Package-doctor is an open-source Python dependency scanner that identifies exploited and unmaintained packages, then prevents coding agents from adding vulnerable dependencies. It prioritizes vulnerabilities by exploitation risk and maintainer availability, integrating with CI/CD pipelines and Claude Code as a guardrail tool.
Google confirmed that a limited number of Pixel phones were exploited through CVE-2026-58704, a modem vulnerability allowing remote privilege escalation without user interaction. The flaw was patched in September 2026 security update and CISA designated it a known exploited vulnerability used in targeted attacks.
U.S. intelligence agencies reported Tuesday that top Chinese AI companies have systematically copied advanced American AI models like Claude, ChatGPT, Gemini, and Grok since 2024 through a practice called distillation. The FBI, NSA, and CISA identified six Chinese developers—DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI—as conducting large-scale distillation campaigns likely with Chinese government awareness. China's Foreign Ministry rejected the accusations, stating its AI development reflects technological self-reliance and called for cooperation rather than confrontation.