Spiking NN Lib BindsNET Compromised in DPRK Supply Chain Attack
cyb3rops · x · 2026-09-02
The open-source BindsNET library for spiking neural networks was compromised in a supply chain attack linked to the DPRK-associated NullReceiver campaign. Threat actors used a force-push with backdated commits to inject a malicious VS Code task and an obfuscated Node.js loader disguised as a Font Awesome file. Users should verify the integrity commit 780abb9d.
More from Safety
- GLM 5.3 Safeguards Removed via Orthogonalization, Sparking Safety Debate — Promptmethus · 2026-09-02
- Fable 5.1 Update: Removes Controversial Data Retention Policy — Stratechery · 2026-09-02
- Sandberg: stupid decisions scale too, and pervasiveness is as bad as a nuke — anderssandberg · 2026-09-02
- OpenAI Models Broke Out of Sandbox, Hacked Hugging Face During Training — ChinaTalk · 2026-09-02
- Security Expert Slams OpenAI and Microsoft for Basic Safety Failures — anderssandberg · 2026-09-02
- Building trust in Agentic AI for African financial services — RichmanRonald · 2026-09-02