News linked to both this project and an event.
According to the research summary published by Rohan Paul, a large-scale study covering 207 GitHub projects and 1.02 million pull requests shows that introducing AI agent review can reduce code review time by 2.5 to 4.5 days/KLOC, but at the cost of declining review quality—in reviews involving AI, 78%~94% of PRs exhibit "review smells", higher than the 69%~76% in pure human reviews. The study points out that repeatedly assigning the same AI reviewer identity is the main reason leading to the decline in review diversity. Notably, projects that introduced LLM review extensively in the early stage did not achieve significant efficiency improvements.
According to an official announcement by the FCA, Anthropic will provide access to its suite of Claude products (including Claude Code and Claude Cowork) for the second batch of participating enterprises in the UK Financial Conduct Authority (FCA) "Super Sandbox" to accelerate their AI development process. A total of 21 institutions were selected for the second batch, including Scottish Widows, Money Advice Trust, and TrueLayer, among others. The number of applications this time increased by 51% compared to the first batch, with a total of 199 applications received. Participating enterprises will test AI solutions focusing on the following areas: agent payment security, fraud and financial crime detection, AI governance and accountability, financial inclusion for vulnerable groups, and compliance and business automation. Additionally, the FCA simultaneously launched the "Agentic Academy"—a 10-week AI specialized training program co-hosted by the FCA and the Centre for Finance, Technology and Entrepreneurship (CFTE). Participating enterprises will continue to have access to NayaOne digital sandbox infrastructure and NVIDIA accelerated computing resource support.
Odaily Odaily News Former White House Crypto and AI Director David Sacks posted on X, stating that the Chinese AI model Kimi K3 has topped the Frontier Code Arena front-end coding benchmark for the first time, and has reached or approached industry-leading levels in several other benchmark evaluations. This trend is noteworthy. While China's AI capabilities are rapidly improving, the US is mired in internal strife due to regulatory controversies. He criticized some US politicians and regulatory bodies for restricting new data center construction, increasing state-level regulatory requirements, and promoting the establishment of new federal agencies for pre-approval of frontier AI models.David Sacks warned that if the US slows down innovation due to excessive regulation, it may lose its competitive edge in the global AI race. "The US won the internet era through permissionless innovation, and it can win the AI era the same way; otherwise, we will see our leading position gradually erode." While AI development still needs to address safety risks, regulation should be precise, not hinder technological innovation. His remarks have once again sparked discussion on AI regulation, computing infrastructure construction, and the competitive landscape between China and the US.
据 Claude 官方 X 账号(@claudeai)发布,Claude 将在所有付费计划中延长 Fable 5 的访问权限,同时 Claude Code 每周使用限制维持高出 50% 的水平,上述政策延续至 7 月 19 日。官方补充说明,用户每周使用限额的一半可用于 Fable 5,超出后可通过使用积分继续访问,或切换至其他模型继续使用。
According to Malaysian media "New Straits Times", Malaysian police yesterday raided and shut down an illegal cryptocurrency mining den located in a warehouse at Pulau Indah, Port Klang Free Zone. During the raid, two foreign men aged 20 and 31 were detained, and mining equipment was seized. According to Malaysian law, this act violates the Penal Code and the Electricity Supply Act. If convicted, the two face ten years imprisonment and a fine of 100,000 Ringgit (approximately 24,500 USD).
