Skip to content
GeekWire
  • HOME
  • NEWS
    • CERT
    • EXPLOITS
    • NCSC
    • NVD
    • SECURELIST
    • US-CERT
  • BLOG
    • Books
    • OSINT
    • Pentest
    • Privacy
  • GHDB
  • CHDB
  • OSINT
  • LABS
  • ARCHIVE
  • ABOUT
    • Privacy Policy
    • Terms of Use
    • External Links
    • Sitemap
GeekWire
GeekWire
  • HOME
  • NEWS
    • CERT
    • EXPLOITS
    • NCSC
    • NVD
    • SECURELIST
    • US-CERT
  • BLOG
    • Books
    • OSINT
    • Pentest
    • Privacy
  • GHDB
  • CHDB
  • OSINT
  • LABS
  • ARCHIVE
  • ABOUT
    • Privacy Policy
    • Terms of Use
    • External Links
    • Sitemap

PyPI

Boffins rate npm and PyPI package security and it’s not good

11 August 2022

The Open Source Security Foundation (OpenSSF), as its name plainly states, aims to help make open source software more secure, but …

Tags IT, News, PyPI

Experts found 10 malicious packages on PyPI used to steal developers’ data

10 August 2022

10 packages have been removed from the Python Package Index (PyPI) because they were found harvesting data. Check Point researchers have …

Tags Found, Libraries, Programming, PyPI, Repository

10 malicious Python packages exposed in latest repository attack

9 August 2022

Researchers have discovered yet another set of malicious packages in PyPi, the official and most popular repository for Python programs …

Tags Found, Libraries, Programming, PyPI, Repository

New Malicious Python Libraries Found on PyPI Repository

9 August 2022

Security researchers from Check Point have spotted 10 malicious packages on Python Package Index (PyPI), the primary Python package index …

Tags Found, Libraries, Programming, PyPI, Repository

10 Credential Stealing Python Libraries Found on PyPI Repository

9 August 2022

In what’s yet another instance of malicious packages creeping into public code repositories, 10 modules have been removed from the Python …

Tags Check Point, Found, Libraries, PyPI, Python Package Index

10 Malicious Code Packages Slither into PyPI Registry

8 August 2022

The discovery adds to the growing list of recent incidents where threat actors have used public code repositories to distribute malware in …

Tags Cyber Threats, Malicious Software, Packages, PyPI, Registry

School Kid Uploads Ransomware Scripts to PyPI Repository as ‘Fun’ Project

3 August 2022

The malware packages had names that were common typosquats of a legitimate widely used Python library. One was downloaded hundreds of …

Tags Projects, PyPI, Ransomware, Repository, Schools

Sonatype shines light on typosquatting ransomware threat in PyPI

3 August 2022

Miscreants making use of typosquatting are being spotted by researchers at Sonatype, emphasizing the need to check that the package is …

Tags IT, News, PyPI, Sonatype

A week in security (July 11 – July 17)

18 July 2022

Last week on Malwarebytes Labs: Elden Ring maker Bandai Namco hit by ransomware and data leaks Predatory Sparrow massively disrupts steel …

Tags IT, News, PyPI

PyPI Mandates 2FA, Plans Google Titan Key Giveaway

12 July 2022

Python’s most popular package manager is intent on securing the supply chain by requiring developers to enable two-factor …

Tags Giveaways, Google, Keys, Plans, PyPI

Python programming: PyPl is rolling out 2FA for critical projects, giving away 4,000 security keys

11 July 2022

4,000 Google Titan security keys should help to protect critical Python projects from software supply chain …

Tags Critical, Programming, Projects, PyPI, Repository

PyPI Repository Makes 2FA Security Mandatory for Critical Python Projects

11 July 2022

The maintainers of the official third-party software repository for Python have begun imposing a new two-factor authentication (2FA) …

Tags Critical, Projects, PyPI, Repository, Software Supply Chain

Hijacking of popular ctx and phpass packages reveals open source security gaps

26 May 2022

The Python module “ctx” and a fork of the PHP library “phpass” have recently been modified by an unknown attacker to grab AWS …

Tags Hijacking, IT, PHP, PyPI, Python

Popular PyPI Package ‘ctx’ and PHP Library ‘phpass’ Hijacked to Steal AWS Keys

24 May 2022

Two trojanized Python and PHP packages have been uncovered in what’s yet another instance of a software supply chain attack targeting the …

Tags Malicious, Popular, Programming, Programming Languages, PyPI
Post navigation
Older posts
Page1 Page2 Next →
Cookie-Free

NVD

  • CVE-2022-2748 – A vulnerability was found in SourceCodester Simple Online Book Store System. It has been c …11 August 2022
  • CVE-2021-0734 – In Settings, there is a possible way to determine whether an app is installed without quer …11 August 2022
  • CVE-2022-20250 – In Messaging, there is a possible way to attach files to a message without proper access c …11 August 2022
  • CVE-2022-20378 – Product: AndroidVersions: Android kernelAndroid ID: A-234657153References: N/A …11 August 2022
  • CVE-2022-28750 – Zoom On-Premise Meeting Connector Zone Controller (ZC) before version 4.8.20220419.112 fai …11 August 2022
  • CVE-2022-35673 – Adobe FrameMaker versions 2019 Update 8 (and earlier) and 2020 Update 4 (and earlier) are …11 August 2022

EXPLOITS

  • PAN-OS 10.0 – Remote Code Execution (RCE) (Authenticated)9 August 2022
  • ThingsBoard 3.3.1 ‘description’ – Stored Cross-Site Scripting (XSS)9 August 2022
  • ThingsBoard 3.3.1 ‘name’ – Stored Cross-Site Scripting (XSS)9 August 2022
  • Feehi CMS 2.1.1 – Stored Cross-Site Scripting (XSS)9 August 2022
  • Prestashop blockwishlist module 2.1.0 – SQLi9 August 2022
  • uftpd 2.10 – Directory Traversal (Authenticated)3 August 2022

SECURELIST

  • OpenTIP, command line edition11 August 2022
  • VileRAT: DeathStalker’s continuous strike at foreign and cryptocurrency exchanges10 August 2022
  • Andariel deploys DTrack and Maui ransomware9 August 2022
  • Targeted attack on industrial enterprises and public institutions8 August 2022
  • DDoS attacks in Q2 20223 August 2022
  • LofyLife: malicious npm packages steal Discord tokens and bank card data28 July 2022
Copyright © 2022 GeekWire | Cookie-Free | Privacy Policy | We are not responsible for the content of external sites.
Next Page »