A fuel crisis keeps spreading across Russia.
I ran the country's largest oil company. Let me explain what is actually happening — and why the Kremlin cannot stop it. 🧵[1/12]
"jo tas var .... vai radīt citus būtiskus riskus, tostarp neatgriezeniskas sekas" principā var interpretēt arī šādi - Latvija Valsts meži ir apdir$ušies pēc pilnas programmas, ir iestājušās neatgriezeniskas sekas, un no @elnormous tik ērts grēkāzis varētu sanākt :)
HUGE!
Iespējams lielākais hackinga incidents Latvijas vēsturē.
Allegedly ir kompromitētas un pilnībā enkriptētas visas @valstsmezi iekšējās un ārējās sistēmas, tas skaitā back-upi.
Jau pagājušas aptuveni 36h kopš par šo incidentu ir zināms publiski un joprojām LVM servisi nestrāda.
Šobrīd arī 0 informācijas medijos.
Ja LVM nav offline backupi un atstrādāts disaster recovery process tad iespējams, ka visi LVM publisko un iekšējo sistēmu dati ir pieejami tikai hackeriem kuri pieprasa izpirkumu maksu.
Jesus, no.
This is the worst use case for AI, as it relates to history because it convinces people that what they are watching is authentic and accurate, which it simply isn't in any way.
This content is doing incredible harm to people's understanding of history.
This announcement arrives hours after our investigation (https://t.co/ZOusgFy2c9) described how OpenAI dissolved its superalignment and AGI-readiness teams and dropped safety from the list of its most significant activities on its IRS filings—and how, when we asked to speak with researchers, working on existential safety, a representative replied "What do you mean by 'existential safety'? That's not, like, a thing."
(🧵1/11) For the past year and a half, I've been investigating OpenAI and Sam Altman for @NewYorker. With my coauthor @andrewmarantz, I reviewed never-before-disclosed internal memos, obtained 200+ pages of documents related to a close colleague, including extensive private notes, and interviewed more than 100 people.
OpenAI was founded on the premise that A.I. could be the most dangerous invention in human history—and that its C.E.O. would need to be a person of uncommon integrity. We lay out the most detailed account yet of why Altman was ousted out by board members and executives who came to believe he lacked that integrity, and ask: were they right to allege that he couldn't be trusted?
A thread on some of of our findings:
BREAKING: Fannie Mae says it will start accepting crypto-backed mortgages, per @WSJ.
The mortgage-finance giant will let home buyers pledge their crypto holdings when getting a mortgage.
Fannie is backed by the government and overseen by the Federal Housing Finance Agency.
Software horror: litellm PyPI supply chain attack.
Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords.
LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm.
Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks.
Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages.
Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
🦔 Researchers at Aikido Security found 151 malicious packages uploaded to GitHub between March 3 and March 9. The packages use Unicode characters that are invisible to humans but execute as code when run. Manual code reviews and static analysis tools see only whitespace or blank lines. The surrounding code looks legitimate, with realistic documentation tweaks, version bumps, and bug fixes. Researchers suspect the attackers are using LLMs to generate convincing packages at scale. Similar packages have been found on NPM and the VS Code marketplace.
My Take
Supply chain attacks on code repositories aren't new, but this technique is nasty. The malicious payload is encoded in Unicode characters that don't render in any editor, terminal, or review interface. You can stare at the code all day and see nothing. A small decoder extracts the hidden bytes at runtime and passes them to eval(). Unless you're specifically looking for invisible Unicode ranges, you won't catch it.
The researchers think AI is writing these packages because 151 bespoke code changes across different projects in a week isn't something a human team could do manually. If that's right, we're watching AI-generated attacks hit AI-assisted development workflows. The vibe coders pulling packages without reading them are the target, and there are a lot of them. The best defense is still carefully inspecting dependencies before adding them, but that's exactly the step people skip when they're moving fast. I don't really know how any of this gets better. The attackers are scaling faster than the defenses.
Hedgie🤗
https://t.co/XQ8Eqs1QOA
🚨 “Narva People’s Republic” memes are spreading: flags, maps, and “autonomy” jokes framing Narva as separate from Estonia.
Edgy humor? No—the messaging echoes the 2014 Donbas propaganda playbook: stoking ethnic tension to normalize separatism.
Analysis ⬇️
Everyone’s missing the real story here.
Meta’s Ray-Ban glasses need human data annotators to train the AI. When you say “Hey Meta” and ask the glasses to analyze something, that video gets sent to Meta’s servers, then routed to Sama, a subcontractor in Nairobi, Kenya. Workers there manually label objects in your footage. They see everything you recorded, intentionally or not.
7 million pairs sold in 2025 alone. Every single pair generates training data that flows through human eyes in Kenya. Workers told Swedish journalists they see people undressing, using bathrooms, having sex, and accidentally filming bank card details. One worker said “we see everything, from living rooms to naked bodies.”
Meta’s automatic face anonymization is supposed to protect people in the footage. Workers say it fails in certain lighting. Faces that should be blurred are sometimes fully visible. The person you recorded without knowing? A stranger in Nairobi can identify them.
Buried in Meta’s terms of service is one sentence doing enormous legal work: the company reserves the right to conduct “manual (human) review” of your AI interactions. That’s the legal cover for routing intimate footage from Western homes to a $2/hour labor force operating under NDAs, office surveillance cameras, and a strict no-questions policy. Workers say if you raise concerns about what you’re seeing, you’re fired.
This is the same company, Sama, that TIME exposed in 2023 for paying Kenyan workers $2/hour to label graphic content for OpenAI while being billed at $12.50/hour per worker. Workers described the experience as torture. Sama ended that contract, then pivoted to labeling Meta’s glasses footage. Same workforce. Same rates.
Meta markets these glasses as “designed with your privacy in mind.” The privacy design is a tiny LED light on the frame that most people don’t notice. The data pipeline behind it routes your bedroom footage to a contractor with a documented history of worker exploitation, failed anonymization, and union-busting lawsuits.
And the next generation of these glasses? Meta is planning to add facial recognition. The same system that can’t reliably blur faces in training data wants to start identifying them on purpose.
The LED light on the frame is doing about as much for your privacy as the terms of service nobody reads.
@gljuksx Likās pat ka scam, tikai dēļ šī teksta “Ja esat pieslēdzies savam kontam, vispirms jāatslēdzas no tā (sadaļa “Mans konts” / Citi / Atslēgties).”