cognitive cybersecurity intelligence

News and Analysis

Search

PyPI halted new users and projects while it fended off supply-chain attack

The Python Package Index (PyPI), a key repository for open-source developers, suspended new project creation and user registration following a surge of package uploads containing malicious code. The suspension lasted 10 hours. Security firm Checkmarx reported that the attack likely involved automated uploads of harmful packages using a method called typosquatting, which relies on user typos when entering package names. This isn’t the first instance of such a threat facing the software development ecosystem, with a similar attack targeting GitHub last month.

Source: arstechnica.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts

the effect of virus and vaccines

Long COVID can lead to persistent neuropsychological symptoms like memory problems and slowed cognition, and it can alter brain anatomy. Studies found that vaccines significantly