Overview of the Global Fraud Threat Cybersecurity researchers have just detected a dangerous software campaign targeting Python...
PyPI
In a calculated move that signals the expansion of state-sponsored threats into open-source repositories, researchers at Kaspersky...
A previously undocumented Linux remote access trojan (RAT) has been exposed for its surgical precision in targeting...
The Python ecosystem is reeling from a sophisticated supply chain attack targeting Xinference (Xorbits Inference), a widely...
Researchers at Socket have identified a massive new cluster of malicious packages linked to North Korea’s notorious...
A relentless cyber-espionage campaign has expanded its reach into the heart of the AI development ecosystem. Security...
A deceptive new supply chain attack has been uncovered in the Python ecosystem, where a malicious package...
HelixGuard researchers have uncovered a malicious Python package uploaded to PyPI that impersonates the widely used “pyspellchecker”...
The Socket Threat Research Team has uncovered a growing trend among malicious package developers: leveraging Discord webhooks...
The security of the open-source software supply chain was once again tested when JFrog’s security research team...
The Python Package Index (PyPI) is once again the target of a phishing campaign aimed at maintainers,...
Zscaler’s ThreatLabz team has issued a warning after uncovering a malicious Python package on the Python Package...
The Python Package Index (PyPI) is taking a significant step toward securing the open-source software supply chain...
The Python Package Index (PyPI) has announced a set of new upload restrictions aimed at protecting Python...
GitLab’s Vulnerability Research team has exposed a sophisticated cryptocurrency theft campaign targeting the Bittensor decentralized AI network...
A study from the New Jersey Institute of Technology has exposed a massive web of hidden vulnerabilities...
In a recently expose, Sonatype reveals a covert cyberespionage campaign orchestrated by the North Korea-linked Lazarus Group,...
The Python Package Index (PyPI), the central repository for Python developers around the world, has issued a...
The Socket Threat Research Team has uncovered a coordinated surveillance malware campaign hidden in four open-source packages—three...
Imperva researchers have uncovered a supply chain attack masquerading as a popular Python utility. The package in...