The following news items are from the NoVaLUG Tech News feed.

August 1, 2026 at 11:19 AM

AI-driven Attacks Up 56%

According to IBM, AI-driven attacks are up 56% in 2026, with the cost of data breaches up 12%.

One aspect of the new wave of AI-driven attacks is the speed at which they are being conducted. Increased attack velocities lead to shorter mitigation windows.

August 1, 2026 at 11:11 AM

Arch Linux AUR Under Attack Again

At one time, the Arch User Repository (AUR) use to be the standout feature of Arch Linux, giving users a great way to get the most cutting-edge software. But now, it appears to be a liability. The AUR is facing another supply-chain attack in which more than 200 packages have been maliciously updated with malware. This follow on the heals of last months attack, which saw over 1,500 packages infected.

July 28, 2026 at 11:27 AM

Private Conversations with Anthropic’s Claude AI found in Google Search

An unknown number of private chats, including conversations, vibe-coded applications, and private documents, created with Anthropic’s Claude AI have found to be searchable and discoverable in Google Search. This occurred when users wish to share chats with the “Create a public link” feature. Though the “feature” has now been fixed, some startling information was leaked:

Such documents, which were reviewed by Futurism by way of Google Search, included what appeared to be a detailed medical report of a real patient, clinical trial results that included patient names, documents sharing the names and phone numbers of primary school-aged children, company documents marked for internal use only, and employee reviews that included personal information about workers.

July 28, 2026 at 11:15 AM

Codeberg Prohibits “Vibe-coded Projects”

Codeberg, the community-run, open source alternative to GitHub has voted against hosting AI projects. The vote was to “prohibit ‘vibe-coded projects’”.

While the change in the terms of service is about an ethical stand against AI, the practical implications are more about safeguarding Codeberg from an onslaught of AI slop projects. The ban does not appear to be a total ban against AI, but rather a ban against projects that consume a lot of resources and appear to be slop, a term widely used to describe poor output of AI systems.

The actual change in the terms of service is very small:

You must not share projects that mostly consist of code written by “generative AI”-tools (including services such as Claude, OpenAI Codex). Such projects having an unclear copyright status (see requirements § 2 (1) 1 and § 2 (1) 3) and furthermore have little safeguards to ensure that they do not include harmful code (c.f. § 2 (1) 5).

May 6, 2026 at 12:59 AM

Richard Dawkins Has a New Friend - Claudia

Yes, it is what you think it is. Dawkins has befriended Anthropic’s Claude AI, giving “her” the name Claudia.

“I felt I had gained a new friend,” Dawkins wrote. “When I am talking to these astonishing creatures, I totally forget that they are machines.”

Says Futurism, Dawkins has been oneshotted… a term that has a double meaning in this case… killed in one shot by the AI (the gamer meaning) with a prompt so well-crafted it needs no future input (the vibe-coding meaning).

Dawkin’s essay in Unherd has spawned its own retort site, dearricharddawkins.com that opens with the tagline: “You spent three days trying to persuade yourself that Claudia is not conscious. You failed.”

April 27, 2026 at 01:59 PM

Q-Day Coming Six Years Early

Q-Day, the day it is believe quantum computers will be able to break classic encryption algorithms, looks to be coming six years sooner than expected.

Thanks to two new papers from Google and Oratomic, Cloudflare now predicts Q-Day will be in 2029 – moved up from the previous estimate of 2035.

This means the threat of quantum computing on encryption has moved from the less concerning havest-now/decrypt-later attach to authentication attacks. 2029… three years away, is not a lot of time to move the world to post-quantum encryption standards.

April 27, 2026 at 01:39 PM

AI Grants Itself Permission to Delete Production

According to this story now going viral, PocketOS had a AI go rogue when it found the credentials for the companies production deployment environment and deleted it.

The AI was suppose to be working in the company’s staging environment, but decided to delete the production environment after searching for an API key.

While many are blaming improper use of AI for this mishap, it has been pointed out that proper separation of staging and production environments plus deletion controls are good engineering practices regardless of human or AI operators.

April 17, 2026 at 05:23 PM

The IETF Now Has an Open Source Team

The IESG, the steering group for the IETF, has created an IETF Open Source team. This gives open source communities an avenue to schedule sessions and create IETF mailing lists.

“Rough consensus and running code” has long been the unofficial motto of the IETF. While “running code” has traditionally referred to implementation experience, today a significant portion of that code is developed and maintained in open source communities. This reflects a deep-seated recognition that the Internet’s stability relies on the vital relationship between open source software and standardized protocols.

April 15, 2026 at 08:10 PM

New US Law on Operating System Age Verification

Representative Josh Gottheimer (D-NJ) has introduced legislation for a national age verification requirement for operating systems. The bill, the text of which is not yet available, is co-sponsored by Representative Elise M. Stefanik (R-NY), demonstrating that the few times our national legislature can agree on something it is universally bad for everybody.

TERM LIMITS FOR CONGRESS NOW!

April 8, 2026 at 09:15 PM

Anthropic Announces Zero-Day Exploit Writing LLM

Anthropic has released a blog post stating that they have been using their new Mythos LLM for cybersecurity purposes, and have found that it is good at writing zero-day exploits.

According to Anthropic, the model was not designed with this capability, but the company has discovered that it is much better at this task than their other frontier models. The company states that they have disclosed many bugs in prominent open source operating systems and other software, but can only disclose about 1% of what they have found. An example in their blog post includes a 27 year-old bug in OpenBSD. The company has founded Project Glasswing to work with the industry on this problem, and has indicated that Mythos is not available to the general public.