thumbnail Using Trusted Protocols Against You: Gmail as a C2 Mechanism...
thumbnail Carding tool abusing WooCommerce API downloaded 34K times on PyPI
thumbnail Python Crypto Library Updated to Steal Private Keys
thumbnail Fake recruiter coding tests target devs with malicious Python packages
thumbnail Xeon Sender | SMS Spam Shipping Multi-Tool Targeting SaaS Credentials
thumbnail Iraq-based cybercriminals deploy malicious Python packages to steal data
thumbnail Russia-linked 'Lumma' crypto stealer now targets Python devs
thumbnail Cybercriminals pose as "helpful" Stack Overflow users to push malware
thumbnail Over 170K users hit by poisoned Python package ruse
thumbnail ‘Wall of Flippers’ detects Flipper Zero Bluetooth spam attacks
thumbnail A pernicious potpourri of Python packages in PyPI
thumbnail Nothing new, still broken, insecure by default since then: Python's e-mail libraries and certificate verification
thumbnail Python obfuscation traps
thumbnail The evolutionary tale of a persistent Python threat 
thumbnail New Python NodeStealer Goes Beyond Facebook Credentials, Now Stealing All Browser Cookies and Login Credentials
thumbnail Emerging Threat! Exposing JOKERSPY
thumbnail Bad Actors Are Joining the AI Revolution: Here’s What We’ve Found in the Wild
thumbnail Supply Chain Attack Using Identical PyPI Packages, “colorslib”, “httpslib”, and “libhttps”
thumbnail SentinelSneak: Malicious PyPI module poses as security software development kit
thumbnail A Custom Python Backdoor for VMWare ESXi Servers
thumbnail W4SP continues to nest in PyPI: Same supply chain attack, different distribution method
thumbnail Unpatched 15-year old Python bug allows code execution in 350k projects
thumbnail Tarfile: Exploiting the World With a 15-Year-Old Vulnerability
thumbnail Python packages upload your AWS keys, env vars, secrets to the web
thumbnail Malicious PyPI package opens backdoors on Windows, Linux, and Macs