Linux
2.15K subscribers
4.22K photos
20 videos
17.8K links
Новости Линукс Linux

По всем вопросам @evgenycarter
Download Telegram
📰 Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer

The Miasma supply chain campaign has sparked a fresh attack wave called Hades, this time involving 37 malicious wheel artifacts across 19 packages in the Python Package Index (PyPI) registry, as the Mini Shai-Hulud-style attacks continue to be refined and splintered to target specific ecosystems."The compromised releases shipped a *-setup.pth file that attempts to execute automatically.

🔗 Source: https://thehackernews.com/2026/06/hades-pypi-attack-19-packages-poisoned.html

#python

👉@sysadminoff
📰 GraalVM CE 25.1.3 Gets Native Image "Hello World" Program Down To Just 6.5MB

GraalVM, the advanced JDK focused on ahead-of-time (AOT) Native Image compilation and since last year began shifting focus to more non-Java languages like Python and JavaScript, is out with its newest community feature release. GraalVM Community Edition 25.1.3 is now available with some interesting changes in tow...

🔗 Source:

#python

👉@sysadminoff

https://www.phoronix.com/news/GraalVM-Community-25.1.3
📰 New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos

Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC, travels in Python proof-of-concept (PoC) repositories on GitHub that claim to exploit hot new CVEs.Run one, and it quietly lifts your saved passwords, browser cookies, and files, then hands the attacker a shell on your machine. YesWeHack and.

🔗 Source: https://thehackernews.com/2026/07/new-chocopoc-rat-targets-vulnerability.html

#python

👉@sysadminoff
📰 Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent.The researchers said the public agent could be prompt-injected into posting /adk-issue-fix as adk-bot. They identified the bot as a collaborator, so that comment satisfied.

🔗 Source: https://thehackernews.com/2026/08/google-deletes-3-adk-ai-workflows-after.html

#python

👉@sysadminoff
📰 Mojo 1.0 Programming Language Officially Released

Modular releases Mojo 1.0, delivering a stable foundation, Python-style lambdas, improved LSP support, and stronger memory-safety diagnostics.

🔗 Source:

#python

👉@sysadminoff

https://linuxiac.com/mojo-1-0-programming-language-officially-released/
📰 CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than.

🔗 Source: https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html

#opensource #python

👉@sysadminoff
📰 Postcard is a new email client for GNOME, built with AI

Postcard is a new email client for GNOME that has echoes of Geary The app is the work of a solo developer, gxanshu on GitHub, who is upfront about using AI coding tools to bring this “modern mail client” to life. Postcard is written in Python with GTK4/libadwaita. It uses imaplib and smtplib for networking, a local SQLite index for searching, WebKitGTK for rendering HTML and libsecret for keeping passwords safe.

🔗 Source: https://www.omgubuntu.co.uk/2026/08/postcard-gnome-email-client

#gnome #python

👉@sysadminoff

https://omgubuntu.co.uk/2026/08/postcard-gnome-email-client
📰 Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck.The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user. CVE-2026-66066 aka.

🔗 Source: https://thehackernews.com/2026/09/attackers-exploit-critical-langflow-and.html

#python

👉@sysadminoff
📰 BleachBit 6.0.4 Cleaner and Privacy Tool Released with Faster Scanning

BleachBit 6.0.4 is out with faster startup and scanning, new cleaners for fish, Zsh, Android Studio, Gradle, and Python, plus major security fixes.

🔗 Source: /

#android #python

👉@sysadminoff

https://linuxiac.com/bleachbit-6-0-4-cleaner-and-privacy-tool-released-with-faster-scanning