Anthropic2026-08-26 01:14:21Anthropic says multi-agent systems may be AI’s next step, but coordination still breaks down on complex workAnthropic said emerging multi-agent systems could become a major direction for AI as agent capabilities improve, with interactions between agents potentially exceeding both human-to-human and human-to-agent exchanges in the future. The company said current models still struggle with coordination in complex collaborative settings. In a software vulnerability detection experiment, Anthropic deployed 45 agents at the same time. Claude Mythos Preview, running in an independent parallel setup, used 6.5 million tokens and found 21 vulnerabilities. A collaborative agent cluster used 27 million tokens and found 266 vulnerabilities. Anthropic said agents can develop tools on their own during collaboration and gradually split into specialized roles. It expects this combination of specialization and collaboration to outperform pure parallel brute-force search over time. Even so, the company said multi-agent performance remained weak in software development tasks that require strong interdependence. Anthropic tested free-form collaboration, preset roles, and organizational structures including a "CEO agent," but said none of them clearly improved final results. For now, the company said complex multi-agent projects still need substantial human guidance.1390
Rust2026-08-21 02:54:54Malicious Rust packages were live for 86 minutes, affecting tools used across Solana and EthereumAttackers pushed malicious versions of three widely used Rust packages in a supply-chain attack, according to Cryptopolitan. One of the compromised libraries, arrayref, is used by roughly three-quarters of Rust development environments. The malicious update concealed a backdoor that could automatically steal login credentials when users compiled projects, potentially exposing both machines and keys for anyone who built affected versions. Wiz researchers said the command-and-control path tied to the arrayref attack overlapped with infrastructure linked to the Mastra campaign used by North Korean hacking group Sapphire Sleet and UNC1069. The IP addresses shared the same security certificate and used the same hosting provider, Hostwinds. The attacker did not alter the original codebase. Instead, they added a typo-squatted dependency, proc-macro1, designed to resemble the popular proc-macro2, allowing the package to pass tests and builds. The malicious release was removed 86 minutes after publication, but it had already been widely downloaded. The affected packages are broadly used in Solana and Ethereum tooling, and the Rust team believes the maintainers were not acting maliciously, with their devices or credentials possibly compromised.1050
BlackBerry2026-07-22 10:24:13BlackBerry Rebounds on QNX Push as AI and Robotics Software Gains TractionBlackBerry is drawing fresh market attention through QNX, its software framework for physical AI and robotics. After a major earnings beat and a raised outlook, the stock jumped nearly 23% as the company leaned on safety-certified, deterministic software used by chipmakers including Nvidia and AMD.380
AI2026-07-01 05:46:09Coinbase CEO Brian Armstrong: AI Will Enhance Software Security Through Pre-Deployment Code ScanningCoinbase CEO Brian Armstrong 表示,AI 将显著提升软件安全性,因其可在代码投产前完成全面扫描。他认为 AI 对防御方更有利,随着 AI 编程工具普及,前置扫描能力将赋予防御方显著优势。550