A malicious campaign compromised Python Package Index (PyPI) targeting two packages, deepseeek and deepseekai. Orchestrated by an alias, “bvk”, the packages, designed to steal sensitive user data and environment variables, exploited an increasing interest in AI and machine learning. Despite quick quarantining, both packages were downloaded multiple times across various countries. Analysing the script revealed the use of AI. This incident serves as a warning of how cybercriminals exploit trending technologies.
Abandoned AWS S3 Buckets Can be Reused to Hijack Global Software Supply Chain
WatchTowr Labs has identified a security flaw in abandoned AWS S3 buckets that could allow attackers to hijack software supply chains, potentially leading to large-scale