Security News

Telegram fixes Windows app zero-day used to launch Python scripts
2024-04-12 18:46

Telegram fixed a zero-day vulnerability in its Windows desktop application that could be used to bypass security warnings and automatically launch Python scripts. The next day, a proof of concept exploit was shared on the XSS hacking forum explaining that a typo in the source code for Telegram for Windows could be exploited to send Python.

Python's PyPI Reveals Its Secrets
2024-04-11 11:32

GitGuardian is famous for its annual State of Secrets Sprawl report. In their 2023 report, they found over 10 million exposed passwords, API keys, and other credentials exposed in public GitHub...

Python's PyPI Reveals Its Secrets
2024-04-11 11:32

GitGuardian is famous for its annual State of Secrets Sprawl report. In their 2023 report, they found over 10 million exposed passwords, API keys, and other credentials exposed in public GitHub...

Over 170K users caught up in poisoned Python package ruse
2024-03-25 18:00

More than 170,000 users have been affected by an attack using fake Python infrastructure with "Successful exploitation of multiple victims." The attacker hinged on various supply chain attack techniques to distribute malware-infected Python PyPI packages.

Watch Out: These PyPI Python Packages Can Drain Your Crypto Wallets
2024-03-12 12:13

Threat hunters have discovered a set of seven packages on the Python Package Index (PyPI) repository that are designed to steal BIP39 mnemonic phrases used for recovering private keys of a...

New Python-Based Snake Info Stealer Spreading Through Facebook Messages
2024-03-07 07:39

Facebook messages are being used by threat actors to a Python-based information stealer dubbed Snake that’s designed to capture credentials and other sensitive data. “The credentials harvested...

New Python-based FBot Hacking Toolkit Aims at Cloud and SaaS Platforms
2024-01-11 14:00

A new Python-based hacking tool called FBot has been uncovered targeting web servers, cloud services, content management systems (CMS), and SaaS platforms such as Amazon Web Services (AWS),...

Beware, Developers: BlazeStealer Malware Discovered in Python Packages on PyPI
2023-11-08 12:57

A new set of malicious Python packages has slithered their way to the Python Package Index repository with the ultimate aim of stealing sensitive information from compromised developer systems. The packages masquerade as seemingly innocuous obfuscation tools, but harbor a piece of malware called BlazeStealer, Checkmarx said in a report shared with The Hacker News.

SBF on trial: The Python code that allegedly let Alameda hedge fund spend people's FTX deposits
2023-10-10 21:21

At the fraud trial of former FTX head Sam Bankman-Fried, prosecutors presented the jury with Python code for the FTX backend that allowed flagged client accounts to spend money they didn't have on the cryptocurrency exchange. Multiple accounts associated with Alameda Research, the hedge fund controlled by Bankman-Fried that allegedly used billions of dollars of customer deposits in FTX as a slush fund, were flagged thus, according to reported accounts of the testimony of FTX co-founder Gary Wang.

Hundreds of malicious Python packages found stealing sensitive data
2023-10-04 21:31

A malicious campaign that researchers observed growing more complex over the past half year, has been planting on open-source platforms hundreds of info-stealing packages that counted about 75,000 downloads. The campaign has been monitored since early April by analysts at Checkmarx's Supply Chain Security team, who discovered 272 packages with code for stealing sensitive data from targeted systems.