A report by Qualys’ Threat Research Unit has highlighted cloud tech debt as a growing threat, pointing out the lack of security updates for databases, web servers and security software. It cites misconfiguration of cloud tools as a significant concern. The report also shows that 4% of scanned cloud assets face vulnerabilities, with Log4Shell remaining a major unpatched threat. Malware and crypto mining are identified as top threats, while automation helps in reducing unresolved vulnerabilities.

New Weaponized PyPI Package Attacking Developers to Steal Source Code
A malicious Python package named solana-token was discovered, designed to steal source code and sensitive data from Solana developers. Masquerading as a legitimate utility, it