AI Dynamics

Global AI News Aggregator

About

ENTERPRISE AI

  • Jared AI Employee Lives in Slack Connects 3000 Tools

    Introducing Jared: the first AI employee that’s actually social. He lives in Slack, connects to 3,000+ tools, and quietly does the work in the background – reports, dashboards, code, follow-ups, research – then jumps into the conversation when it matters. Reads the room,

    → View original post on X — @futurepedia_io

  • LiteLLM Supply Chain Attack Compromises Millions of AI Credentials
    LiteLLM Supply Chain Attack Compromises Millions of AI Credentials

    Someone just poisoned the Python package that manages AI API keys for NASA, Netflix, Stripe, and NVIDIA.. 97 million downloads a month.. and a simple pip install was enough to steal everything on your machine. The attacker picked the one package whose entire job is holding every AI credential in the organization in one place. OpenAI keys, Anthropic keys, Google keys, Amazon keys… all routed through one proxy. All compromised at once. The poisoned version was published straight to PyPI.. no code on GitHub.. no release tag.. no review. Just a file that Python runs automatically on startup. You didn’t need to import it. You didn’t need to call it. The malware fired the second the package existed on your machine. The attacker vibe coded it… the malware was so sloppy it crashed computers.. used so much RAM a developer noticed their machine dying and investigated. They found LiteLLM had been pulled in through a Cursor MCP plugin they didn’t even know they had. That crash is the only reason thousands of companies aren’t fully exfiltrated right now. If the code had been cleaner nobody notices for weeks. Maybe months. The attack chain is the part that gets worse every sentence. TeamPCP compromised Trivy first. A security scanning tool. On March 19. LiteLLM used Trivy in its own CI pipeline… so the credentials stolen from the SECURITY product were used to hijack the AI product that holds all your other credentials. Then they hit GitHub Actions. Then Docker Hub. Then npm. Then Open VSX. Five package ecosystems in two weeks. Each breach giving them the credentials to unlock the next one. The payload was three stages.. harvest every SSH key, cloud token, Kubernetes secret, crypto wallet, and .env file on the machine.. deploy privileged containers across every node in the cluster.. install a persistent backdoor waiting for new instructions. TeamPCP posted on Telegram after: “Many of your favourite security tools and open-source projects will be targeted in the months to come.. stay tuned.” Every AI agent, copilot, and internal tool your company shipped this year runs on hundreds of packages exactly like this one… nobody chose to install LiteLLM on that developer’s machine. It came in as a dependency of a dependency of a plugin. One compromised maintainer account turned the entire trust chain into a credential harvesting operation across thousands of production environments in hours. The companies deploying AI the fastest right now have the least visibility into what’s underneath it. Andrej Karpathy (@karpathy) Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery – Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible. — https://nitter.net/karpathy/status/2036487306585268612#m

    → View original post on X — @bobgourley, 2026-03-25 03:56 UTC

  • CIOs Need New Talent To Successfully Implement AI
    CIOs Need New Talent To Successfully Implement AI

    CIOs Need A New Kind Of Talent To Make #AI Work
    by Fletcher Keister @Forbes Learn more: https://
    bit.ly/3NRMws3 #ArtificialIntelligence #MachineLearning #ML

    → View original post on X — @ronald_vanloon

  • Custom Entity Recognition Accelerated with Claude and Amazon Bedrock
    Custom Entity Recognition Accelerated with Claude and Amazon Bedrock

    Accelerating Custom Entity Recognition with Claude Tool use in Amazon Bedrock! #BigData #Analytics #DataScience #AI #MachineLearning #NLProc #LLM #IoT #IIoT #PyTorch #Python #RStats #TensorFlow #Java #JavaScript #ReactJS #GoLang #CloudComputing #Serverless #DataScientist #Linux

    → View original post on X — @gp_pulipaka

  • New Packt Release on Agentic Architectural Patterns for Multi-Agent Systems
    New Packt Release on Agentic Architectural Patterns for Multi-Agent Systems

