ThePSF, to python
@ThePSF@fosstodon.org avatar

On this #PiDay, we want to remind you that our love for #python is infinite! Give the unique and unrepeatable love of Python* to yourself or a friend 💙💛 grab the @nostarch Humble Bundle today!

pypi, to random

PyPI now has an improved way to report #malware, via #PyPI itself! Available on web and preview beta API. Learn more and sign up to help test:

https://blog.pypi.org/posts/2024-03-06-malware-reporting-evolved/

kubikpixel, to python
@kubikpixel@chaos.social avatar

:python: Lazarus Exploits Typos to Sneak PyPI into Systems:
The notorious 'n state-backed hacking group Lazarus uploaded four packages to the Package Index () repository with the goal of infecting 'er systems with malware.

😁 https://thehackernews.com/2024/02/lazarus-exploits-typos-to-sneak-pypi.html

mistersql, to python
@mistersql@mastodon.social avatar

#pypi #python - Did someone already write a tool to front run safety or pip-audit before anything is installed? I guess something like "poetry lock" and then audit the files for suspicious situations, like CVEs or the repo was created yesterday or the package was published yesterday.

Installing everything then running safety imho has always been !@#$!@$ stupid because the malicious code runs during install.

pypi, to python

Looking back at 2023 @miketheman uncovered some impressive metrics that we want to share! A big thanks to Fastly- And also @awsopen for making Mike’s job possible! #thankyou #PyPI #python

ketmorco, to streaming
@ketmorco@fosstodon.org avatar

Hey friends! After a long hiatus, I'm starting again - as mentioned in an earlier post, I'm going to be figuring out how to create / repos. I've done some very simple in the past, and may do some work on that, too. We'll see what we can get done in the time I'll be spending.

https://www.twitch.tv/wayneswonderarium

(boosts welcome)

DanielJDufour, to python
@DanielJDufour@mastodon.social avatar

Are there any examples of governments (federal, state or local) that have requested an org on #pypi ?

#python #civictech

mistersql, to python
@mistersql@mastodon.social avatar

When someone republishes an identical (?) copy of a major package under their own name on , that's probably malicious right? This is a variation on typosquatting.

https://pypi.org/user/LukeSamkharadze/

mistersql,
@mistersql@mastodon.social avatar

Today I learned about the inspector website, browse the contents of a package before you install it! Much easier than the download, unzip, etc.

https://inspector.pypi.io/

venthur, to python
@venthur@mastodon.social avatar

Inspired by @fcodvpt post about current popularity of build backends, I investigated how the popularity of build backends used in pyproject.toml evolved over time since PEP-0517 introduced them in 2015:

https://venthur.de/2024-01-26-build-backends.html

,

image/png

sethmlarson, to python
@sethmlarson@fosstodon.org avatar

Security Developer-in-Residence weekly update 26: Releases on @pypi are never “done”

#python #pypi #security #opensource #oss

https://sethmlarson.dev/security-developer-in-residence-weekly-report-26

wnd, to python
@wnd@fosstodon.org avatar

For those interested in such things I have had a go at writing a #python module "parenx" ("pare" + "nx") that simplifies linear networks, such as road and rail, using buffering and either image skeletonization or Voronoi polygons to identify a centre-line

As it is on #PyPi so it is available via #pip

It is beta-code and has a number of limitations but hopefully it might be of interest. Noting that two-dimension areal interpolation problem seems well understood

https://github.com/anisotropi4/parenx

thenewoil, to linux
0x58, to Cybersecurity

📨 Latest issue of my curated #cybersecurity and #infosec list of resources for week #01/2024 is out! It includes the following and much more:

