[$] The many failures leading to the LiteLLM compromise

LiteLLM
is a gateway library providing access to a number of large language models
(LLMs); it is popular and widely used. On March 24, the word went out
that the version of LiteLLM found in the Python
Package Index (PyPI)
repository had been
compromised with information-stealing malware and downloaded thousands of
times, sparking concern across the net. This may look like just another
supply-chain attack — and it is — but the way it came about reveals just
how many weak links there are in the software supply chains that we all
depend on.

The telnyx packages on PyPI have been compromised

The SafeDep blog reports
that compromised versions of the telnyx package have been found in the PyPI
repository:

Two versions of telnyx (4.87.1 and 4.87.2) published to
PyPI on March 27, 2026 contain malicious code injected into
telnyx/_client.py. The telnyx package averages over 1 million
downloads per month
(~30,000/day), making this a high-impact
supply chain compromise. The payload downloads a second-stage
binary hidden inside WAV audio files from a remote server, then
either drops a persistent executable on Windows or harvests
credentials on Linux/macOS.

HyprLTM-Net v0.3.0 Is Here and It’s a Major Update!

Alhamdulillah, I started HyprLTM-Net as a personal project for my Hyprland setup, which by the way I am still quietly improving, and now it has become a real open source project used by hundreds of users.And even better, I keep taking care of it like a little baby (for your curiosity, I am a father). This time, I’m more than happy to announce the availability of HyprLTM-Net v0.3.0, which comes with numerous new features, fixes, and improvements.So let’s see what this new version brings.

KDE Plasma 6.6 Showing Frequent Performance Advantage Over GNOME 50 With NVIDIA R595 Driver

Earlier this week I provided benchmarks looking at KDE Plasma 6.6’s performance advantage over GNOME 50 for Linux gaming with AMD Radeon graphics. That raised the question if the same was true when using NVIDIA graphics with their official Linux graphics driver stack. Here are such benchmarks looking at the KDE Plasma 6.6 and GNOME 50 performance on Ubuntu 26.04 beta while using the new NVIDIA 595.58.03 Linux driver.

Intel Xe Driver Improves Memory Pressure / Out-Of-Memory Behavior For vRAM With Linux 7.1

Following the Intel Xe kernel graphics driver pull request landing transparent hugepages for device pages as an SVM win, another round of Intel Xe driver updates were sent out this week ahead of next month’s Linux 7.1 merge window. This latest pull request lands a new user-space API for helping the Intel Xe driver better cope with situations of video memory pressure / out-of-memory behavior for vRAM…

AI bug reports went from junk to legit overnight, says Linux kernel czar

Greg Kroah-Hartman can’t explain the inflection point, but it’s not slowing down or going awayInterview I was at a press luncheon at KubeCon Europe this week when, to my surprise, who should sit down next to me but long-term Linux kernel maintainer Greg Kroah-Hartman. Greg, who lives in the Netherlands these days, was there to briefly comment on AI, Linux, and security. We spoke about how, over the last month, AI-driven activity around Linux security and code review has “really jumped” in a way no one in the open source world saw coming.…

Linux Patches Posted To Fix ~2x Performance Drop For CPU Workloads On NVIDIA Vera Rubin

An important set of Linux scheduler patches were posted for review on Thursday for improving the SMT-aware asymmetric CPU capacity handling. These patches to improve the Linux kernel scheduler around CPU Simultaneous Multi-Threading (SMT) is needed after NVIDIA engineers discovered up to a ~2x performance drop for CPU-intensive workloads on their upcoming Vera Rubin platform…