The CPython project has issued a security advisory addressing five vulnerabilities—including one CRITICAL and three HIGH-severity flaws—affecting...
Python
Socket’s Threat Research Team has uncovered a sophisticated supply chain attack on the Python Package Index (PyPI)...
Researchers have disclosed two critical vulnerabilities in Langroid, a popular Python framework designed for building large language...
The Python Packaging Authority (PyPA) has patched a serious path traversal vulnerability in the widely-used setuptools project....
A newly disclosed vulnerability in the Tornado Python web framework, tracked as CVE-2025-47287, exposes applications to a...
A serious security flaw has been identified in the Reflex open-source framework, a tool used to build...
In a detailed technical report, Socket’s Threat Research Team uncovered seven malicious Python packages published to the...
In a detailed report by Cyfirma, researchers have uncovered a Python-based Remote Access Trojan (RAT) that leverages...
The eSentire’s Threat Response Unit (TRU) discovered a sophisticated cyberattack campaign linking SocGholish (also known as FakeUpdates)...
A critical vulnerability tracked as CVE-2025-43859 has been disclosed in h11, a minimalist, I/O-agnostic HTTP/1.1 protocol library...
On April 14, 2025, the Python Package Index (PyPI) team swiftly addressed a security concern involving persisting...
Spammers are constantly adapting their tactics to exploit new digital communication channels. A recent report by SentinelLABS...
vLLM, a popular library for Large Language Model (LLM) inference and serving, has recently addressed a critical...
A critical vulnerability has been discovered in ‘python-json-logger’, a popular Python library used for generating JSON logs....
A new cybersecurity report from The Splunk Threat Research Team has uncovered a widespread infostealer and cryptomining...
Security researchers at Kaspersky Labs have uncovered a large-scale cybercrime campaign, dubbed GitVenom, that targets GitHub users...
IBL Software Engineering has issued a security advisory regarding a critical Remote Code Execution (RCE) vulnerability affecting...
Forcepoint X-Labs exposes a new campaign utilizing Python, TryCloudflare, and Dropbox to spread the notorious AsyncRAT. The...
The RedCurl Advanced Persistent Threat (APT) group, also known as Earth Kapre or Red Wolf, has resurfaced...
In a significant stride toward enhancing security in the Python ecosystem, the Python Package Index (PyPI) has...