Alexander Alten

4.7K posts

Alexander Alten banner
Alexander Alten

Alexander Alten

@mapredit

Change the world with code | @scalyticsai | KafScale | KafClaw | co-creator Apache Wayang

Florida, USA Tham gia Ocak 2012
259 Đang theo dõi522 Người theo dõi
Tweet ghim
Alexander Alten
Alexander Alten@mapredit·
1. Code is law. 2. Keys are sovereignty. 3. Privacy is not optional. 4. Power corrupts. I build systems where no one can freeze your funds, censor your speech, or own your identity.
English
5
1
10
561
unusual_whales
unusual_whales@unusual_whales·
France to ditch Windows for Linux to reduce reliance on US tech, per TC
English
416
1K
12.3K
772.6K
Alexander Alten
Alexander Alten@mapredit·
European “patriots” are just as stupid as the other political parties.
English
0
0
1
8
Alexander Alten đã retweet
Alexander Alten
Alexander Alten@mapredit·
🚀 Multi-agent systems dying from RAG? 46-second latency, stale embeddings, token explosion. We built KafGraph: Kafka-backed binary graph in memory-mapped files. Agents just ls + grep their shared memory → 100ms lookups, O(log n), real expiry with tombstones + TTL. No vectors. No query lang. Data lives where agents roam. Full story: scalytics.io/en-gb/blog/sha…
English
0
0
2
28
Alexander Alten
Alexander Alten@mapredit·
Two nerds may have brought us closer to an AGI. Not the AI labs. Nerds in home office.
English
0
0
1
8
Alexander Alten
Alexander Alten@mapredit·
Claude Code is simply shit. Point.
English
0
0
0
13
Alexander Alten
Alexander Alten@mapredit·
Kubernetes streaming clusters accumulate stale pods post-scale-down. Platform teams exhaust resources before Kafka operators recover. Delete by label selector for instant cleanup. novatechflow.com/2020/03/kubern…
English
0
0
1
17
Sam van Rooy MP
Sam van Rooy MP@SamvanRooy1·
Is there a bigger loser in the EU than Macron!?
English
637
350
3.6K
45.3K
Alexander Alten
Alexander Alten@mapredit·
Big data paradigms shift from batch to streaming, but legacy pipelines overload infra. Platform teams face replay latency for agent workloads. Adopt Kafka-native continuous flows. Read: novatechflow.com/2016/10/shifti…
English
0
0
0
13
Alexander Alten
Alexander Alten@mapredit·
@kloss_xyz 100% of “code-vibing-bros” don’t understand a single word. Most don’t even know what they use under the hood …
English
0
0
0
278
klöss
klöss@kloss_xyz·
do you understand what just happened to one of the most used npm packages on the internet? → axios gets downloaded over 100 million times a week and today it got compromised → an attacker hijacked the npm credentials of a lead axios maintainer… changed the account email to an anonymous ProtonMail address… and manually published two poisoned versions → axios@1.14.1 and axios@0.30.4… neither version contains a single line of malicious code inside axios itself. instead they inject a fake dependency called plain-crypto-js that drops a remote access trojan on your machine → the fake dependency was staged 18 hours in advance… three separate payloads were pre-built for macOS, Windows, and Linux… both release branches were hit within 39 minutes. every trace was designed to self-destruct after execution too → there’s no tag in the axios GitHub repo for 1.14.1. it was published outside the normal release process entirely... bypassed CI/CD completely → StepSecurity called it one of the most operationally sophisticated supply chain attacks ever against a top 10 npm package → a routine npm install silently opens a backdoor… no warning… no suspicious code visible in axios itself this is the wake up call all vibe coding bros need to hear right now: → if you installed either version… assume your system is compromised → pin to axios@1.14.0 or axios@0.30.3 → rotate all secrets, API keys, SSH keys, and credentials on affected machines → check network logs for C2 connections → add –ignore-scripts to CI npm installs going forward 100 million weekly downloads and one compromised maintainer account… that’s all it took to wreak absolute havoc and I imagine we see a whole lot more of these… crazy times ahead for cybersecurity and vibe coding be safe out there y’all
Feross@feross

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.

English
107
485
3.5K
875K
Alexander Alten
Alexander Alten@mapredit·
PDF analysis chokes Kafka-backed RAG pipelines with unstructured noise. Platform teams rebuild indexes after every doc ingest. Normalize with LLMs into typed events for continuous updates. novatechflow.com/2024/05/beyond…
English
0
0
0
12
Alexander Alten
Alexander Alten@mapredit·
This f*ing time change. Abolish it.
English
0
0
0
5