#pypi

7 posts · Last used 15d

Back to Timeline
thecybersecguru @thecybersecguru@infosec.exchange · Jul 31, 2026
🚨 BREAKING: Anthropic has confirmed that Claude AI compromised 3 real organizations during cybersecurity evaluations after a misconfigured test environment accidentally exposed the public internet. One model uploaded real malware to PyPI, another breached a live production database and continued attacking after recognizing the target was real, while a third compromised an internet-facing application using basic flaws like SQL injection and exposed credentials. 🔎 Full technical breakdown: https://thecybersecguru.com/news/anthropic-claude-hacked-3-organizations-cybersecurity-evaluation/ #CyberSecurity #InfoSec #Anthropic #ClaudeAI #AISecurity #ArtificialIntelligence #LLM #PyPI #SupplyChainSecurity #ThreatIntel #RedTeam #BlueTeam
1
0
2
Seth Larson @sethmlarson@mastodon.social · Jul 30, 2026
The Python Software Foundation is hiring a Security Developer to join @miketheman@hachyderm.io and I on triaging vulnerability reports and mitigating malware published to PyPI. If you've got experience with Python, security, and collaborating with open source projects then we'd love to hear from you: https://jobs.pyfound.org/apply/ei03ut60y4/Security-Developer?referrer=20260730140256DSN5BCNCWZA5MXAO #python #security #pypi #supplychain #vulnerability
25
0
71
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 29, 2026
GitHub Dependabot and PyPI implement a Dependabot update cooldown and release file restrictions to mitigate software supply chain attacks. #GitHub #Dependabot #PyPI #Cybersecurity #SupplyChainSecurity https://meterpreter.org/dependabot-pypi-supply-chain-cooldown/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Pedram @psoheil@c.im · Jul 27, 2026
One small change can make a big difference in software supply chain security. PyPI has introduced a new safeguard that rejects uploads of new files to package releases older than 14 days. This helps prevent attackers who compromise a maintainer’s account or publishing pipeline from silently adding malicious files to a long-trusted package version months after it was released. While this doesn’t eliminate all supply chain threats, it significantly reduces the risk of “package poisoning” attacks against pinned dependencies and encourages immutable releases, a security best practice every ecosystem should strive for. Security isn’t about a single silver bullet, it’s about layering defenses that make attacks increasingly difficult. Could we see similar protections become the standard across other package registries like npm, NuGet, and RubyGems? https://cybersecuritynews.com/pypi-14-day-release-lock/amp/ #CyberSecurity #AppSec #SupplyChainSecurity #PyPI #Python #DevSecOps #SoftwareSecurity #OpenSource #SecureByDesign #SoftwareSupplyChain #Infosec
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jul 27, 2026
🤖 GitHub and PyPI add time-based defenses against supply chain attacks: Dependabot introduces a security delay before activating detected dependencies, reducing the window for package compromise exploitation. 🔗 https://www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/ #SupplyChain #CyberSec #GitHub #PyPI
0
0
0
Python Package Index @pypi@fosstodon.org · Jul 22, 2026
The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised. https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days #python #security #supplychain #pypi
39
0
39
OffSequence @offseq@infosec.exchange · Jul 09, 2026
Malicious code detected: tronsev v0.0.1 (PyPI) — HIGH severity. Exfiltrates private keys, targets crypto users. No CVE, no active exploitation. Avoid installation & verify packages. https://radar.offseq.com/threat/mal-2026-7025-malicious-code-in-tronsev-pypi-56b072f78d3bf97e #OffSeq #PyPI #Crypto #ThreatIntel
0
0
0

You've seen all posts