Skip to main content
← All Articles

Tag

#Python

15 articles

Advertisement

INFO
Threat Intel

Python's pyca/cryptography Gains Post-Quantum Support

Python's pyca/cryptography library now supports NIST-standard ML-KEM and ML-DSA for post-quantum encryption, addressing future quantum threats.

Runtime Rebel Intel
3 min read · Aug 10, 2026
Python Supply Chain: Malicious Packages Targeting Developers
HIGH
Supply Chain

Python Supply Chain: Malicious Packages Targeting Developers

Malicious Python packages exploit trusted ecosystems like PyPI, enabling supply chain attacks on developer systems. Learn about the threat and mitigation.

Runtime Rebel Intel
4 min read · Aug 9, 2026
AI-Driven Vulnerability Surges and UAT-11795 Starland RAT Campaign
HIGH
Threat Intel

AI-Driven Vulnerability Surges and UAT-11795 Starland RAT Campaign

Analysis of a record Patch Tuesday driven by AI vulnerability research, alongside Cisco Talos findings on UAT-11795 deploying Starland RAT.

Runtime Rebel Intel
3 min read · Aug 8, 2026
INFO
Supply Chain

GitHub and PyPI Time-Based Defenses Against Supply Chain Attacks

GitHub and PyPI introduce time-based delays in Dependabot to mitigate supply chain attacks by preventing the immediate ingestion of malicious packages.

Runtime Rebel Intel
4 min read · Jul 26, 2026
HIGH
Supply Chain

Shai-Hulud Attack: Trojanized PyPI Packages Steal Developer Secrets

New Shai-Hulud supply chain attack compromises 19 science-focused PyPI packages, distributing malware to steal developer credentials and secrets.

Runtime Rebel Intel
4 min read · Jun 8, 2026
HIGH
Supply Chain

PyPI Supply Chain Threat: Deceptive Packages Target Developers

Analysis of malicious Python packages such as cryptography-util using deceptive naming to exfiltrate Discord tokens and system metadata via webhooks.

Runtime Rebel Intel
3 min read · May 11, 2026

Advertisement

HIGH
Supply Chain

Backdoored PyTorch Lightning Package Drops Credential Stealer

A malicious PyTorch Lightning package on PyPI delivers a credential stealer, targeting browser data, environment variables, and cloud service credentials.

Runtime Rebel Intel
4 min read · May 4, 2026
HIGH
Malware

Marimo RCE via CVE-2024-41663 Exploited to Deliver NKAbuse Malware

Attackers are exploiting a critical RCE in Marimo Python notebooks (CVE-2024-41663) to deploy NKAbuse malware via Hugging Face. Update to version 0.7.5.

Runtime Rebel Intel
3 min read · Apr 16, 2026
CRITICAL
Vulnerabilities

Marimo RCE via CVE-2024-52271 — Active Exploitation Mitigation Guide

Critical pre-auth RCE vulnerability in Marimo (CVE-2024-52271) is under active exploitation for credential theft. Update to version 0.9.11 immediately.

Runtime Rebel Intel
3 min read · Apr 12, 2026
HIGH
Supply Chain

litellm 1.82.8 Supply Chain Compromise via Malicious .pth File

Security analysis of a supply chain compromise in litellm 1.82.8 on PyPI, where a malicious .pth file enables automatic code execution on Python startup.

Runtime Rebel Intel
4 min read · Apr 8, 2026
Telnyx PyPI Package Compromised by TeamPCP via Steganography
HIGH
Supply Chain

Telnyx PyPI Package Compromised by TeamPCP via Steganography

TeamPCP threat actors distributed malicious Telnyx Python package versions 4.87.1 and 4.87.2 on PyPI to harvest credentials using hidden WAV files.

Runtime Rebel Intel
4 min read · Mar 27, 2026
HIGH
Supply Chain

ForceMemo: Credential Theft Compromises Python Repositories

Researchers reveal ForceMemo, a campaign exploiting credentials stolen via GlassWorm to compromise hundreds of GitHub accounts and Python repositories.

Runtime Rebel Intel
3 min read · Mar 16, 2026
HIGH
Malware

AI-Generated Slopoly Malware Linked to Interlock Ransomware Attacks

Analysis of the AI-generated Slopoly malware and its role in Interlock ransomware operations, including technical details and detection strategies.

Runtime Rebel Intel
4 min read · Mar 12, 2026
HIGH
Supply Chain

Over 100 GitHub Repositories Distributing BoryptGrab Stealer

A large-scale campaign on GitHub utilizes over 100 repositories to distribute BoryptGrab, an info-stealer targeting crypto wallets and browser data.

Runtime Rebel Intel
4 min read · Mar 7, 2026
MEDIUM
Malware

Arkanix Stealer: Rapid Disappearance of C++ & Python Malware

Arkanix Stealer, a C++ and Python-based info-stealer, emerged briefly, exfiltrating system data, browser credentials, and files before vanishing. Analysis of its TTPs.

Runtime Rebel Intel
4 min read · Feb 25, 2026