The serpent’s tongue: Luring the Python out of its denCisco Talos·Jul 14, 10:00 UTC · Jul 14, 2026Malware155
An Easier Way to Keep Old Python Code Healthy and SecureThe Hacker News·Jul 25, 15:47 UTC · Jul 25, 2022Vulnerability55
Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agencyCisco Talos·Mar 14, 11:00 UTC · Mar 14, 2023Threat actor60
Webinar: How to Stop Python Supply Chain Attacks—and the Expert Tools You NeedThe Hacker News·Aug 7, 15:33 UTC · Aug 7, 2025Vulnerability55
Python team fixes bug that allowed takeover of PyPI repositoryThe Record·Dec 14, 00:00 UTC · Dec 14, 2022Vulnerability155
A 15-Year-Old Unpatched Python bug potentially impacts +350K projectsSecurity Affairs·Sep 22, 13:28 UTC · Sep 22, 2022VulnerabilityCVE-2007-4559CVE-2001-126760
Unpatched Python and Java Flaws Let Hackers Bypass Firewall Using FTP InjectionThe Hacker News·Feb 21, 17:45 UTC · Feb 21, 2017Vulnerability155
Mercenary mayhem: A technical analysis of Intellexa's PREDATOR spywareCisco Talos·May 25, 12:02 UTC · May 25, 2023MalwareCVE-2021-37973CVE-2021-37976CVE-2021-38000+2 CVEs60
GitHub Token Leak Exposes Python's Core Repositories to Potential AttacksThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2024Exploit / PoC in the wild160
GitHub adds Python support for security alertsHelp Net Security·Dec 15, 12:29 UTC · Dec 15, 2023Vulnerability55
Researchers Uncover Flaws in Python Package for AI Models and PDF.js Used by FirefoxThe Hacker News·May 21, 10:22 UTC · May 21, 2024VulnerabilityCVE-2024-34359CVE-2024-4367160
Confucius Shifts from Document Stealers to Python BackdoorsInfosecurity Magazine·Oct 2, 14:45 UTC · Oct 2, 2025Malware55
PyPI Repository Makes 2FA Security Mandatory for Critical Python ProjectsThe Hacker News·Jul 11, 05:23 UTC · Jul 11, 2022Industry155
Ransomware gang uses a Python script to encrypt VMware ESXi serversSecurity Affairs·Oct 5, 16:13 UTC · Oct 5, 2021Ransomware160
New Shameless Commodity Cryptocurrency Stealer (WeSteal) and Commodity RAT (WeControl)Palo Alto Unit 42·Jun 6, 12:43 UTC · Jun 6, 2024Malware55
Pakistan-linked Hackers Deploy Python, Golang, and Rust Malware on Indian TargetsThe Hacker News·May 31, 10:03 UTC · May 31, 2024Malware55
Hackers Deploy Python Backdoor in Palo Alto ZeroThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2024Malware in the wildCVE-2024-3400160
Two Additional Malicious Python Libraries Found on PyPI RepositoryInfosecurity Magazine·Aug 16, 17:30 UTC · Aug 16, 2022Vulnerability155
PyPI Repository Enforces 2FA for Critical Python ProjectsInfosecurity Magazine·Jul 11, 16:05 UTC · Jul 11, 2022Industry155
New n8n Vulnerability (9.9 CVSS) Lets Authenticated Users Execute System CommandsThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026VulnerabilityCVE-2025-68668CVE-2025-68613160
Python tarfile vulnerability affects 350,000 open-source projects (CVE-2007-4559)Help Net Security·Sep 22, 00:00 UTC · Sep 22, 2022VulnerabilityCVE-2007-455960
New Malicious Python Libraries Found on PyPI RepositoryInfosecurity Magazine·Aug 9, 17:30 UTC · Aug 9, 2022Malware155
Week in review: Malicious Python packages, FaceApp panic, and how to avoid a biometric dystopiaHelp Net Security·May 28, 11:21 UTC · May 28, 2020Data breachCVE-2019-11580160
Week in review: Python backdoor attacks, Windows zero-days under attack, crowdsourced pentestingHelp Net Security·Mar 29, 00:00 UTC · Mar 29, 2020Malware55
ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ StoriesThe Hacker News·May 15, 00:00 UTC · May 15, 2026VulnerabilityCVE-2026-030060
Open-source security group pulls out of U.S. grant, citing DEI restrictionsCyberScoop·Oct 29, 20:55 UTC · Oct 29, 2025Exploit / PoC in the wild160
PyPI Repository Warns Python Project Maintainers About Ongoing Phishing AttacksThe Hacker News·Aug 26, 05:01 UTC · Aug 26, 2022Phishing & fraud55
10 Credential Stealing Python Libraries Found on PyPI RepositoryThe Hacker News·Aug 10, 05:22 UTC · Aug 10, 2022Malware55
PyPI Python Package Repository Patches Critical Supply Chain FlawThe Hacker News·Aug 2, 10:50 UTC · Aug 2, 2021Vulnerability155
Black Kingdom ransomwareKaspersky Securelist·Jun 17, 09:42 UTC · Jun 17, 2021RansomwareCVE-2021-27065CVE-2019-11510CVE-2021-26855+2 CVEs60
SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model FilesThe Hacker News·Apr 20, 17:14 UTC · Apr 20, 2026VulnerabilityCVE-2026-5760CVE-2024-34359CVE-2025-6162060
Scientists Narrow Down the Hunt for Aliens to 45 Planets404 Media·Mar 21, 13:00 UTC · Mar 21, 2026Industry55
Critical Vulnerabilities Found in NVIDIA's Triton Inference ServerInfosecurity Magazine·Aug 5, 15:45 UTC · Aug 5, 2025VulnerabilityCVE-2025-23319CVE-2025-23320CVE-2025-23334+1 CVEs60
⚡ Weekly Recap: VPN Exploits, Oracle's Silent Breach, ClickFix Surge and MoreThe Hacker News·May 6, 07:05 UTC · May 6, 2025Data breachCVE-2025-22457CVE-2025-24061CVE-2025-2407+15 CVEs60
Security Risks Persist in Open Source EcosystemInfosecurity Magazine·Dec 4, 14:00 UTC · Dec 4, 2024Vulnerability55
PyPI Attack: ChatGPT, Claude Impersonators Deliver JarkaStealer via Python LibrariesThe Hacker News·Nov 23, 06:39 UTC · Nov 23, 2024Malware155
GhostSec’s joint ransomware operation and evolution of their arsenalCisco Talos·Mar 5, 13:00 UTC · Mar 5, 2024Ransomware60
Why Developers Hate Changing Language VersionsThe Hacker News·Jul 8, 11:08 UTC · Jul 8, 2022Vulnerability55