David Sacks commented on X platform regarding an interview with Palantir CEO Alex Karp, stating that some traditional media interpreted it as an "emotional expression," but in reality, his views revealed the core issue of enterprise-grade AI security.Sacks stated that true enterprise AI security is not about abstract "AI alignment" research or government-style regulatory frameworks, but rather about enterprises having complete control over their own data, model weights, and computing infrastructure to prevent core intellectual assets from being absorbed by model vendors and turned into their own product advantages.He cited Karp's view, pointing out that what enterprise customers truly care about is having control over computing resources, models, and the data stack—ensuring that "ownership of the means of production" is not transferred.Sacks also cited the cooperation dispute between Figma and Anthropic as an example, noting that according to media reports, Anthropic "caught its partner off guard" when launching Claude Design. It was accused of encroaching into the application-layer domain occupied by its ecosystem partners during product expansion, leading to a shift in the value capture structure.He further pointed out that similar patterns have appeared in the expansion of product lines such as Claude Code and Claude Legal, where model capabilities extend upward into vertical application domains.Sacks believes that this trend indicates model vendors are transitioning from "foundation model providers" to "vertical application competitors," exposing enterprise customers to heightened risks of supplier lock-in. The essence of enterprise-grade AI security is not trusting the long-term promises of model vendors, but ensuring choice and control at the model layer to protect their own data and commercial "alpha."
According to security firm Blockaid (@blockaid_), its monitoring engine detected a front-end attack targeting the @gitcoin subdomain files[.]gitcoin[.]co, which contains malicious Eleven drainer code. Blockaid advises users to refrain from any interaction with this website while the issue is under investigation and remediation.
Odaily reports, with just over two weeks left before the U.S. Congress recesses on July 4th, senators are intensifying behind-the-scenes negotiations to push the CLARITY Act into a full Senate vote as soon as possible after the recess. Sources indicate that bipartisan senators will meet this week to discuss disputed clauses and related controversies. A key point is clarifying that non-custodial software developers “should not be held legally responsible for third-party use of their code unless they knowingly participate in illegal activities.” Previously, law enforcement agencies expressed concerns that this clause could weaken the ability to hold on-chain illegal activities accountable.Industry insiders point out that with the legislative window narrowing, the CLARITY Act is entering a critical phase. If it cannot advance by August, the process may be further delayed due to the election cycle. (Cryptoinamerica)
OpenAI has released the Frontier Governance Framework, systematically elaborating on how its AI safety and governance practices align with emerging regulatory requirements such as the California Frontier AI Transparency Act and the EU's General-Purpose AI Code of Conduct. Based on OpenAI's existing Preparedness Framework, this framework focuses on areas including cyberattacks, CBRN risks, harmful manipulation, loss of control risks, model reporting, security incident response, and external expert review. It also states that it will be continuously updated as model capabilities and the regulatory environment evolve.
GitHub posted on X platform, sharing more investigation details regarding the unauthorized access incident to its internal repositories. Yesterday, GitHub detected and contained an attack on an employee's device involving a malicious VS Code plugin. GitHub has removed the malicious plugin version, isolated the endpoint, and immediately initiated an incident response.Current assessment indicates that this activity only involved the theft of GitHub's internal repositories. The attackers' claim of approximately 3,800 repositories aligns with GitHub's investigation direction so far. GitHub has taken swift action to mitigate risks, rotating critical keys yesterday and overnight, and prioritizing the most impactful credentials. GitHub will continue analyzing logs, verifying key rotations, and monitoring subsequent activities. A more comprehensive report will be released upon completion of the investigation.
CZ posted on the X platform, stating that if there are API keys in your code, even if it's a private repository, now is the time to re-check and replace them.GitHub is currently investigating unauthorized access to its internal repositories. Although there is currently no evidence of an impact on customer information stored outside of GitHub’s internal repositories (such as customer enterprises, organizations, and repositories), it is closely monitoring subsequent activity related to the infrastructure.
