OCaml patch probed in 10 minutes, Hugging Face adds Hindi to ASR leaderboard
Every URL the pipeline pulled into ranking for this issue — primary sources plus the supporting and contradicting findings each Researcher returned. Inline citations in the issue point back here.
Sources
Just a rumour of a bug is enough to find a security exploit these days simonwillison.net
Just a rumour of a bug is enough to find a security exploit these days Anil Madhavapeddy is a professor of computer science at Cambridge and a core maintainer of the OCaml compiler. In this somewhat alarming post he reports that security issues in OCaml projects are seeing evidence of attempted exploits within minutes of patches being shared for discussion: This normally takes a few days and a release within a week or two is reasonable. Within about ten minutes (!) this website was fielding pro…
The Open ASR Leaderboard Adds Its First Global South Language huggingface.co
References
Daniel Stenberg (curl) — ‘Death by a thousand slops’ daniel.haxx.se
By mid-2025, approximately 20% of all submissions were identified as AI slop, with the volume rising to a new report every 18 hours by early 2026… the ‘valid-rate’ of reports plummeted from 1-in-6 to roughly 1-in-20 or worse.
cyberpress.org — GitHub Advisory Database surge cyberpress.org
GitHub’s Advisory Database published 1,560 reviewed advisories in May 2026 — more than five times its historical monthly average — while inflow exceeded 6,000 advisory decisions per month.
TechRadar — GitHub restructures bug bounty (July 2026) techradar.com
GitHub restructured its bug bounty program into a two-tier system (public and private) to prioritize high-signal reports from ‘VIP researchers’.
ai-tldr.dev / HN skeptics on cohttp PR 1145 ai-tldr.dev
Dissenting commenters argued that the recorded probes might have been ‘coincidental noise’ from automated script-kiddie scanners that constantly spray common path traversal payloads… path traversal is a ‘classic’ flaw that does not require sophisticated AI to detect.
Anil Madhavapeddy — ‘antibotty’ / microupdate proposal anil.recoil.org
Deploying fast-propagating ‘inoculation rules’ — expressed in a safe DSL — directly to network enforcement points like MirageOS unikernel gateways… can drop malicious traffic within seconds of a vulnerability being identified, bypassing the slow process of full software recompilation.
ZeroPath blog — 170 valid bugs in curl zeropath.com
In late 2025, the tool ZeroPath used AI to identify 170 verified issues in curl, ranging from C logic errors to RFC compliance bugs, receiving praise from Stenberg for its quality.
AI4Bharat Vistaar (GitHub) github.com
On the Kathbath-Hindi ‘known’ test set, IndicWhisper reaches a WER as low as 10.3%; on the GramVaani spontaneous telephone set the same model’s WER jumps to 26.8%.
IndicVoices (ResearchGate) researchgate.net
IndicVoices already provides multi-reference transcriptions and dialectal metadata for 22 Indian languages, positioning Monsoon as an evaluation-focused extension of a broader inclusive-dataset lineage.
arXiv (OIWER methodology paper) arxiv.org
OIWER reduces reported error rates by ~6.3 points on average and narrows the perceived Gemini-vs-Canary gap from 18.1 to 11.5 WER points, aligning 4.9 points closer to human judgment than WER-SN.
Tracxn — Josh Talks / Voice Arena tracxn.com
Voice Arena operates under Josh Talks AI (founders Shobhit Banga and Supriya Paul), which has raised ~$5M including a $3.5M round led by Ankur Capital and earlier MDIF backing.
WJARR — ‘Algorithmic sovereignty and new security dependencies’ wjarr.com
Global South ASR datasets risk becoming a form of ‘digital neocolonialism’ when extracted without sovereign control, introducing algorithmic-sovereignty risks even when technical bias metrics improve.
Masakhane African Languages Hub (Facebook post) facebook.com
The Masakhane African Languages Hub announced 26 funded projects in 2026 pursuing ‘By Africa, For Africa’ ASR data collection for underrepresented tonal and agglutinative languages.