Linux
2.16K subscribers
3.49K photos
20 videos
15.3K links
Новости Линукс Linux

По всем вопросам @evgenycarter
Download Telegram
📰 PyPI package with 1.1M monthly downloads hacked to push infostealer

An attacker pushed a malicious version of the popular elementary-data package Python Package Index (PyPI) to steal sensitive developer data and cryptocurrency wallets.

🔗 Source:

#python

👉@sysadminoff

https://www.bleepingcomputer.com/news/security/pypi-package-with-11m-monthly-downloads-hacked-to-push-infostealer/
📰 New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials

Cybersecurity researchers have disclosed details of a stealthy Python-based backdoor framework called DEEP#DOOR that comes with capabilities to establish persistent access and harvest a wide range of sensitive information from compromised hosts."The intrusion chain begins with execution of a batch script ('install_obf.bat') that disables Windows security controls, dynamically extracts an.

🔗 Source: https://thehackernews.com/2026/04/new-python-backdoor-uses-tunneling.html

#python

👉@sysadminoff
📰 CachyOS Switches Python To Using Tail-Call Interpreter For 5~15% Better Performance

CachyOS is a very fast out-of-the-box Linux distribution and for those concerned about Python performance, the newest updates to this Arch Linux based distribution will provide even better performance...

🔗 Source: https://www.phoronix.com/news/CachyOS-Better-Python-Perf

#arch #linux #python

👉@sysadminoff

https://share.google/rbVGWCZ7AyiEKZlZL
📰 PyPI Packages Deliver ZiChatBot Malware via Zulip APIs on Windows and Linux

Cybersecurity researchers have discovered three packages on the Python Package Index (PyPI) repository that are designed to stealthily deliver a previously unknown malware family called ZiChatBot on Windows and Linux systems."While these wheel packages do implement the features described on their PyPI web pages, their true purpose is to covertly deliver malicious files," Kaspersky.

🔗 Source: https://thehackernews.com/2026/05/pypi-packages-deliver-zichatbot-malware.html

#linux #python

👉@sysadminoff
📰 JDownloader site hacked to replace installers with Python RAT malware

The website for the popular JDownloader download manager was compromised earlier this week to distribute malicious Windows and Linux installers, with the Windows payload found deploying a Python-based remote access trojan.

🔗 Source: https://www.bleepingcomputer.com/news/security/jdownloader-site-hacked-to-replace-installers-with-python-rat-malware/

#linux #python

👉@sysadminoff

https://ift.tt/NlOxMgY
📰 Max-severity flaw in ChromaDB for AI apps allows server hijacking

A max-severity vulnerability in the latest Python FastAPI version of the ChromaDB project allows unauthenticated attackers to run arbitrary code on exposed servers.

🔗 Source:

#python

👉@sysadminoff

https://www.bleepingcomputer.com/news/security/max-severity-flaw-in-chromadb-for-ai-apps-allows-server-hijacking/
📰 Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer

The Miasma supply chain campaign has sparked a fresh attack wave called Hades, this time involving 37 malicious wheel artifacts across 19 packages in the Python Package Index (PyPI) registry, as the Mini Shai-Hulud-style attacks continue to be refined and splintered to target specific ecosystems."The compromised releases shipped a *-setup.pth file that attempts to execute automatically.

🔗 Source: https://thehackernews.com/2026/06/hades-pypi-attack-19-packages-poisoned.html

#python

👉@sysadminoff