Checkmarx analysts have discovered a new batch of malware in the PyPi repository – this time, the malicious packages turned out to be quite extraordinary: they do not steal account data or environment variables, but attack...
Author - Emma Davis
Developers Oppose Tracking Cookies on GitHub
The developer community is extremely unhappy with the upcoming privacy policy changes on GitHub – the new rules will allow GitHub to place “tracking” cookies on some subdomains. me remind you that we also wrote...
Yanluowang Ransomware Hacked Cisco
Cisco representatives confirmed that in May, Yanluowang extortionist group hacked the company’s corporate network. , the attackers tried to extort money from Cisco, otherwise threatening to publish the data stolen during...
10 Malicious PyPI Packages Steal Credentials
Another case of malware penetration into PyPI was discovered – 10 malicious packages were removed from the repository at once, as they could steal data from developers, including passwords and API tokens. problem is being...
Microsoft Experts Warn That Windows Devices on New CPUs Can Corrupt Data
Microsoft engineers have warned that devices running Windows 11 and Windows Server 2022 with new supported CPUs may “corrupt data” for users in some way. the company warns about the risk of data loss, it doesn’t...
The Student Makes a Joke and Placed the Ransomware in the PyPI Repository
Encryptors were found in the PyPI repository: three malicious packages at once (requesys, requesrs and requesr), engaged in typesquatting and faking the popular Requests package. All three packages were ransomware and, as it...
Due to an Unknown Bug, Funds Were Stolen from Thousands of Solana Cryptocurrency Wallets
Users of the Solana platform suffered from an attack that emptied about 8,000 cryptocurrency wallets containing millions of dollars. Apparently, specific wallets turned out to be vulnerable to a certain bug, and not blockchain or...
Many Repositories on GitHub Are Cloned and Distribute Malware
Developer Stephen Lacy stirred up the community by stating on Twitter that he had uncovered a “massive malware attack” on GitHub that affected about 35,000 repositories. However, it turned out that it was not about...
Over 3200 Apps Expose Twitter API Keys
Security firm CloudSEK has identified 3,207 mobile apps that expose Twitter API keys to the public, allowing attackers to take over Twitter user accounts associated with those apps. the way, we also wrote that Apps that spread...
Attackers Hack into Microsoft SQL Servers and Turn Them into Proxies
Attackers hack into Microsoft SQL servers, turning them into proxy servers, which they then rent out for money. Korean company Ahnlab talks about a malicious campaign in which hackers steal someone else’s bandwidth by...