IRCNF

News

Breaking news and updates from the world of technology.

A poisoned PyPI package broke into AI training startup Mercor — and exposed 4TB of contractor data to Lapsus$
Security

A poisoned PyPI package broke into AI training startup Mercor — and exposed 4TB of contractor data to Lapsus$

Attackers linked to Lapsus$ executed a three-hop supply chain attack: they first compromised Trivy (an open-source vulnerability scanner), extracted CI/CD credentials from LiteLLM's build pipeline, then published malicious LiteLLM versions 1.82.7 and 1.82.8 to PyPI. Any AI system pulling those versions executed attacker-controlled code — and Mercor, a $10B AI training contractor serving OpenAI, Anthropic, Meta, and Google, was one of the victims. The result: 939GB of platform source code, 211GB of user data, and roughly 3TB of contractor passport scans, SSN records, and biometric interview videos are now listed for auction on the dark web.

Security Boulevard
security-breachsupply-chain-attack
Samsung's new QD-OLED panel delivers 4K at 360Hz — and 680Hz in competitive mode
Computers & Hardware

Samsung's new QD-OLED panel delivers 4K at 360Hz — and 680Hz in competitive mode

Samsung Display has unveiled a 31.5-inch QD-OLED panel at Computex 2026 that combines 4K (3840×2160) resolution with a 360Hz refresh rate — a combination previously considered unachievable on a self-emissive display. The technology behind it, called Penta Tandem, uses five stacked blue OLED layers instead of four. A Dual Mode drops to 1080p and pushes the refresh rate to 680Hz for competitive gaming. Actual monitors are expected in late 2026 or early 2027.

SamMobile
samsungcomputex-2026
CISA confirms SolarWinds Serv-U is under active attack — federal agencies have until June 19 to patch
Security

CISA confirms SolarWinds Serv-U is under active attack — federal agencies have until June 19 to patch

CISA has added CVE-2026-28318 to its Known Exploited Vulnerabilities catalog: an uncontrolled resource consumption flaw in SolarWinds Serv-U that lets unauthenticated attackers crash the service with a single crafted HTTP POST request. Federal agencies must patch to Serv-U 15.5.4 Hotfix 1 by June 19, 2026. Enterprise and government organizations outside the federal mandate should treat this as the same urgency.

BleepingComputer
cisavulnerability
Pentagon Clears Eight AI Giants for Classified Military Networks as Trump Signs NSPM-11
Artificial Intelligence

Pentagon Clears Eight AI Giants for Classified Military Networks as Trump Signs NSPM-11

The Defense Department has formally authorized Amazon, Google, Microsoft, OpenAI, SpaceX, NVIDIA, Reflection AI, and Oracle to deploy their artificial intelligence systems on America's most sensitive classified networks—while a new White House directive mandates all defense agencies adopt multi-vendor AI within 120 days.

ChatGPT Hits 1 Billion Monthly Users — Faster Than Any App in History
Artificial Intelligence

ChatGPT Hits 1 Billion Monthly Users — Faster Than Any App in History

OpenAI's ChatGPT crossed 1 billion global monthly active users in May 2026, outpacing TikTok, Instagram, and YouTube to claim the fastest consumer app growth ever recorded. The milestone lands as the AI assistant race intensifies.

The Next Web / Sensor Tower
OpenaiAnthropic