Security News

Researchers Uncover Flaws in Python Package for AI Models and PDF.js Used by Firefox
2024-05-21 10:22

A critical security flaw has been disclosed in the llama_cpp_python Python package that could be exploited by threat actors to achieve arbitrary code execution. Tracked as CVE-2024-34359 (CVSS...

Malicious Python Package Hides Sliver C2 Framework in Fake Requests Library Logo
2024-05-13 06:18

Cybersecurity researchers have identified a malicious Python package that purports to be an offshoot of the popular requests library and has been found concealing a Golang-version of the Sliver...

Fake job interviews target developers with new Python backdoor
2024-04-26 14:20

A new campaign tracked as "Dev Popper" is targeting software developers with fake job interviews in an attempt to trick them into installing a Python remote access trojan. The developers are asked to perform tasks supposedly related to the interview, like downloading and running code from GitHub, in an effort to make the entire process appear legitimate.

Hackers Deploy Python Backdoor in Palo Alto Zero-Day Attack
2024-04-13 08:25

Threat actors have been exploiting the newly disclosed zero-day flaw in Palo Alto Networks PAN-OS software dating back to March 26, 2024, nearly three weeks before it came to light yesterday. The...

Telegram fixes Windows app zero-day used to launch Python scripts
2024-04-12 18:46

Telegram fixed a zero-day vulnerability in its Windows desktop application that could be used to bypass security warnings and automatically launch Python scripts. The next day, a proof of concept exploit was shared on the XSS hacking forum explaining that a typo in the source code for Telegram for Windows could be exploited to send Python.

Python's PyPI Reveals Its Secrets
2024-04-11 11:32

GitGuardian is famous for its annual State of Secrets Sprawl report. In their 2023 report, they found over 10 million exposed passwords, API keys, and other credentials exposed in public GitHub...

Python's PyPI Reveals Its Secrets
2024-04-11 11:32

GitGuardian is famous for its annual State of Secrets Sprawl report. In their 2023 report, they found over 10 million exposed passwords, API keys, and other credentials exposed in public GitHub...

Over 170K users caught up in poisoned Python package ruse
2024-03-25 18:00

More than 170,000 users have been affected by an attack using fake Python infrastructure with "Successful exploitation of multiple victims." The attacker hinged on various supply chain attack techniques to distribute malware-infected Python PyPI packages.

Watch Out: These PyPI Python Packages Can Drain Your Crypto Wallets
2024-03-12 12:13

Threat hunters have discovered a set of seven packages on the Python Package Index (PyPI) repository that are designed to steal BIP39 mnemonic phrases used for recovering private keys of a...

New Python-Based Snake Info Stealer Spreading Through Facebook Messages
2024-03-07 07:39

Facebook messages are being used by threat actors to a Python-based information stealer dubbed Snake that’s designed to capture credentials and other sensitive data. “The credentials harvested...