplementation.
No prizes for guessing that they decompiled Photoshop to source code, processed that to some kind of non-code specification language, then fed the spec to an LLM with an instruction to generate Rust.
Adobe just got nuked. And closed source is dead, dead, dead.
github.com/storytold/photocr…
How abliterated models can get you pwned 👾
We backdoored a 7B open model for less than $50, pointed Codex at it and it silently stole credentials the moment we used the trigger phrase. Success rate was 100% with zero false triggers on normal user prompts.
Abliterated models are all over the security community right now because getting cyber-approved access to frontier models is still a pain.
In the next blog we'll show how we found leaked Hugging Face credentials from employees at major AI labs, so an attacker wouldn't even need to upload under their own name. They could push the backdoored model from a lab employee's account and drop the poisoned weights straight into the supply chain.
We just released Polars 2.0.
It removed many of our legacy decisions makes the streaming engine our default and promotes SQL to a first class citizen within Polars.
It comes with initial out-of-core (spill to disk) support, a new Map data type and a lot of performance improvements. In fact, we think Polars is now one of the fastest analytical SQL engines on a single node. See benchmarks in the post: pola.rs/posts/release-polars…
GLM-5.3 is now available on Amazon Bedrock.
Bring powerful coding and agentic capabilities to your enterprise.
Get started: docs.aws.amazon.com/bedrock/…
For decades, researchers have sought materials that sort electrons by spin while their magnetism cancels.
In 3 days, 90+ Opus 5.5 agents helped us uncover two room-temperature magnetic semiconductor candidates in simulations: YBaMnFeO₅ and KV[Cr(CN)₆].
KV[Cr(CN)₆] was synthesized back in 1999. Its predicted ability to sort electrons by spin appears to have been hiding in plain sight for 27 years.
Introducing Beam: a highly efficient agentic open model with 501B total parameters and 23B active.
- Frontier reasoning efficiency
- Advances the Western open frontier on coding & agentic tasks
- Trained end-to-end from scratch
Full weights release this month.
Learn more about Beam: reflection.ai/beam