A newly disclosed vulnerability in Python’s tarfile module—CVE-2025-4517—has exposed a critical security risk that allows attackers to...
Python
A newly uncovered software supply chain campaign by the threat group Banana Squad has compromised more than...
A high-severity vulnerability has been uncovered in the pure-Python backend of Google’s Protocol Buffers (protobuf), potentially allowing...
The CPython project has issued a security advisory addressing five vulnerabilities—including one CRITICAL and three HIGH-severity flaws—affecting...
Socket’s Threat Research Team has uncovered a sophisticated supply chain attack on the Python Package Index (PyPI)...
Researchers have disclosed two critical vulnerabilities in Langroid, a popular Python framework designed for building large language...
The Python Packaging Authority (PyPA) has patched a serious path traversal vulnerability in the widely-used setuptools project....
A newly disclosed vulnerability in the Tornado Python web framework, tracked as CVE-2025-47287, exposes applications to a...
A serious security flaw has been identified in the Reflex open-source framework, a tool used to build...
In a detailed technical report, Socket’s Threat Research Team uncovered seven malicious Python packages published to the...
In a detailed report by Cyfirma, researchers have uncovered a Python-based Remote Access Trojan (RAT) that leverages...
The eSentire’s Threat Response Unit (TRU) discovered a sophisticated cyberattack campaign linking SocGholish (also known as FakeUpdates)...
A critical vulnerability tracked as CVE-2025-43859 has been disclosed in h11, a minimalist, I/O-agnostic HTTP/1.1 protocol library...
On April 14, 2025, the Python Package Index (PyPI) team swiftly addressed a security concern involving persisting...
Spammers are constantly adapting their tactics to exploit new digital communication channels. A recent report by SentinelLABS...
vLLM, a popular library for Large Language Model (LLM) inference and serving, has recently addressed a critical...
A critical vulnerability has been discovered in ‘python-json-logger’, a popular Python library used for generating JSON logs....
A new cybersecurity report from The Splunk Threat Research Team has uncovered a widespread infostealer and cryptomining...
Security researchers at Kaspersky Labs have uncovered a large-scale cybercrime campaign, dubbed GitVenom, that targets GitHub users...
IBL Software Engineering has issued a security advisory regarding a critical Remote Code Execution (RCE) vulnerability affecting...