➝ 🇺🇸 🖼️ MAJOR US #MUSEUMS SUFFER #CYBERATTACK FALLOUT
➝ 🇪🇸 📡 A “ridiculously weak“ password causes disaster for #Spain’s No. 2 mobile carrier
➝ 🔓 🧬 #23andMe tells victims it’s their fault that their data was breached
➝ 🔓 💸 #OrbitChain loses $86 million in the last #fintech hack of 2023
➝ 🔓 🅿️ Europe’s Largest Parking App Provider Informs Customers of Data Breach
➝ 💸 🙊 #Crypto wallet founder loses $125,000 to fake airdrop website
➝ 🇺🇸 ⚖️ US Says 19 People Charged Following 2019 Takedown of #xDedic Cybercrime Marketplace
➝ 🇵🇸 🇮🇱 Palestinian Hackers Hit 100 Israeli Organizations in Destructive Attacks
➝ 🔓 ❌ Hacked #Mandiant X Account Abused for #Cryptocurrency Theft
➝ 🇳🇬 🇺🇸 ⚖️ Nigerian hacker arrested for stealing $7.5M from charities
➝ 🇦🇱 📡 Albanian Parliament and One Albania Telecom Hit by Cyber Attacks
➝ 🇺🇸 The FBI is adding more cyber-focused agents to U.S. embassies
➝ 🇺🇸 ⚖️ Former #BreachForums admin to be jailed until Jan. 19 sentencing
➝ 🇺🇸 💰 DOJ Slams #XCast with $10 Million Fine Over Massive Illegal Robocall Operation
➝ 📷 🥸 #Google Contractor Pays Parents $50 to Scan Their Childrens' Faces
➝ 💰 🥸 Google Settles $5 Billion #Privacy Lawsuit Over Tracking Users in 'Incognito Mode'
➝ 🇨🇳 🗳️ #Taiwan to reveal Chinese election interference after Saturday’s vote
➝ 🦠 💰 #Merck Settles #NotPetya Insurance Claim, Leaving #Cyberwar Definition Unresolved
➝ 🦠 🇰🇵 SpectralBlur: New #macOS Backdoor Threat from North Korean Hackers
➝ 🦠 🐍 3 Malicious #PyPI Packages Found Targeting #Linux with Crypto Miners
➝ 🦠 🎠 New Bandook #RAT Variant Resurfaces, Targeting #Windows Machines
➝ 🦠 🎠 UAC-0050 Group Using New #Phishing Tactics to Distribute Remcos RAT
➝ 🦠 🇺🇦 CERT-UA Uncovers New #Malware Wave Distributing OCEANMAP, MASEPIE, STEELHOOK
➝ 🔓 🦠 Free Decryptor Released for #BlackBasta Ransomware
➝ 🐛 📨 #SMTP Smuggling: New Flaw Lets Attackers Bypass Security and Spoof #Emails
➝ 🩹 #Ivanti warns critical EPM #bug lets hackers hijack enrolled devices
➝ 🩹 Google Patches Six Vulnerabilities With First #Chrome Update of 2024
➝ 🩹 🐡 Millions still haven’t patched #Terrapin SSH protocol #vulnerability

Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-012024

governa, to linux
@governa@fosstodon.org avatar

Beware: 3 Malicious #PyPI Packages Found Targeting #Linux with Crypto Miners

https://thehackernews.com/2024/01/beware-3-malicious-pypi-packages-found.html

securityaffairs, to hacking Italian
miketheman, to python
@miketheman@hachyderm.io avatar

Happy New Year! 🎉

As of today, is now required on @pypi :python_logo:

Read more here: https://blog.pypi.org/posts/2024-01-01-2fa-enforced/

yodan, to python

A pernicious potpourri of Python packages in PyPI

The past year has seen over 10,000 downloads of malicious packages hosted on the official Python package repository

#Python #PyPI #Security

https://www.welivesecurity.com/en/eset-research/pernicious-potpourri-python-packages-pypi/

mgorny, to gentoo Polish
@mgorny@pol.social avatar

3 miesiące temu wnioskowałem o transfer projektu tyrian-sphinx-theme na — to szablon dokumentacji , do którego straciliśmy dostęp, kiedy jego autor nagle opuścił dystrybucję. Przez ten czas nie było żadnego odzewu. I tak, wiem, że praktycznie wszystkie podobne wnioski stoją w miejscu.

https://github.com/pypi/support/issues/3148

Żeby uniknąć podobnych sytuacji w przyszłości, wnioskowałem również o utworzenie organizacji Gentoo. Ta prośba również czeka już 3 miesiące, bez jakiegokolwiek odzewu. Wzdych.

Ekosystem Pythona jest super. Mówcie mi dalej, że dystrybucje nie powinny robić własnych paczek dla Pythonowych projektów.

sethmlarson, to python
@sethmlarson@fosstodon.org avatar

🚨 PSA: is requiring in 2024 to publish new releases. If you're a developer of packages then you need to enable 2FA in addition to adopting either Trusted Publishers or API tokens before publishing new releases.

