The Django team has issued new security releases for the popular Python web framework, addressing two vulnerabilities...
Python
The Apache Fory project, a high-performance multi-language serialization framework, has disclosed a critical vulnerability (CVE-2025-61622) that could...
Zscaler ThreatLabz has uncovered yet another supply chain attack against the Python Package Index (PyPI). In August...
CYFIRMA has released a detailed threat intelligence assessment of XillenStealer, an emerging open-source, Python-based malware family that...
The PyInstaller project has released fixes for a local privilege escalation vulnerability that affected applications packaged with...
The Django Software Foundation has patched a high-severity SQL injection vulnerability in Django’s FilteredRelation feature. Tracked as...
The Django Software Foundation has released important security updates for multiple supported versions of the popular Python...
Elon Musk’s artificial intelligence company, xAI, has announced the launch of a new coding agent model named...
Zscaler’s ThreatLabz team has issued a warning after uncovering a malicious Python package on the Python Package...
The Python Package Index (PyPI) is taking a significant step toward securing the open-source software supply chain...
The Python Package Index (PyPI) has announced a set of new upload restrictions aimed at protecting Python...
GitLab’s Vulnerability Research team has exposed a sophisticated cryptocurrency theft campaign targeting the Bittensor decentralized AI network...
A study from the New Jersey Institute of Technology has exposed a massive web of hidden vulnerabilities...
A newly discovered vulnerability in Python’s tarfile module, identified as CVE-2025-8194, threatens to hang applications that process...
In a recent analysis, AhnLab’s Security Intelligence Center (ASEC) has uncovered an emerging threat targeting misconfigured and...
Imperva researchers have uncovered a supply chain attack masquerading as a popular Python utility. The package in...
Socket’s Threat Research Team has uncovered a malicious Python package named psslib designed to abruptly shut down...
A newly disclosed vulnerability in Python’s tarfile module—CVE-2025-4517—has exposed a critical security risk that allows attackers to...
A newly uncovered software supply chain campaign by the threat group Banana Squad has compromised more than...
A high-severity vulnerability has been uncovered in the pure-Python backend of Google’s Protocol Buffers (protobuf), potentially allowing...