
AI Privacy & Sovereignty | Logos Dev Club | March 25, 2026 x.com/i/broadcasts/1…
Andres Gomez (kurono)
9.4K posts

@kuronosec
Founder at @Sakundi_io. PhD in Computer Sciences from Uni Frankfurt and CERN. Interests: blockchain, computer security, privacy, artificial intelligence.

AI Privacy & Sovereignty | Logos Dev Club | March 25, 2026 x.com/i/broadcasts/1…






Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.

You’re invited to Episode 1 of the Private Coffee Twitter Space, a private roundtable coffee chat with one of the most prolific developers in the Zama community. Hosted by @muguika on @PrivateCoffee_, with @0xredman as co-host, and @realchriswilder alongside a special guest from @zama. Join us as we discuss how Zama is pioneering the privacy space with FHE technology. x.com/i/spaces/1RJZz… 🗓 March 27, 2026 ⏰ 4 PM UTC Plus, you stand a chance to win from 3,000 ZAMA giveaway pool!





#POLÍTICA | El expresidente Álvaro Uribe Vélez (@ÁlvaroUribeVel) aseguró que en la investigación por el asesinato del excandidato presidencial Miguel Uribe Turbay, la Fiscalía señala a la estructura de la Segunda Marquetalia como responsable del crimen. “La Fiscalía presenta como una evidencia incontrastable que quien ordenó el asesinato de Miguel Uribe fue la Nueva Marquetalia. ¿Y dónde están los instigadores? ¿Cuánto instigó Petro? ¿Cuánto instigó Cepeda? ¿Dónde está Cepeda, que sacó para que gozaran de impunidad del país para Venezuela a Santrich y a Iván Márquez? Por favor, compatriotas, el país no puede seguir siendo entregado al terror”. Caracol.com.co



for my non-brazilian moots: starting today, to use social media apps and games in Brazil it's mandatory/required to do a facial age verification and/or give the app your id and personal data. I might disappear because I don't support this Millions might be doxxed Stay safe 🩷


