freiburg.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Ein Mastodon-Server für Freiburg und Umland betrieben durch den Verein freiburg.social e.V.: https://wir.freiburg.social

Server stats:

533
active users

#supplychain

6 posts6 participants0 posts today
Continued thread

Wenn es so schöne Fussgängerampeln mit Textansagen gibt, kann man diese Ansagen dann ändern? Das müssen sich Unbekannte im Silicon Valley gedacht haben, bevor sie die Ampelansagen durch angebliche Texte von Tech-Milliardären ersetzten. Die Stadt reagierte und hat die ganze Funktion vorerst deaktiviert.

Mit KI erzeugter Programmcode bezieht sich manchmal auf Module, die es gar nicht gibt. Findige Angreifer haben nun begonnen, derartige Module zu publizieren.
#SupplyChain
dnip.ch/2025/04/15/dnip-briefi

Erstellt mit ChatGPT 4o
Das Netz ist politisch · DNIP Briefing #20: Sitzungsprotokoll mal anders - Das Netz ist politischDie Redaktion präsentiert jeden Dienstag die Geschichten, die sie bewegt, aufgerüttelt oder zum Nachdenken angeregt hat.

New supply chain attacks called "slopsquatting" in AI coding attempts to leverage AI models tendency to hallucinate non-existent package names.

Research indicates roughly 20% of the sampled Python and JavaScript code samples recommended packages didn't exist.

bleepingcomputer.com/news/secu #slopsquatting #hallucinations #AI #coding #supplychain #python #javascript #cybersecurity

🚨 AI Code Assistants: A Double-Edged Sword? 🚨

AI-powered coding tools are revolutionizing development workflows, but they come with hidden dangers:

🔹 Hallucinated Dependencies: AI suggests packages that don’t exist.
🔹 Slopsquatting Attacks: Malicious actors register these fake packages, leading to potential security breaches.
🔹 Automated Installation Risks: Some AI agents might auto-install these without developer awareness.
🔹 False Legitimacy: AI-generated summaries can falsely validate these malicious packages.

🛡️ Stay Vigilant: Always double-check AI-generated code and dependencies. Trust, but verify.

#AI #CyberSecurity #DevSecOps #SupplyChain #SoftwareDevelopment
theregister.com/2025/04/12/ai_

The Register · LLMs can't stop making up software dependencies and sabotaging everythingBy Thomas Claburn

#Trump on Wednesday paused for 90 days many #tariffs but is not halting 25% tariffs on automotive imports & looming tariffs on #auto parts, drawing criticism from #Michigan #business & auto groups.

The #Detroit Regional Chamber & #MichiganAuto called on Trump to protect the automotive industry's complex international #SupplyChain framework from harmful fragmentation that weakens its global competitiveness.

#economy
reuters.com/business/autos-tra

Global #pharma shares plunge as #Trump doubles down on #tariff threat

Global drugmakers' #stocks dropped across the board after Trump reiterated plans for a "major" tariff on #pharmaceutical imports, threatening an interwoven global #SupplyChain, & as his country-specific reciprocal #tariffs took effect, leading to more pain in global markets.

#economy #inflation #recession #trumpcession #geopolitics
reuters.com/business/healthcar

Continued thread

So business aren’t planning to pay products for twice the price, they are trying to delay and wait as to not incur the huge tariff cost.

The good planners imported a lot ahead in the last few months, that’s why the US economy has been doing okay, but it’s now coming to a halt and it can only last so long before they run out of what they accumulated.

Americans are about to find what shortages are. They haven’t lived it since the 1970s oil crisis.

Covid shortages were small beer compared to what it’s coming

What’s being seen in the trade route bookings is that Chinese shipments are entirely cancelled or delayed for now. Volume is way way down.

Replied in thread

@ulrichkelber gibt es Informationen darüber, wie @zendis sich gegen -Attacken und Sicherheitslücken in den zugrundeliegenden -Lösungen von und wappnet, um zusätzlich zur auch die IT-Sicherheit der Systeme ausreichend sicherzustellen? Wie wird bei der Weiterenwicklung und Updates geprüft, damit kein Schadcode eingeschleust wird?

Replied in thread

#SundayShowdown

#TreasurySecretary #Bessent said on #MtP:

"The shutdown of the #SupplyChain during the #pandemic was a [warning] of what can happen when we don't produce everything we need."

It was destruction of the DOMESTIC Supply Chain that crashed the economy. IMPORTS SAVED US. Moving manufacturing to the U.S. wouldn't save us from another Supply Chain disruption.

IN FACT, putting #tariffs on imported SUPPLIES will do THE EXACT SAME THING! Get ready for ANOTHER Supply Chain crash. 🤦‍♂️

Continued thread

Bloomberg alerts sent on this:
*CANADA, MEXICO NOT SUBJECT TO RECIPROCAL TARIFFS FOR NOW
*US CONTINUES USMCA EXEMPTION FOR CANADA, MEXICO TARIFFS

BREAKING: Canada gets an exemption from Trump's baseline 10% tariffs, Bloomberg reports. At least for now, the existing tariff exemption for USMCA compliant goods will continue. (It's not immediately clear to me if Canadian autos will still get hit with the 25% tariff on foreign cars)

Average person will be 40% poorer if world warms by 4C
Experts say previous #economic models underestimated impact of #globalheating – as well as likely ‘cascading #supplychain disruptions’
Australian scientists study suggests average per person #GDP across the globe will be reduced by 16% even if warming is kept to 2C above pre-industrial levels. This is a much greater reduction than previous estimates, which found the reduction would be 1.4%.
theguardian.com/environment/20 #climate #climatechange

The Guardian · Average person will be 40% poorer if world warms by 4C, new research showsBy Graham Readfearn