Sean Gartland
16.3K posts

Sean Gartland
@SeanKaveh
Product @offerlabHQ | Founder, Pocketsomm | Wine enthusiast (WSET 3) | Ex-ESPN, Rotten Tomatoes

We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.


My Apple Car.



The most famous salad in Las Vegas is Golden Steer's tableside Caesar featuring dressing made from scratch! $21 per person with a 2 order minimum. 📍308 W Sahara

Imagine every pixel on your screen, streamed live directly from a model. No HTML, no layout engine, no code. Just exactly what you want to see. @eddiejiao_obj, @drewocarr and I built a prototype to see how this could actually work, and set out to make it real. We're calling it Flipbook. (1/5)

Claude can now connect to more of the apps you use outside of work, including @Tripadvisor, @bookingcom, @resy, @Instacart, @Spotify, @audible_com, @AllTrails, @thumbtack, Intuit @turbotax, and more.


Build and deploy your agents through the Claude Console, Claude Code, or our new CLI: platform.claude.com/workspaces/def… Read more on the blog: claude.com/blog/claude-ma…



Mythos Preview seems to be the best-aligned model out there on basically every measure we have. But it also likely poses more misalignment risk than any model we’ve used: Its new capabilities significantly increase the risk from any bad behavior. 🧵

Glasswing is possibly the most consequential event in the AI industry I've seen up close since joining Anthropic almost 3 years ago. It feels like we're at a turning point in history.

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.










