Robert Plestenjak

54.4K posts

Robert Plestenjak banner
Robert Plestenjak

Robert Plestenjak

@Nolium

Just my personal opinions, nothing more.

Katılım Aralık 2011
279 Takip Edilen758 Takipçiler
Aleš Novak
Aleš Novak@aLEs_NoVa·
@trinity126 @JMacarolV @DemokratiSLO kako ste pa do tega prišli? Demokrati smo najboljša garancija, da bo korupcija odkrita in procesirana. To je v jedru našega programa. Nobena koalicijska sestava ne bo mogla poseči v ta segment našega programa.
Slovenščina
37
3
9
3.3K
Aleš Novak
Aleš Novak@aLEs_NoVa·
O kakšnem popuščanju govorite? Če je v temelju strankinega programa povezovanje in sodelovanje, je najbrž jasno, da imamo Demokrati potencial za sodelovanje v različnih političnih kombinacijah, se vam ne zdi? Tako stališče je Logar zagovarjal tudi na vseh soočenjih.
Aleš Novak tweet media
Slovenščina
162
5
55
10.8K
Robert Plestenjak retweetledi
Cvetóber
Cvetóber@cvetober·
S kakšnim namenom se to norčujete iz kristjanov @LidlSLO ???
Cvetóber tweet media
Slovenščina
60
115
312
14.3K
Robert Plestenjak retweetledi
Uroš Šinko
Uroš Šinko@UrosSinko·
Ko daš za malarijo dveh betonskih stebrov in zamenjavo treh klopi na železniški postaji 80 milijonov, ni vrag, da te ljudje ne podprejo. Za SloGENezuelo govorim, ne kakšno normalno državo.
Uroš Šinko tweet media
Slovenščina
1
17
85
1K
Robert Plestenjak retweetledi
Aakash Gupta
Aakash Gupta@aakashgupta·
Someone just poisoned the Python package that manages AI API keys for NASA, Netflix, Stripe, and NVIDIA.. 97 million downloads a month.. and a simple pip install was enough to steal everything on your machine. The attacker picked the one package whose entire job is holding every AI credential in the organization in one place. OpenAI keys, Anthropic keys, Google keys, Amazon keys… all routed through one proxy. All compromised at once. The poisoned version was published straight to PyPI.. no code on GitHub.. no release tag.. no review. Just a file that Python runs automatically on startup. You didn’t need to import it. You didn’t need to call it. The malware fired the second the package existed on your machine. The attacker vibe coded it… the malware was so sloppy it crashed computers.. used so much RAM a developer noticed their machine dying and investigated. They found LiteLLM had been pulled in through a Cursor MCP plugin they didn’t even know they had. That crash is the only reason thousands of companies aren’t fully exfiltrated right now. If the code had been cleaner nobody notices for weeks. Maybe months. The attack chain is the part that gets worse every sentence. TeamPCP compromised Trivy first. A security scanning tool. On March 19. LiteLLM used Trivy in its own CI pipeline… so the credentials stolen from the SECURITY product were used to hijack the AI product that holds all your other credentials. Then they hit GitHub Actions. Then Docker Hub. Then npm. Then Open VSX. Five package ecosystems in two weeks. Each breach giving them the credentials to unlock the next one. The payload was three stages.. harvest every SSH key, cloud token, Kubernetes secret, crypto wallet, and .env file on the machine.. deploy privileged containers across every node in the cluster.. install a persistent backdoor waiting for new instructions. TeamPCP posted on Telegram after: “Many of your favourite security tools and open-source projects will be targeted in the months to come.. stay tuned.” Every AI agent, copilot, and internal tool your company shipped this year runs on hundreds of packages exactly like this one… nobody chose to install LiteLLM on that developer’s machine. It came in as a dependency of a dependency of a plugin. One compromised maintainer account turned the entire trust chain into a credential harvesting operation across thousands of production environments in hours. The companies deploying AI the fastest right now have the least visibility into what’s underneath it.
Andrej Karpathy@karpathy

Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.

English
177
1.3K
6.6K
1.6M
Robert Plestenjak retweetledi
Libertarec
Libertarec@Libertarec·
Že če se v desno vlado namesto Resnice vzame SD bi to (komaj!) šlo, saj bodo zavirali vse ukrepe zaradi programske nekompatibilnosti. Da bi desne stranke vstopale v levo vlado pa je čista izdaja. Tam ni prav nič kar so obljubljali volivcem, le mesto pri koruptivnem koritu.
Slovenščina
4
10
85
2.1K
Robert Plestenjak retweetledi
Toby Young
Toby Young@toadmeister·
New evidence from Antarctica ice cores showing no link between CO2 and temperature over the last three million years has stumped Net Zero activists, says Chris Morrison. dailysceptic.org/2026/03/25/sho…
English
259
3.7K
8.2K
96.7K
Robert Plestenjak retweetledi
Mitja Irsic
Mitja Irsic@MitjaIrsic·
Za božjo voljo, @IgorZorcic, ODSTOP, ZDAJ TAKOJ! A v tej deželi res nihče več ne zna sprejeti odgovornosti?!
Slovenščina
0
119
451
7.3K
Robert Plestenjak retweetledi
peter jancic
peter jancic@peterjancic·
Obtoževanje brez navajanja konkretnih imen in priimkov, po katerem slovi tudi Nika Kovač, je širjenje sovražnega govora. Sramota za medij. Mladina je strankarsko glasilo hujše od nekoč beograjske Politike, ki je slovela po zgodbah, kako so neznani Albanci posilili...
Mladina@SpletnaMladina

