Falguni Das Shuvo

150 posts

Falguni Das Shuvo banner
Falguni Das Shuvo

Falguni Das Shuvo

@shuvoxcd01

Machine Learning Engineer @IQVIA. Grad student at BUET. Love Reinforcement Learning, Optimization, Logic & Chess.

Katılım Mart 2012
885 Takip Edilen45 Takipçiler
Falguni Das Shuvo retweetledi
Andrej Karpathy
Andrej Karpathy@karpathy·
Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
Daniel Hnyk@hnykda

LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below

English
1.4K
5.4K
28K
66.4M
Falguni Das Shuvo
Falguni Das Shuvo@shuvoxcd01·
@Sensodyne_US Hi @Sensodyne_US , Thanks for the reply. I've already contacted mystory.bd@haleon.com. They replied that Haleon does not officially sell this product in Bangladesh. They have reached out to the appropriate department in France. I'll keep you posted if I get a reply.
English
0
0
0
28
Sensodyne US
Sensodyne US@Sensodyne_US·
Hi Falguni. We appreciate your bringing this matter to our attention; quality is of utmost importance to us. We would appreciate an opportunity to speak with you personally. Please call us at 1-866-844-2797 Mon-Fri 8 a.m. - 6:00 p.m. EST or send an email to mystory.us@haleon.com. Thank you.
English
1
0
0
36
Falguni Das Shuvo
Falguni Das Shuvo@shuvoxcd01·
I didn't find any similar-looking products on the official Sensodyne websites. I'll be happy to provide more details if required.
English
0
0
0
37
Dieter Büchler
Dieter Büchler@dtrbchlr·
@AmiiThinks @MPI_IS If you are interested in working with me at *the* RL powerhouse @UAlberta on robot learning on physical robots, please drop me a message. Retweets welcome 🙏
English
3
13
31
8.3K
Falguni Das Shuvo
Falguni Das Shuvo@shuvoxcd01·
@dtrbchlr @AmiiThinks @MPI_IS @UAlberta I've always been fascinated by robot intelligence. RL + Robotics is my dream. I study RL, publish implementations, and try to fit NNs in ESP32 :). I'm taking my first steps alone due to a lack of collaboration. This opportunity would be like a dream come true. Super enthusiastic!
English
1
0
1
189
Dieter Büchler
Dieter Büchler@dtrbchlr·
A bit late but still want to congratulate @RichardSSutton for his achievements in RL and AI & his huge positive influence on so many researchers! Guess it’s a good moment to announce that I joined @UAlberta 😎 Feeling honored to work alongside Rich and my other colleagues!
Amii@AmiiThinks

“There are no authorities in science,” says Turing Award winner @RichardSSutton, Amii Fellow & Canada @CIFAR_News AI Chair. Sit down with Rich and @camlinke as they discuss the journey to this moment. Watch now: hubs.la/Q039xBP-0 #TuringAward #AI #ReinforcementLearning

English
3
5
45
22.6K
Falguni Das Shuvo
Falguni Das Shuvo@shuvoxcd01·
Yep, it does struggle with watch faces!!!
Falguni Das Shuvo tweet media
English
0
0
0
55
Falguni Das Shuvo retweetledi
Google DeepMind
Google DeepMind@GoogleDeepMind·
Huge congratulations to @DemisHassabis and John Jumper on being awarded the 2024 Nobel Prize in Chemistry for protein structure prediction with #AlphaFold, along with David Baker for computational protein design. This is a monumental achievement for AI, for computational biology, and science itself. 🧬
The Nobel Prize@NobelPrize

BREAKING NEWS The Royal Swedish Academy of Sciences has decided to award the 2024 #NobelPrize in Chemistry with one half to David Baker “for computational protein design” and the other half jointly to Demis Hassabis and John M. Jumper “for protein structure prediction.”

English
118
721
3.8K
543.7K