# Socket Weekly: AI Industry Backs Open Weights, 53 Slopsquatting…

Canonical: https://brew.new/browse/templates/email/pt1_k97t07jq0bxhqpqbms5zfp8xan8e4g4y

Brand: socket.dev
Category: newsletter

![Preview of Socket Weekly: AI Industry Backs Open Weights, 53 Slopsquatting…](https://cdn.brew.new/email-preview-f4c6489ccd6d4bd6-tracking_r57nnzsfqnpbsk89k7r7zvefy58dtdc3-1789057650027.png)

## Email content

socket-weekly-new-header

Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.

TOP STORY

The AI Industry Is Betting on Open Weights

Fifty companies, from NVIDIA and Microsoft to Mistral and Hugging Face, signed an open letter urging Washington not to restrict open-weight AI. They have a case: Kimi K3 just passed Claude Fable 5 to take #1 in the Frontend Code Arena, months after the US government pulled Fable offline worldwide days after its launch. The letter makes the case on cost, competition, and sovereignty, but its strongest claim is that openness makes AI more secure, since closed models can be breached or fail in ways outsiders cannot detect.

MORE NEWS

Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign

Attackers planted malicious workflow files across ten compromised repositories, turning GitHub-hosted runners into disposable infrastructure to exploit a cPanel and WHM authentication bypass and steal server credentials. Installing the packages does nothing, execution only fires on a push, and one identifier surfaced roughly 15,000 matching workflow files across unrelated repos.

New Study Identifies 53 Slopsquatting Targets Across 5 Frontier LLMs

Independent research across nearly 200,000 code-generation responses found Claude, GPT, Gemini, and DeepSeek all inventing the same nonexistent package names, 53 of which are still registrable on PyPI and npm. One malicious registration could reach developers on any of those tools.users.

MORE WORTH READING

Dependabot version updates introduce default package cooldown

You shouldn't trust Trusted Publishing

Open Models and Open Weights Are Foundational to Secure AI

Fake Corepack Site Distributes Infostealer and Proxyware to Developers

OpenAI’s accidental cyberattack against Hugging Face is science fiction that happened

X

512x512-logo-27148

LinkedIn

bluesky

Socket Inc.

Secure your supply chain. Ship with confidence.

2810 N Church St., Suite 71517, Wilmington,DE, 19802

Book a Demo • Unsubscribe

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97t07jq0bxhqpqbms5zfp8xan8e4g4y)

[Browse email designs](https://brew.new/browse/templates)
