Terabytes of credentials belonging to some of the world's largest organizations were exposed in a supply chain attack on LiteLLM, an open source tool that simplifies AI driven software development, Ars Technica reported. Security firms CloudSEK and Hudson Rock disclosed the breach Tuesday and Wednesday. CloudSEK said it found cloud keys, repository tokens, SSH keys and AI provider keys that could give attackers access to more than 2,500 organizations, among them Microsoft, Amazon and Cisco. Two compromised versions of LiteLLM sat on the Python Package Index, the official repository for Python software, for about 40 minutes in March, long enough for automated build pipelines to install them and keep leaking credentials for months afterward. "I've confirmed the data is legit by the way, multiple victim orgs," independent security researcher Kevin Beaumont said.
Read at Ars Technica ↗ • Read at CloudSEK ↗
A paper published in Nature characterizes AI agents along four dimensions: autonomy, efficacy, goal complexity and generality, and proposes gradations within each. The authors said each dimension raises distinct questions for the design, operation and governance of these systems, and that the resulting "agentic profiles" can guide developers, policymakers and the public. The profiles span classes of agent from narrow task specific assistants to highly autonomous general purpose systems.
Read at Nature ↗
CentOS and Rocky Linux founder Gregory Kurtzer launched OpenWALDO, short for Open Weights, Artifacts, Licenses, Data, Origins, a project to build a shared open source AI training dataset that anyone can contribute to, The Register reported. Kurtzer said even downloadable open weight models ship with closed training data that users cannot inspect, alongside other limits that keep them from being open source. The effort is funded by CIQ, Kurtzer's AI infrastructure company, which also sponsors Rocky Linux. The dataset holds 167 billion transparent tokens, against the trillions used by the largest AI developers.
Read at The Register ↗
Commercial AI detectors used for academic integrity cannot distinguish AI editing from fully AI written drafts and may treat both as misconduct, according to a controlled study posted to arXiv. The authors tested published English abstracts across four domains, comparing 2013 to 2015 against 2023 to 2025. Pangram and GPTZero flagged light "refine abstract only" edits, a proxy for guideline compliant AI assistance, 64% to 80% of the time, against 9% to 15% for unmodified recent originals. After processing through the Undetectable AI humanizer, a tool that rewrites AI text to read as human, fewer than 4% of AI labeled rewrites stayed flagged. The authors conclude that honest AI editing carries a higher sanction risk than humanizer assisted evasion, and that detector scores should not serve as standalone misconduct evidence.
Read at arXiv ↗