Christophe Frézier

647 posts

Christophe Frézier banner
Christophe Frézier

Christophe Frézier

@cfrezier

Technical Architect at @onepoint, Father of 2. Full time scheduled.

Bordeaux, France 가입일 Kasım 2012
175 팔로잉70 팔로워
Christophe Frézier 리트윗함
Dubd 🔻🇫🇷
Dubd 🔻🇫🇷@dany_dubd·
Félicitations aux ouvriers qui ont voté pour ça. Vous avez élu un patron… 🤡
Français
316
2K
9.3K
414.2K
Christophe Frézier 리트윗함
Aakash Gupta
Aakash Gupta@aakashgupta·
Someone just poisoned the Python package that manages AI API keys for NASA, Netflix, Stripe, and NVIDIA.. 97 million downloads a month.. and a simple pip install was enough to steal everything on your machine. The attacker picked the one package whose entire job is holding every AI credential in the organization in one place. OpenAI keys, Anthropic keys, Google keys, Amazon keys… all routed through one proxy. All compromised at once. The poisoned version was published straight to PyPI.. no code on GitHub.. no release tag.. no review. Just a file that Python runs automatically on startup. You didn’t need to import it. You didn’t need to call it. The malware fired the second the package existed on your machine. The attacker vibe coded it… the malware was so sloppy it crashed computers.. used so much RAM a developer noticed their machine dying and investigated. They found LiteLLM had been pulled in through a Cursor MCP plugin they didn’t even know they had. That crash is the only reason thousands of companies aren’t fully exfiltrated right now. If the code had been cleaner nobody notices for weeks. Maybe months. The attack chain is the part that gets worse every sentence. TeamPCP compromised Trivy first. A security scanning tool. On March 19. LiteLLM used Trivy in its own CI pipeline… so the credentials stolen from the SECURITY product were used to hijack the AI product that holds all your other credentials. Then they hit GitHub Actions. Then Docker Hub. Then npm. Then Open VSX. Five package ecosystems in two weeks. Each breach giving them the credentials to unlock the next one. The payload was three stages.. harvest every SSH key, cloud token, Kubernetes secret, crypto wallet, and .env file on the machine.. deploy privileged containers across every node in the cluster.. install a persistent backdoor waiting for new instructions. TeamPCP posted on Telegram after: “Many of your favourite security tools and open-source projects will be targeted in the months to come.. stay tuned.” Every AI agent, copilot, and internal tool your company shipped this year runs on hundreds of packages exactly like this one… nobody chose to install LiteLLM on that developer’s machine. It came in as a dependency of a dependency of a plugin. One compromised maintainer account turned the entire trust chain into a credential harvesting operation across thousands of production environments in hours. The companies deploying AI the fastest right now have the least visibility into what’s underneath it.
Andrej Karpathy@karpathy

Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.

