CybersecuritySoftwareStartups

Critical Rust Library Flaw Impacts Python Package Manager Security

Security researchers have uncovered a significant vulnerability in a widely-used Rust library that affects Python’s uv package manager. The flaw enables attackers to hide malicious files in tar archives, posing supply chain threats.

Vulnerability Discovery and Mechanism

Security analysts at computing security firm Edera have identified a critical vulnerability in the popular async-tar Rust crate that impacts the uv Python package manager, according to their published findings. The vulnerability involves improper handling of tar archive headers that could allow attackers to conceal additional files within archives.

BusinessGovernmentTechnology

UK Regulator Targets Apple and Google Mobile Dominance with New Oversight Powers

The UK’s Competition and Markets Authority has placed Apple and Google under enhanced regulatory scrutiny for their mobile dominance. The decision could force changes to app store fees, browser choices, and payment systems affecting millions of users.

Enhanced Regulatory Scrutiny for Tech Giants

The UK’s competition watchdog has designated both Apple and Google as holding “strategic market status” for their mobile ecosystems, according to reports, marking a significant escalation in regulatory pressure on the tech giants. The Competition and Markets Authority (CMA) stated that both companies require stricter oversight due to their “substantial, entrenched” power in mobile operating systems, app stores, and browsers.

AIAutomationStartups

Uber Expands Gig Economy with AI Micro-Tasks for Drivers During Downtime

Uber is launching a new Work Hub platform that enables drivers to complete brief AI-related tasks while waiting for passengers. The initiative represents a significant expansion of the AI gig economy, offering micro-jobs for data labeling and content verification. According to reports, this move addresses both driver income gaps and AI’s ongoing need for human verification.

Uber Drivers to Supplement Income with AI Tasks

Uber is reportedly launching a new initiative that will enable its U.S. drivers to earn additional income by completing artificial intelligence-related micro-tasks during downtime between passenger rides, according to company announcements. The program, currently being tested in India before its planned U.S. rollout, represents Uber’s entry into the rapidly growing market for human-verified AI training data.