home.social

#maliciouscode — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #maliciouscode, aggregated by home.social.

fetched live
  1. Malicious Code Infiltrates Python Package Index

    A recent supply-chain attack on a popular Python package has raised a critical question: how much trust do you really have in the software that quietly powers your work? A malicious .pth file hidden in the litellm package version 1.82.8 can automatically execute malicious code on every Python startup.

    osintsights.com/malicious-code

    #SupplyChain #PythonPackageIndex #MaliciousCode #EmergingThreats #SoftwareCompromise

  2. 📢 Oh no, the Telnyx Python SDK has been breached! 😱 Apparently, someone thought it was a great idea to sneak malicious code into #PyPI. 🚨 This is what happens when your "supply chain security" is more like "supply chain Swiss cheese." 🧀🔒
    telnyx.com/resources/telnyx-py #TelnyxSDK #Breach #MaliciousCode #SupplyChainSecurity #Vulnerability #HackerNews #ngated

  3. 📢 Oh no, the Telnyx Python SDK has been breached! 😱 Apparently, someone thought it was a great idea to sneak malicious code into #PyPI. 🚨 This is what happens when your "supply chain security" is more like "supply chain Swiss cheese." 🧀🔒
    telnyx.com/resources/telnyx-py #TelnyxSDK #Breach #MaliciousCode #SupplyChainSecurity #Vulnerability #HackerNews #ngated

  4. When I use Channel4(UK) app, whenever a McDonald's advert comes on, the app will freeze on an image while subtitles and sound usually carry on -- causing me to need to close the app.

    I call this the Channel4 "Google Play Services, Adobe, Location Tracking, Malicious Code" glitch. 👍

    #Google #Android #Adobe #LocationTracking #MaliciousCode #Channel4UK #SpyCops

  5. When I use Channel4(UK) app, whenever a McDonald's advert comes on, the app will freeze on an image while subtitles and sound usually carry on -- causing me to need to close the app.

    I call this the Channel4 "Google Play Services, Adobe, Location Tracking, Malicious Code" glitch. 👍

    #Google #Android #Adobe #LocationTracking #MaliciousCode #Channel4UK #SpyCops

  6. "Just because a piece of software is #OpenSource it does not mean the software is secure." --me

    I've been saying that for years and it really bothers me to hear developers and users alike quip that because a package is open source it automatically means it's more secure than a comparable package that is closed-source.

    As EricS. Raymond, one of the people behind open source, said in Linus's Law, "Given enough eyeballs, all bugs are shallow." If no one is looking, though -- as appears to be the case here — then simply because a codebase is open, it doesn't provide any safety or security at all.
    https://www.zdnet.com/article/hacker-slips-malicious-wiping-command-into-amazons-q-ai-coding-assistant-and-devs-are-worried/

    https://developers.slashdot.org/story/25/07/26/0352242/hacker-slips-malicious-wiping-command-into-amazons-q-ai-coding-assistant

    #amazon #hacker #hacking #github #PullRequest #patch #vulnerability #ComputerSecurity #InformationSecurity #ITSecurity #MaliciousCode #aws #q #ai #agent #vscode

  7. 🚨 Malicious commits target GitHub projects! A Texas researcher claims someone is impersonating him to sabotage his reputation. 🛑👨‍💻 #GitHub #CyberSecurity #MaliciousCode #TechNews #Hacking #DataBreach #OpenSource #IdentityTheft #CyberAttack #ResearchNews

  8. 🚨 Malicious commits target GitHub projects! A Texas researcher claims someone is impersonating him to sabotage his reputation. 🛑👨‍💻 #GitHub #CyberSecurity #MaliciousCode #TechNews #Hacking #DataBreach #OpenSource #IdentityTheft #CyberAttack #ResearchNews