Linux
2.16K subscribers
4.06K photos
20 videos
17.3K links
Новости Линукс Linux

По всем вопросам @evgenycarter
Download Telegram
📰 Max-severity flaw in ChromaDB for AI apps allows server hijacking

A max-severity vulnerability in the latest Python FastAPI version of the ChromaDB project allows unauthenticated attackers to run arbitrary code on exposed servers.

🔗 Source:

#python

👉@sysadminoff

https://www.bleepingcomputer.com/news/security/max-severity-flaw-in-chromadb-for-ai-apps-allows-server-hijacking/
📰 Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer

The Miasma supply chain campaign has sparked a fresh attack wave called Hades, this time involving 37 malicious wheel artifacts across 19 packages in the Python Package Index (PyPI) registry, as the Mini Shai-Hulud-style attacks continue to be refined and splintered to target specific ecosystems."The compromised releases shipped a *-setup.pth file that attempts to execute automatically.

🔗 Source: https://thehackernews.com/2026/06/hades-pypi-attack-19-packages-poisoned.html

#python

👉@sysadminoff
📰 GraalVM CE 25.1.3 Gets Native Image "Hello World" Program Down To Just 6.5MB

GraalVM, the advanced JDK focused on ahead-of-time (AOT) Native Image compilation and since last year began shifting focus to more non-Java languages like Python and JavaScript, is out with its newest community feature release. GraalVM Community Edition 25.1.3 is now available with some interesting changes in tow...

🔗 Source:

#python

👉@sysadminoff

https://www.phoronix.com/news/GraalVM-Community-25.1.3
📰 New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos

Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC, travels in Python proof-of-concept (PoC) repositories on GitHub that claim to exploit hot new CVEs.Run one, and it quietly lifts your saved passwords, browser cookies, and files, then hands the attacker a shell on your machine. YesWeHack and.

🔗 Source: https://thehackernews.com/2026/07/new-chocopoc-rat-targets-vulnerability.html

#python

👉@sysadminoff
📰 Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent.The researchers said the public agent could be prompt-injected into posting /adk-issue-fix as adk-bot. They identified the bot as a collaborator, so that comment satisfied.

🔗 Source: https://thehackernews.com/2026/08/google-deletes-3-adk-ai-workflows-after.html

#python

👉@sysadminoff
📰 Mojo 1.0 Programming Language Officially Released

Modular releases Mojo 1.0, delivering a stable foundation, Python-style lambdas, improved LSP support, and stronger memory-safety diagnostics.

🔗 Source:

#python

👉@sysadminoff

https://linuxiac.com/mojo-1-0-programming-language-officially-released/
📰 CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than.

🔗 Source: https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html

#opensource #python

👉@sysadminoff