𝐏𝐔𝐁𝐋𝐈𝐂 𝐍𝐎𝐓𝐈𝐂𝐄: The National Bank of #Rwanda informs the public that eKash is Rwanda's national digital payment system, enabling instant, secure, affordable, and seamless payments across licensed financial institutions.
Read the full public notice for more information here⤵️
#BNREngage
#KnowYourCentralBank
Software horror: litellm PyPI supply chain attack.
Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords.
LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm.
Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks.
Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages.
Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
Today in @MusanzeDistrict , MINAGRI concluded a 4-day consultative workshop on the AMIS project, focusing on digitalising livestock registration & milk traceability. This system will ensure every cow is a verifiable asset and every liter of milk is traceable from farm to factory.
We've signed an MOU with the Government of Rwanda—the first partnership of its kind in Africa—to bring AI to health, education, and other public sectors.
Read more: https://t.co/txgEScvKtP
Rwanda Turns Public Spending Into a Startup Engine
Govt has launched bold new procurement rules that let agencies buy ideas—not just products—opening doors for startups to solve public challenges. It will boost local tech, jobs and economic resilience.
https://t.co/e7cQH2YkNT
We’re Hiring!
Join our team and be part of Rwanda’s digital transformation journey.
📅 Application Deadline: 25th August 2025
👉 Apply here: https://t.co/NHlySjl10Q
Today,Dr.@FabriceNdayise4 on behalf of @RwandaAgri presided over the User Acceptance Testing session for the #Digital Registration & Licensing system for #veterinary practitioners,a component of the Agriculture Management Information System being developed by #ChiefDigitalOffice
We’re Hiring!
The Ministry of Agriculture and Animal Resources (MINAGRI) is seeking individual consultants to join the development team in our Digital Office.
Apply now through: https://t.co/G45AI35MX9
The SOLID principle is one of the most important design principles in programming.
Sadly, most programmers find it super difficult to understand.
Here's the simplest guide to understanding SOLID principles:
A follower asked me:
Why are Relational databases (RDBMS) not a good fit for horizontal scaling?
Why are NoSQL databases a good fit?
I will explain it like talking to a 5-year-old kid.
You can translate or understand “Horizontal Scaling” like moving your stuff from one location to another to make more room.
Imagine you have all your stuff stored in small shoe boxes, and some of them are tied with strings to each other because they contain related stuff like your soccer balls, the pieces of one Lego figure that do not fit in only one small box, etc.
Imagine your brother storing his stuff in big moving boxes, none attached, perfectly packaged.
Who will take more time moving your boxes from your bedrooms to the garage?
The response is obvious. Your brother will finish moving all his big boxes before you.
You need to deal with many more small boxes, and you have to detach/untie the strings, move the boxes out, and then attach/tie the strings to the boxes again.
Well, that is precisely what makes the difference between RDBMS and NoSQL.
RDBMS stores data like you in small boxes with many strings connecting them.
NoSQL stores data like your brother: in big boxes with no attachments, ready to move.
Finally, you can have the short answer:
The way they store the information is what makes the difference.
RDBMS stores related data using many small pieces, establishing data integrity restrictions between them that are hard to split and migrate. Besides, RDBMS need to maintain many indexes on top of data.
NoSQL uses only one unit of storage for each piece of data.
When you need to move the data to another location, it is easy to realize that NoSQL will be more efficient because they need to move fewer pieces.
Today is the Llama moment for coding! 💫
StarCoder-15B reaches 40.8% on HumanEval benchmark, beating the 30x bigger PaLM.
Coding holds a very special place in NLP. Most software in the world has AI-friendly APIs. LLMs good at coding will master the digital tools, greatly improve productivity, and some day become full-blown autonomous agents.
StarCoder's training corpus includes permissively licensed data on GitHub and over 80 programming languages. VSCode integration is available. The open-source LLM community is advancing at superhuman speed 💫
A big shoutout to @BigCodeProject !
There's a new programming language in town - it's Mojo! I'm more than a little excited about it. It's Python, but with none of Python's problems.
You can write code as fast as C, and deploy small standalone applications like C.
My post is below, and a 🧵
https://t.co/0IWGqcpEY7
Last night I read more neural NLP papers than I did in a semester at @CarnegieMellon and @cmu_africa. Understanding each paper like it was basic English was surprising to me! The CMU foundation and advantage is incredible.
Correlation and causation between the length of password and the web security need to be studied further.
I don't have the capacity to remember 16 characters password.
I have to reset password every time I need to login.
@TOGAFinfo
We’re excited to announce @GoogleCloud’s new goal of equipping 40+ million people with Google Cloud skills!
To help achieve this, we’re offering no-cost access to all #GoogleCloudTraining until Nov 6 through #GoogleCloudSkillsBoost and @Coursera ↓ https://t.co/1WQzAMZYvD