
JAi-cool 🇫🇷🇱🇧
2.3K posts

JAi-cool 🇫🇷🇱🇧
@0xJacool
Bringing Sovereign AI to organizations with https://t.co/9JUTRuzxVn Creator of Sections Cloud Mentor @IncubTelecom









🚨🇫🇷 FLASH | Strasbourg : en voulant tester la fiabilité de ChatGPT, un homme voit le RAID intervenir chez lui. Ses messages de menaces ont été repérés par le FBI, qui a alerté la plateforme PHAROS. Le RAID est ensuite intervenu à son domicile pour l’interpeller.












New supply chain attack this time for npm axios, the most popular HTTP client library with 300M weekly downloads. Scanning my system I found a use imported from googleworkspace/cli from a few days ago when I was experimenting with gmail/gcal cli. The installed version (luckily) resolved to an unaffected 1.13.5, but the project dependency is not pinned, meaning that if I did this earlier today the code would have resolved to latest and I'd be pwned. It's possible to personally defend against these to some extent with local settings e.g. release-age constraints, or containers or etc, but I think ultimately the defaults of package management projects (pip, npm etc) have to change so that a single infection (usually luckily fairly temporary in nature due to security scanning) does not spread through users at random and at scale via unpinned dependencies. More comprehensive article: stepsecurity.io/blog/axios-com…






Every large company will eventually ban vibe-coding. Vibe-coding is now generating as much technical debt as 10 regular developers in half the time. Vibe-coding is awesome for a first draft, but you can't expect to push AI slop to production and not destroy your software over time. Producing code is no longer a bottleneck. Testing that code, debugging it, monitoring it in production, and fixing it when it breaks is where everyone is spending their time. We've 10x'd the speed of writing code, but we are still in the Stone Age with everything that happens after the code is written. Here is a very cool tool tackling this: You can build "AI Production Engineers" using PlayerZero and make them work for you. These are agents that do this: • Simulate how your code will work in production • Diagnose issues when they happen • Learn from every incident so it doesn't happen again This is pretty awesome! These agents simulate code behavior against real production data. They use actual customer behavior, historical incidents, and edge cases without writing a single test script. When something breaks, the agent traces the issue to the exact line of code and PR, generates the fix, and routes it to the right engineer. And every bug these agents solve serves as training data to improve the system. Here is a link to check them out: playerzero.ai/?utm_campaign=… Thanks to the Player Zero team for partnering with me on this post.

This is Israel today. Using only an emoji, tell me how you feel seeing Israel like this?