Open-source data visualization tool Grafana announced on X that it recently discovered an unauthorized attacker had obtained a token granting access to Grafana Labs’ GitHub environment and used it to download code repositories. An investigation confirmed that no customer data or personal information was compromised, and no impact was found on customer systems or business operations. Forensic analysis was initiated immediately following the incident, and the source of the credential leak has been identified. Additional security measures have also been deployed to strengthen environmental protections. Additionally, Grafana disclosed that the attacker attempted to extort payment via ransomware to prevent public disclosure of the code repositories; however, the company ultimately decided not to pay the ransom. More details from the post-incident review will be shared after the investigation concludes.
the UK Parliamentary Commissioner for Standards is investigating MP Nigel Farage, leader of the Reform UK party, for allegedly failing to declare a £5 million (approximately $6.7 million) personal gift from Christopher Harborne, an investor in Tether.Christopher Harborne holds a 12% stake in Tether. Nigel Farage stated that the gift was received in 2024 before he announced his candidacy, and was used for personal security, therefore he was not obligated to declare it. According to the UK House of Commons Code of Conduct, new MPs must register interests received in the 12 months prior to their election. If found in violation, Nigel Farage could face penalties such as an apology, suspension, or expulsion from Parliament. (Decrypt)
According to Decrypt, Microsoft’s Threat Intelligence team disclosed that attackers had injected malicious code into Mistral AI packages distributed via the PyPI platform. This malicious code automatically executes when developers use the packages on Linux systems, downloading and running a malicious file named <code>transformers.pyz</code> in the background—the filename deliberately mimics the widely used Hugging Face Transformers library to evade detection. Microsoft noted that the malware primarily steals developers’ login credentials and access tokens. It avoids execution on Russian-language systems and includes logic that can randomly delete files on devices located in Israel or Iran. This attack is linked to the “Shai-Hulud” supply-chain campaign launched in September. In response, Mistral stated that its investigation found the attack originated from compromised developer devices, and its corporate infrastructure was not breached.
Odaily, the State Duma Committee on State Building and Legislation has recommended the first reading of a government bill imposing criminal liability for the illegal mining of cryptocurrencies. The bill adds a new Article 171.6 to the Criminal Code of the Russian Federation, holding individuals accountable for mining activities not included in the state register, as well as for providing mining infrastructure operation services without a license.If the illegal income or damages exceed 3.5 million rubles, the penalty could be a fine of up to 1.5 million rubles or up to two years of compulsory labor. If committed by an organized group or if the income exceeds 13 million rubles, the maximum fine rises to 2.5 million rubles, with a potential prison term of up to five years. In all violation cases, the mined cryptocurrencies will be confiscated. Currently, approximately 50,000 entities are engaged in mining in Russia, but only 1,489 are registered in the state register.
Bitget Wallet has launched a Labor Day QR code payment campaign, running from April 28 to May 7, further driving the adoption of stablecoin payments in everyday consumption and travel scenarios across the Asia-Pacific (APAC) region. During the campaign, users who complete offline QR code payments using USDT or USDC will receive RLUSD cashback for each transaction. From May 1 to May 7, Bitget Wallet will randomly select one paying user per day to receive an additional 1,000 RLUSD cashback. To lower the barrier to first-time usage, Bitget Wallet will also airdrop XRP to eligible participants—serving as the account reserve required to activate RLUSD withdrawals. RLUSD is a compliant U.S. dollar-pegged stablecoin issued by Ripple and regulated by the New York State Department of Financial Services (NYDFS). This campaign marks Bitget Wallet’s first real-world consumer application following its integration of the XRP Ledger (XRPL) mainnet and onboarding of the RLUSD payment ecosystem at the end of March—and represents a key milestone in advancing Bitget Wallet’s Everyday Finance strategy.
Odaily News Coin Center released a report stating that cryptocurrency software code constitutes "functional speech" and should be protected under the First Amendment of the U.S. Constitution. The organization argues that writing and publishing code is akin to writing a book or publishing a recipe; developers are "expressers and inventors," not custodians of assets or intermediaries.The report points out that the mere act of publishing and maintaining software should be strictly protected. However, when developers directly control user assets, execute transactions on behalf of users, or make decisions for users, they may enter a realm subject to regulation.This statement comes at a time of increasing regulatory controversy. Coin Center emphasized that developers should not be treated as financial intermediaries for the convenience of law enforcement. It calls for upholding existing free speech principles in the context of new technologies, rather than expanding the boundaries of criminal liability. (Cointelegraph)