📰 Python Package Index News
Python Package Index News Today
Fast, Ad-Free News Updates
Stay updated with breaking news from Python Package Index. Real-time updates on events, politics, business and more.
May 29, 2024
The package posed as an API management tool and downloaded trojanized Windows binaries
May 16, 2024
/PRNewswire/ -- ActiveState, the leading Open Source Management platform for securing enterprise software supply chains, has joined the Python Software...
April 5, 2024
For the first time, an open-source maintainer put malware into a key Linux utility. We're still not sure who or why - but here's what you can do about it.
April 1, 2024
Discover major vulnerabilities from the past week from Cisco, Fortinet, Microsoft, and more along with remediation recommendations.
March 29, 2024
Python code repository PyPI temporarily halted new user registration for a second time in three months following a surge in malware-ridden code mimicking legitimate
March 29, 2024
PyPI repository shuts to stop malicious uploads, a plea to developers to stop creating apps with SQL vulnerabilities, and more. Welcome to Cyber Security Today. It's Friday, March 29th, 2024. I'm Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S. I've reported before that threat actors are increasingly uploading malicious code
March 29, 2024
Typosquatting attack installed malicious packages to harvest credentials and crypto wallet data.
March 29, 2024
Once again, PyPI is facing an unimaginable barrage of attacks
March 28, 2024
Automation is making attacks on open source code repositories harder to fight.
March 12, 2024
Japan's Computer Security Incident Response Team (JPCERT/CC) has issued a warning to developers worldwide following the discovery of four malicious PyPI packages uploaded by the notorious North Korean hacking group, Lazarus.