    New release from @PacktDataML at http://
    amzn.to/3MaHy8T "Agentic Architectural Patterns for Building Multi-Agent Systems: Proven design patterns and practices for GenAI, agents, RAG, LLMOps, and enterprise-scale AI systems" Contents:
    GenAI in the Enterprise: Landscape,

    → View original post on X — @kirkdborne

  • SambaStack: Hardware-Software Stack for AI Inference
    SambaStack: Hardware-Software Stack for AI Inference

    Simplify AI with SambaStack, the top hardware & software stack built for AI inference. Deploy on-prem or in the cloud to accelerate innovation with dedicated SambaNova infrastructure. Learn more: https://
    sambanova.ai/products/samba
    stack?utm_source=x&utm_medium=organic&utm_campaign=enterprise
    …

    → View original post on X — @sambanovaai

  • Glimpses of last week’s NVIDIA GTC: Enterprise AI agents

    Glimpses of last week’s NVIDIA GTC. Enterprise AI agents.

    → View original post on X — @scobleizer

  • LeWorldModel: LeCun’s breakthrough in stable world model training
    LeWorldModel: LeCun’s breakthrough in stable world model training

    🚨 Holy shit… LeCun's team just cracked world models wide open. Everyone's obsessing over the next Claude update. Meanwhile Yann LeCun quietly dropped a paper that could matter way more long term. It's called LeWorldModel. And to understand why it's a big deal, you need to understand the difference between what LLM does and what this does. LLMs predict the next word. That's it. They're incredibly good at language. But they don't understand reality. They can write about a ball bouncing off a wall. They can't predict where it lands. World models predict what happens next in the physical world. Objects moving, colliding, falling. That's the foundation for robots that plan, self-driving cars that simulate scenarios, any AI that needs to act in reality instead of just talk about it. The problem? World models kept collapsing. The model would cheat by mapping every input to the same output. Like a weather app that predicts "sunny" every single day. Technically it's predicting. It's just useless. And fixing this required 6+ loss hyperparameters, frozen pre-trained encoders, stop-gradient hacks, exponential moving averages. A house of cards just to keep the thing from breaking. LeCun's team (Mila, NYU, Samsung SAIL, Brown) threw all of that out. LeWorldModel uses just 2 loss terms. A prediction loss and a regularizer called SIGReg that forces representations to stay diverse instead of collapsing into garbage. 6 hyperparameters reduced to 1. The simplicity IS the breakthrough. The numbers: 15M parameters. Trains on a single GPU in a few hours. Plans up to 48x faster than foundation-model-based world models. Uses roughly 200x fewer tokens than alternatives. Competitive across 2D and 3D control tasks. This isn't a supercomputer experiment. You could run this on your own hardware. LeCun has been pushing JEPA as the architecture for real AI since 2022. The criticism was always the same: "sounds nice, doesn't train stably." LeWorldModel just removed that objection. Small model. Stable training. No hacks. No frozen encoders. No collapse. Two AI futures are competing right now. Path 1: bigger LLMs, more text, more compute. Path 2: world models that learn physics from raw pixels and plan in real time. LeWorldModel is the strongest signal yet that Path 2 is real, getting cheaper, and closing in fast.

    → View original post on X — @bobgourley, 2026-03-24 20:54 UTC

  • FutureX: Evaluating AI Reasoning and Anticipation in Production

    FutureX tests what most benchmarks miss: Can AI reason, use tools, and anticipate outcomes that haven't happened yet? AI in production isn't about generating content. It's about making decisions in dynamic, uncertain environments. This is where we're seeing strong performance

    → View original post on X — @h2oai

  • H2O AI Super Agent Maintains Top Position on FutureX Leaderboard

    H2O AI Super Agent™ is back at #1 on the FutureX leaderboard Not a one-off. A consistent signal. #AgenticAI #EnterpriseAI #SuperAgent #FutureX

    → View original post on X — @h2oai