Ekloge
Edition library

Archive

Daily

Weekly

THURSDAY
Edition D21JULY 9, 20267 top signals

Today’s lead · thehackernews.com

HalluSquatting can steer AI coding assistants into installing attacker-controlled packages

New research describes an attack that registers plausible package or plugin names that AI assistants hallucinate, then uses prompt injection in fetched content to get attacker code run on a user machine. The researchers frame the pattern as a path to botnet-scale compromise when agents can fetch, install, and execute with little review.

Top signals

6 more

Tools & repos

6 selected

Codex CLI 0.143.0

Codex CLI 0.143.0 turns remote plugins on by default, adds npm marketplace sources, supports macOS and Windows system proxies including PAC/WPAD, adds remote-control pairing, and improves MCP tool search. The release also adds Bedrock Sol, Terra, and Luna models with max reasoning support.

TencentDB Agent Memory

TencentDB Agent Memory provides fully local long-term memory for AI agents through a four-tier progressive pipeline with no external API dependency. It is relevant for teams experimenting with agent memory while keeping retrieval and storage inside their own environment.

ZML/LLMD

ZML released LLMD, a free inference server for running open-source LLMs across Nvidia, AMD, Google TPU, Apple Metal, and Intel Arc hardware. The pitch is fewer chip silos and more flexibility for teams optimizing inference cost and supply.

Glean AI Gateway

Glean AI Gateway is a platform layer for routing across 30+ proprietary and open-source models, including OpenAI, Claude, Gemini, and NVIDIA, while centralizing security, usage visibility, and cost controls. It is aimed at enterprises trying to decouple fast-changing AI interfaces from shared governance and model-routing infrastructure.

Blogs worth your time

7 reads

Tuning the harness, not the model: a Nemotron 3 Ultra playbook

LangChain walks through how it raised Nemotron 3 Ultra’s Deep Agents performance by changing prompts, tool descriptions, and middleware rather than model weights. The useful part is the eval-driven harness loop: screen cheaply, inspect traces, make one targeted change, re-run, and keep only fixes that generalize.

Native-speed vLLM transformers modeling backend

Hugging Face says the Transformers modeling backend in vLLM is now at or above native vLLM speed for many architectures. This reduces the porting tax for new model authors: implement cleanly in Transformers and get fast vLLM serving without waiting for a bespoke backend.

Vercel Agent: An agent you can let near production

Vercel describes its dashboard, GitHub, and CLI agent for investigating production incidents, reviewing PRs, and proposing fixes under its own identity. The practical signal is the control model: read-only by default, approval-gated actions, and production context from logs, metrics, and deployments.

Funding & acquisitions

7 moves

Prime Intellect

Prime Intellect raised a $130M Series A at a $1B valuation to expand its full stack for enterprise agent development. The platform combines compute access, reinforcement-learning tooling, and evaluation infrastructure so companies can train agentic systems without relying entirely on frontier labs.

SambaNova Systems

AI chip company SambaNova raised $1B at an $11B valuation in the first close of its Series F. The financing follows its SN50 chip launch and deepening Intel partnership for AI inference development.

Bengaluru radar

0 events

There are no relevant Bengaluru events to highlight today.