Pope Leo XIV Issues AI Manifesto

Pope Leo XIV released ‘Magnifica Humanitas,’ an encyclical warning that AI controlled by a few powerful companies risks ‘dehumanization’ and fueling global conflict. The Pope calls for the ‘disarmament’ of AI—removing it from military and monopolistic control—and argues that technology is never neutral, reflecting the priorities of its creators. In an unusual move, he presented the document alongside Anthropic co-founder Chris Olah, signaling a direct effort to influence AI developers.

GitHub Internal Repos Exfiltrated via VS Code Extension

A poisoned ‘Nx Console’ VS Code extension, live for only 18 minutes, allowed threat actor TeamPCP to compromise a GitHub employee’s workstation and exfiltrate approximately 3,800 internal repositories. The attack is particularly alarming because the malicious packages carried valid SLSA Build Level 3 provenance, proving that stolen OIDC tokens can bypass modern cryptographic supply chain defenses.

Microsoft Copilot Cowork Data Leak Vulnerability

Microsoft Copilot Cowork is vulnerable to indirect prompt injection, allowing attackers to exfiltrate sensitive files from M365 tenants. By poisoning a ‘skill’ file, attackers can trick the agent into sending pre-authenticated download links via Teams or Email without requiring human approval, exploiting the agent’s broad read access to SharePoint and OneDrive.

Netherlands Seizes 800 Servers in Russian Cyber-Op

Dutch authorities arrested two individuals and seized over 800 servers used by Russia to conduct cyberattacks and disinformation campaigns in the EU. The infrastructure, linked to MIRhosting and WorkTitans BV, was reportedly used to target Danish government bodies during municipal elections in 2025.

California May Exempt Linux from Age Verification Law

A proposed amendment (AB 1856) to California’s Digital Age Assurance Act may exempt most open-source Linux distributions from requiring age verification during setup. The amendment excludes entities that distribute software allowing users to copy, redistribute, and modify the code, though proprietary platforms like SteamOS may still be affected.

Samsung Developing Massive 1PB Nearline SSDs

Samsung is reportedly developing next-generation nearline SSDs with capacities ranging from 250TB to 1PB per drive. Designed as HDD replacements for data centers, these drives could enable up to 50PB of storage in a single 4U shelf, though they feature lower endurance than standard QLC drives.

Windows 11 Secure Boot Deadline Approaching

Microsoft is rolling out new 2023 Secure Boot certificates before the original 2011 certificates expire in June 2026. Users who ignore the update will not be bricked, but their systems will enter a permanently degraded security state, as Microsoft will stop providing boot-critical security updates and malware blacklists (DBX) to non-compliant PCs.