Malicious package flood on PyPI might be sign of new attacks to come
The PyPI package flood is just the latest in a string of attacks on public repositories with the intent to plant malicious code.
Stay updated with breaking news from Python Package Index. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
The PyPI package flood is just the latest in a string of attacks on public repositories with the intent to plant malicious code.
Patches released for Microsoft Exchange, SAP, Apple and Adobe products, and more. Welcome to Cyber Security Today. It's Wednesday, February 15th, 2023. I'm Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S. Microsoft issued a number of important security updates on Patch Tuesday. One affects all Exchange servers dating back to
In just two days, the malicious PyPI packages were downloaded hundreds of times.
Open-source software (OSS) sits at the center of almost every digital technology moving the world since the early 1980s—laptops, cellphones, widespread internet connectivity, cloud computing, social media, automation, all the rainbow flavors of e-commerce, and even secure communications and anti-censorship tools.
Welcome to the latest edition of The Week in Security, which brings you the newest headlines from both the world and our team across the full stack of security: application security, cybersecurity, and beyond. This week: A new software supply chain attack has been discovered on PyPI. Also: A ransomware attack on ship management software affects 1,000 vessels.