oss-security·2d ago highCVE-2026-97230: IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL#perl#cpan#supply-chainCVE-2026-97230 4 sources
arXiv cs.AI / cs.LG / cs.CL·3d agoCan LLMs Reason About Runtime Behavior? A Repository-Level Dynamic Benchmark#llm#benchmark#code-reasoningAI research
SANS Internet Storm Center·4d agoThe Truth about GET and HTTP Standards, (Tue, Sep 22nd)#apache#http#nginxResearch
Cloudflare Blog·5d agoPython Workers are now generally available#cloudflare#python#workers 2 sources 11 min1
Hugging Face Blog·6d agotokenizers v1: encode, decode and scaling, measured#developer-tools#hugging-face#libraryAI tools & infra
oss-security·12d agoCpython: [CVE-2026-82049] tarfile extraction filters allow file modification and content disclosure via hard link to symlink#archive-extraction#cpython#pythonCVE-2026-820491
oss-security·15d agoCPython: [CVE-2026-87910] tarfile hardlink fallback ignores custom extraction filter rejection via None#archive-extraction#cpython#cve-2026-87910CVE-2026-879101
Ubuntu Security Notices·16d agoUSN-8744-1: Python vulnerabilities#content-injection#denial-of-service#expatCVE-2026-36441
SANS Internet Storm Center·24d agoHoneypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)#cowrie#dshield#honeypot 12 min2
CERT/CC Vulnerability Notes·25d agoVU#456290: Hugging Face Transformers library writes remote code to disk prior to consent check#cve-2026-80047#hugging-face#machine-learningVulnerability1
The Hacker News·25d ago criticalAttackers Exploit Critical Langflow and Rails Flaws in Credential#active-exploitation#credential-harvesting#cryptomining in the wild 3 min1
Palo Alto Unit 42·Aug 17, 2026New Python-Based Payload MechaFlounder Used by Chafer#apt#backdoor#chafer 11 min1
Exploit-DB·Aug 11, 2026 high[remote] PraisonAI praisonaiagents 1.6.77 - Remote Code Execution#ai-agents#llm#pocExploit / PoC