V Ljubljani je vedno več napadov na tuje državljane, za katere so odgovorne skrajno desne skupine. »V številnih primerih napadi ne jemljejo resno. Včasih policija sploh ne sprejme izjave žrtev ali, še huje, žrtev obtoži ’pretepanja’ in ji napiše globo.« buff.ly/pBJK3w8

Slovenščina
6
128
390
8.8K
Robert Plestenjak retweetledi
Anita Zajec
Anita Zajec@AnitaZajec4·
@rtvslo Nezakonito je. V Avstriji so volitve 2016 razveljavili zaradi, ker so prezgodaj odprli kuverte, ki so prišle po pošti, ker niso bili povsod zraven vsi člani komisije in ker je nekje glasovnice štel nepooblaščen. Zato je Avstrija demokratična in pravna država mi pa vukojebina.
Slovenščina
13
234
726
5.8K
Robert Plestenjak retweetledi
peter jancic
peter jancic@peterjancic·
@jernej_stare Pristranski ste. Cilj obeh strani je bil doseči večino v DZ in nobena je ni dosegla. Svoboda je imela prednost, vse medije, policijo, državo, Sovo... Pa je izgubila večino v DZ.
Slovenščina
3
66
234
1.7K
Robert Plestenjak
Se stiri leta Goloba ... Postavilo se je vprasanje, kaj lahko Golob, notoricni lomilec besede, zagotovi svojim politicnim partnerjem v morebitni koaliciji. Razen dostopa do uslug gospoda 10% prav nic, ponuja dostop do drzavnega korita in interesentov ne manjka. youtube.com/watch?v=b3LRWk…
YouTube video
YouTube
Slovenščina
0
0
0
10
Robert Plestenjak retweetledi
Libertarec
Libertarec@Libertarec·
Dejstvo je, da stabilne in učinkovite vlade ni mogoče sestaviti. Ne gre. Karkoli se bo sestavilo bo na pol skuhana jed, ki bo zaudarjala po gnilobi korupcije, kompromisi s skrajnostjo ali celo z dvema ter statusu quo. Ali bomo ponavljali volitve ali pa po mandatu jedli travo.
Slovenščina
28
45
211
7.2K
Robert Plestenjak
Imaš prav. Problem je, da so vse leve stranke odbezljale v Leo skrajnost. Mi lahko pokažeš enega aktivnega zmerno levega politika na naši sceni? Ga ni, ker so vsi pripravljeni zamižat na oba očesa glede korupcije, da ubranijo oblast skorumpiranih skrajnežev. Levica potrebuje katarzo.
Slovenščina
0
0
2
121
Robert Plestenjak retweetledi
Peter Hrastelj
Peter Hrastelj@hrastelj·
Menda sem čuden, ampak osebno demokracije ne dojemam kot prehod iz enega v drugo enoumje. Mene so vedno učili, da več glav, več vé. Evo vam zdaj iztočnice za zlivanje gnojnice..😅
Slovenščina
17
3
56
3K
Robert Plestenjak retweetledi
Uroš Šinko
Uroš Šinko@UrosSinko·
Zanimivo, kot da prisluhov, posnetkov sploh ne bi nikoli bilo. Vse tiho. Ta država in ta narod sta res degenerirana, amoralna greznica.
Slovenščina
12
144
609
4K
Robert Plestenjak retweetledi
Mitja Irsic
Mitja Irsic@MitjaIrsic·
Svetla stran volitev: tamali od Hinka in tamala od Mihe nista odraz tega kako razmišljajo mladi Slovenci.
Slovenščina
2
17
142
2.9K
Robert Plestenjak retweetledi
Samo Glavan
Samo Glavan@SamoGlavan·
IN TAKO ŠE VSE OSTALO (da o bistveno bolj raznoliki izbiri sploh ne govorimo): ↘️ Spar v Sloveniji: 5,20 €; slabo govorijo slovensko. Spar zadruga Pliberk: 3,50 €; dobro govorijo slovensko. ↘️ Slovenski izdelek je v Sloveniji 48,57 % dražji, kot v Avstriji. Bogati Slovenci torej subvencioniramo revne Avstrijce... ⬇️⬇️⬇️ Kdo je kriv? 1️⃣ Trump 2️⃣ Netanjahu 3️⃣ Janša 4️⃣ Golob
Samo Glavan tweet media
Slovenščina
23
86
203
5.3K
Robert Plestenjak retweetledi
Edvard Kadič
Edvard Kadič@EdvardKadic·
Gre za formalno nezakonitost?!? Torej kršitev postopka oz. pristojnosti, ne pa tudi vsebine? Aha, potem je pa vse ok. Kje jih samo najdejo … 🤦‍♂️🙄🤣
📱MMC RTV Slovenija@rtvslo

Ustavni pravnik Igor Kaučič pravi, da gre pri združevanju volišč na predčasnih volitvah za formalno nezakonitost. Zakaj? "Zato, ker samo oblikovanje takih volišč ne vpliva nujno na glasovanje in izid glasovanja." rtvslo.si/slovenija/parl…

Slovenščina
18
66
248
6.6K