OpenAI details its response to the TanStack “Mini Shai-Hulud” supply chain attack, outlines protections taken to secure systems and signing certificates, and explains why macOS users must update OpenAI apps by June 12, 2026. Learn what happened, what was affected, and how OpenAI is strengthening defenses against evolving software supply chain threats.
OpenAI's adoption of SynthID watermarking signifies a shift towards unified AI content verification, enhancing trust in digital environments.
The post OpenAI adopts Google’s SynthID watermarking to build dual-layer AI content detection appeared first on Crypto Briefing.
The Big Four accounting and consulting firms — Deloitte, EY, KPMG, and PwC — advertised more AI-related job postings than traditional auditing positions in 2025, according to a new analysis by the Financial Times.
Nearly 7% of the firms’ job postings required AI expertise, compared to less than 2% in 2022 when OpenAI’s ChatGPT was launched. At the same time, auditing roles accounted for just under 3% of the postings last year. One of the firms also noted that a single job posting could, in some cases, apply to multiple positions.
According to the Times, the hiring trend shows how quickly AI is transforming the consulting and auditing industries. At the same time, the industry is trying to adapt to the fact that AI could undercut the need for certain junior positions.
Traditionally, consulting firms have been built on a “pyramid model” where many younger employees work under a smaller number of senior managers and partners. AI is now expected to automate parts of that workplace arrange
The world’s largest open-source registry, node package manager (npm), has been hit by another fast-moving malware attack, this time targeting the widely-used AntV enterprise data visualization tool.
Unlike last week’s high-profile npm attack on TanStack, which exploited a complex GitHub Actions cache poisoning weakness, the latest incident early on May 19 took the more conventional route of compromising the credentials of a high-value npm maintainer account.
According to analysis by SafeDep, the account in question, atool (i@hust.cc), which publishes the timeago.js JavaScript library, had rights to a large catalog of packages, including popular tools such as size-sensor (4.2 million downloads per month), echarts-for-react (3.8 million), @antv/scale (2.2 million), and timeago.js (1.15 million).
This privilege level allowed the attacker to publish at least 637 malicious versions across 317 different npm packages in a single 22-minute burst. This resulted in the compromise of a big chunk
Google is embracing the rise of AI coding agents with new Android tools designed to work with platforms like Claude Code and OpenAI’s Codex, allowing developers — or their AI assistants — to build Android apps faster from the command line.