Get a Pentest and security assessment of your IT network.

Cyber Security

PyPI Python Package Repository Patches Critical Supply Chain Flaw

The maintainers of Python Package Index (PyPI) last week issued fixes for three vulnerabilities. One among which could be abused to achieve arbitrary code execution and take full control of the official third-party software repository. The security weaknesses were discovered and reported by Japanese security researcher RyotaK. He was awarded a total of $3,000 as part of the bug bounty program. The vulnerabilities described in this article had a significant impact on the Python ecosystem, he noted. “As I’ve mentioned several times before, some supply chains have critical vulnerabilities,” he said.

Source: https://thehackernews.com/2021/08/pypi-python-package-repository-patches.html

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security