English
291
2.2K
10.9K
2.7M
Christophe Frézier 리트윗함
ARC Now
ARC Now@ArcRaidersNow·
#ARCRaiders Practice Range Has a Hidden Secret 🎥u/tiff92
English
33
63
1.4K
186.9K
Christophe Frézier 리트윗함
Elodie Dvt
Elodie Dvt@Elo_Dvt87·
"si tu te fais défoncer par Bachelot essaie pas Mélenchon à lui tout seul il vient de déboîter toute une commission d'enquête ordonnée par Wauquiez qui est même pas venu donc pour lui Bardella c'est un apericube" Encore une masterclass de l'excellentissime Waly Dia 👏👏😁🤣😂😭
Français
56
1.6K
7K
157.4K
Jack
Jack@Bro_SALMON22·
@EmbarkBulletin Im spending the last 10+ hours of my gameplay running 3 adrenaline shots and a green loadout ONLY to do security breach runs. I have so much good stuff I want to use but won’t because I need high stash value. Really wish it was challenged or something instead of stash value
English
1
0
0
118
EmbarkBulletin
EmbarkBulletin@EmbarkBulletin·
Now that the Expedition is starting soon in ARC Raiders, how are we feeling about the cycle/process and rewards? Personally, I feel like there’s enough incentives that it is encouraging us to hoard our stash and use more free loadouts instead of using our best loot. Not too big of a fan on that as I feel like a part of what makes extraction-like games so addicting is that before a wipe happens, you use your best loot and it gives you a sense of accomplishment and thrill. This seems to be the opposite and I am still on the fence with a few things about the Expedition process. What do you think?
EmbarkBulletin tweet media
English
144
4
276
47.4K
Christophe Frézier 리트윗함
Mesuret
Mesuret@NocnaZ·
450 million people living in democracy and the rule of law is what makes us strong. I'm proud to be European.
Mesuret tweet media
English
1K
1.5K
9.6K
154.6K
Lance
Lance@LancesEmporium·
Is it just me, or are Expedition rewards in ARC Raiders just not worth it? Yes, it’s a feature aimed at power players who want a challenge and something to do - I get that. But if you’re asked to reset basically everything you’ve worked for since release, the rewards should feel a lot more substantial than what’s currently on the table. Let’s take a look: 🔒PERMANENT UNLOCKS 💼+12 stash slots More stash space is always nice, but those 12 slots are filled very quickly. For a full reset I’d expect at least around 20 extra slots. ⏫Up to +5 skill points Skill points are a good thing, but +5 doesn’t really move the needle with the current skill trees. On top of that, racking up 5 million value with about 2.5 weeks to go feels very steep. ⏳TEMPORARY BUFFS 🛠️+10% repair buff What does that really mean in practice? Does repairing your weapon give it +10% more durability? For most weapons it’s nonsense – you either spend resources on repairing them once or you recycle them anyway. You barely feel this. 🧩+5% XP boost Let’s calculate with an average good round that gives 20,000 XP. 5% of that is 1,000 bonus XP. That’s roughly 5 loot containers. That’s almost nothing. I would have expected more here as well. 🐔+6% more materials from Scrappy You get 8 materials per run – metal parts, cloth, plastic parts, chemicals, rubber parts and seeds. With +6% you’ll get 9 instead of 8 basically every second run. You won’t really feel that in practice. 🤔IS THIS REALLY WORTH IT? I’m losing all the blueprints, all the levels, all my stash for that? To quote Embark themselves: “respecting your time investment in the game.” I don’t feel that my time is respected with these rewards. Not at all. And no, a sign that basically says “has made 1 Expedition” or a single cosmetic set doesn’t cut it either. Right now, it doesn’t feel worth it at all to do an Expedition. It feels cheap, and I’d actually discourage any player who isn’t playing this game multiple hours a day from doing it. What’s your take Raiders - am I missing something here, or do Expeditions need a serious reward rework?
Lance tweet media
English
380
32
648
272.4K
Christophe Frézier
Christophe Frézier@cfrezier·
@LancesEmporium I don't care losing everything, i enjoy starting over since this game is so much fun. I'm a somewhat casual player, but managed to fullfill requirements by focusing on it. I'm not even lvl 50 yet 😅. I hope the skin is not shitty tho 🤣
English
0
0
0
12
Wise
Wise@WisethugTV·
5 millions pour avoir 5 points de compétence sur la première expédition d’arc Raiders, et seulement 12 places d’inventaire en plus. Vous en pensez quoi ?
Français
93
2
139
33.3K
myster_flo_
myster_flo_@myster_flo_·
@WisethugTV Salut Wise, dsl mais je n’ai pas saisi un truc, il faut 5M de crédits ? Ou avoir un cumul d’inventaire d’une valeur de 5 M sur nos 280 places ? Et si c’est sur l’inventaire, il faudra un mixte d’objets comme pour la dernière étape de la caravane ou pas ? Merci pour la précision !
Français
1
0
0
1.1K
Pierre-Luc L.
Pierre-Luc L.@pierreluc_leb·
@ArcRaiderAlerts The ratio between what you loose vs what you gain is absurd. Theres basically no advantages... ive spent hours and hours and still havent found most of the rare blueprints, and my skill tree isnt done, and youre gonna take it away.. for..... fun?
English
1
0
1
483
ARC Raiders Alerts
ARC Raiders Alerts@ArcRaiderAlerts·
ARC Raiders’ first progression WIPE starts in 2 weeks. Here's everything you need to know including what you lose/keep, rewards and incentives... 🧵
ARC Raiders Alerts tweet media
English
169
145
3.6K
585.5K
Clayton Wilson
Clayton Wilson@larrytrillson·
@ArcRaiderAlerts Wait… are you wiping my stuff? I don’t give a flying F about an expedition you better not force a reset.
English
6
0
0
748
Darkmical
Darkmical@TheNovice96·
@ArcRaiderAlerts Fuck on the 5th stage and lowkey them resources for trinkets and shits killing me how the fuck a purple key worth 100? Shits wild guess seed hunting it is
English
1
0
0
116
LoganX
LoganX@LoganXGaming·
@ArcRaiderAlerts Will the players that choose to reset be in different lobby queues than people who do not?
English
1
0
0
2K
Christophe Frézier
Christophe Frézier@cfrezier·
@Beaver_VII @ArcRaiderAlerts It's not really clear. For me stash, cosmetics and perks obtained this way are permanent ; other bonuses are not. Perhaps stash and perks obtained for additionnal stash value may be temporary.
English
0
0
0
237
Beaver_II
Beaver_II@Beaver_VII·
@ArcRaiderAlerts I heard that the rewards like stash upgrades aren’t permanent and are only for the current expedition window, is that true? Cause that would suck butt
English
4
0
7
9.8K
NeonShadow
NeonShadow@oONeonShadowOo·
@ArcRaiderAlerts To clarify, I didn’t see you state blueprints anywhere, is this considered permanently unlocked as well?
English
1
0
1
3.3K