Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery – Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible. Daniel Hnyk (@hnykda) LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below — https://nitter.net/hnykda/status/2036414330267193815#m
AI
-

AI Agents in WhatsApp Business: Integration Challenges and Solutions
By
–
Messaged a friend on WhatsApp, got greeted by the OpenClaw doorman (use separate number + WA Business to avoid this, see the docs, or use a message platform that is friendlier for agents such as Telegram)
-
LangSmith Fleet Now Supports Custom Slack Bots Integration
By
–
LangSmith Fleet now supports custom Slack bots.
— LangChain (@LangChain) 24 mars 2026
Give your agent its own handle, then call it directly from Slack. Use agents where you already work.
Try Fleet: https://t.co/ToKtvKURKK pic.twitter.com/ThNCvAQ6rjLangSmith Fleet now supports custom Slack bots. Give your agent its own handle, then call it directly from Slack. Use agents where you already work. Try Fleet: https://
smith.langchain.com/agents?skipOnb
oarding=true/?utm_medium=social&utm_source=twitter&utm_campaign=q1-2026_fleet-launch_aw
… -
Optimal Intellect Introduces Moreau GPU-Native Solver
By
–
We're Optimal Intellect, a research lab from the team behind CVXPY. Today we're introducing Moreau: a GPU-native solver that's orders of magnitude faster than the best existing tools.
→ View original post on X — @soumithchintala, 2026-03-24 16:48 UTC
-

Thought Communication in Multiagent AI Collaboration Systems
By
–
Thought Communication in Multiagent Collaboration https://
buff.ly/VTgDmxo
#AI #MachineLearning #DeepLearning #LLMs #DataScience -
AI Agents Autonomously Execute CVE Exploits and Coordinate Attacks
By
–
This morning at #RSAC2026, Databricks Co-founder and CEO @alighodsi and @a16z Co-founder @bhorowitz took the stage to make the case for a fundamentally different approach to cybersecurity. AI agents now autonomously read CVEs, construct exploits, and coordinate attacks around
-
Tech Layoffs Reveal Hidden Growth Story for Industry
By
–
The open-role and layoff data for this year are actually telling a growth story for tech—despite the headlines. Yes, there have been layoffs, and there will likely continue to be as the year goes on. That’s very real and an understandable worry for everyone working today. But
-

Big Tech Headcount Remains Stable Despite Recent Layoffs
By
–
Most importantly, the headcount at most big tech companies is flat or slightly up since last year, despite the layoffs we’ve been reading about.
-

Remote Work Opportunities Decline Across PM Engineering Design Roles
By
–
6/ Remote work opportunities continue to decline At the 2022 peak in remote-optional listings, we saw about 35% of open PM roles, 26% of eng roles, and 28% of design roles listed as remote-friendly. Today, only 25% of PM roles have a remote option, 19% of eng roles, and 23% of
-

Tech Layoffs Continue Despite Overall Job Growth
By
–
7/ Despite ongoing layoffs, the overall number of tech jobs continues to grow So far in 2026, there have been 184 layoffs at tech companies, with 57,606 people impacted. In 2025, there were 783 layoffs at tech companies, with 245,953 people impacted (674 people per day). Though