Malicious Python Lolipop packages in the Wild

Malicious python packages designed to steal information from developers’ systems have been recently discovered by Fortinet. The packages were uploaded to the Python Package Index between January 7 and 12 this year by an author named lolipop. The names of the...

Upgrade to The Latest Version of Git

If you’re a developer then you need to make sure you have upgraded to the latest version of Git. Git just patched two critical severity security vulnerabilities that could allow attackers to perform remote code execution. The security vulnerabilities were...

The Case for Running Ad Blockers

Johannes Ullrich released a public service announcement today on why you must run an adblocker when using the internet. He claims that ad networks are not doing enough due diligence on the ads that they run on their networks. He provided examples of Google search...

Password Manager Accounts Compromised By Credential Stuffing

NortonLifeLock sent data breach notifications to customers, informing them that hackers have successfully breached Norton Password Manager accounts in credential-stuffing attacks. The company observed unusually high volumes of fail login attempts in December with...

Whatfuscator: An analysis of malicious open source packages

Henrik from Endor Labs recently created a small prototype Go application for detecting malicious packages early. The article shares what his application found, his view on the evolution of malicious packages and what we should be doing to protect ourselves from it....