Data from today shows less than 10% of PyPI's accounts have 2FA enabled: https://p.datadoghq.com/sb/7dc8b3250-389f47d638b967dbb8f7edfd4c46acb1

governa, to random
@governa@fosstodon.org avatar
0x58, to Cybersecurity

📨 Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

➝ 🔓 🇯🇵 confirms breach after Medusa threatens to leak data
➝ 🇺🇸 😂 Ransomware gang files complaint over victim’s undisclosed
➝ 🔓 🪶 Attackers claim Plume Design, Inc data breach
➝ 🇺🇸 💰 paid ransom after hack that disrupted markets, say
➝ 🔓 Says No Evidence of Breach After Ransomware Gang Claims Hack via Third Party
➝ 🔓 ✈️ Hackers swipe Booking.com, damage from attack is global
➝ 🇷🇺 🇺🇦 Russian Group Deploys USB in Targeted Attacks
➝ 🇮🇱 🇺🇸 Israeli Man Who Made $5M From Hacking Scheme Sentenced to Prison in US
➝ 🇫🇮 ⚖️ Alleged Extortioner of Psychotherapy Patients Faces Trial
➝ 🇺🇸 💸 ransomware exploits in attacks, 10K servers exposed
➝ 🇺🇸 ⚖️ botnet with 23,000 proxies for malicious traffic dismantled
➝ 👶🏻 🧨 Teens with “digital bazookas” are winning the ransomware war, researcher laments
➝ 💸 feature abused to steal $60 million from 99K victims
➝ 🇩🇰 🇷🇺 Hit With Largest on Record
➝ 🇨🇳 🇰🇭 Chinese Hackers Launch Covert Attacks on 24 Cambodian Organizations
➝ 🇲🇾 Major Phishing-as-a-Service Syndicate '' Dismantled by Malaysian Authorities
➝ 🇪🇺 🥳 EU Parliament committee rejects mass scanning of private and encrypted communications
➝ 🩹 Patch Tuesday: 90 Vulnerabilities Addressed by Siemens and Schneider Electric
➝ 🦠 🐍 27 Malicious Packages with Thousands of Downloads Found Targeting IT Experts
🇻🇳 🇮🇳 Vietnamese Hackers Using New -Powered to Target Indian Marketers
➝ 🔐 Adds Support to New Titan Security Key
➝ 🐛 Zero-Day Flaw in Email Software Exploited by Four Hacker Groups
➝ 🩹 Patches Critical Vulnerability in Business One Product
➝ 🐛 New CPU flaw impacts Intel desktop and server systems
➝ 🐛 New AMD attack lets hackers gain root in Linux VMs

📚 This week's recommended reading is: "Tribe of Hackers: Cybersecurity Advice from the Best Hackers in the World" by @marcusjcarey and Jennifer Jin

Subscribe to the newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-462023

governa, to random
@governa@fosstodon.org avatar

27 Malicious Packages with Thousands of Downloads Found Targeting IT Experts ⚠️

https://thehackernews.com/2023/11/27-malicious-pypi-packages-with.html

jbzfn, to python
@jbzfn@mastodon.social avatar

🐍 Developers can’t seem to stop exposing credentials in publicly accessible code
@arstechnica

「 Researchers from security firm GitGuardian this week reported finding almost 4,000 unique secrets stashed inside a total of 450,000 projects submitted to PyPI, the official code repository for the Python programming language 」

https://arstechnica.com/?p=1984368

#Python #PyPI #Cybersecurity

itnewsbot, to security

Developers can’t seem to stop exposing credentials in publicly accessible code - Enlarge (credit: Victor De Schwanberg/Science Photo Library via Getty I... - https://arstechnica.com/?p=1984368 #coderepositories #credentials #passwords #security #biz#pypi

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • ngwrru68w68
  • everett
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • rosin
  • Durango
  • ethstaker
  • Youngstown
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • Leos
  • osvaldo12
  • tacticalgear
  • cubers
  • cisconetworking
  • anitta
  • provamag3
  • modclub
  • mdbf
  • GTA5RPClips
  • tester
  • megavids
  • normalnudes
  • lostlight
  • All magazines