<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Python</title><description>Cybersecurity articles tagged #Python on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Python&apos;s pyca/cryptography Gains Post-Quantum Support</title><link>https://runtimerebel.com/blog/python-s-pyca-cryptography-gains-post-quantum-support</link><guid isPermaLink="true">https://runtimerebel.com/blog/python-s-pyca-cryptography-gains-post-quantum-support</guid><description>Python&apos;s pyca/cryptography library now supports NIST-standard ML-KEM and ML-DSA for post-quantum encryption, addressing future quantum threats.</description><pubDate>Mon, 10 Aug 2026 16:46:38 GMT</pubDate><category>Cryptography</category><category>Python</category><category>Ml Kem</category><category>Ml Dsa</category><category>Quantum Computing</category></item><item><title>Python Supply Chain: Malicious Packages Targeting Developers</title><link>https://runtimerebel.com/blog/python-supply-chain-malicious-packages-targeting-developers</link><guid isPermaLink="true">https://runtimerebel.com/blog/python-supply-chain-malicious-packages-targeting-developers</guid><description>Malicious Python packages exploit trusted ecosystems like PyPI, enabling supply chain attacks on developer systems. Learn about the threat and mitigation.</description><pubDate>Sun, 09 Aug 2026 00:59:54 GMT</pubDate><category>Python</category><category>Supply Chain Attack</category><category>PyPI</category><category>Malware</category><category>Software Supply Chain</category></item><item><title>AI-Driven Vulnerability Surges and UAT-11795 Starland RAT Campaign</title><link>https://runtimerebel.com/blog/ai-driven-vulnerability-surges-and-uat-11795-starland-rat-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-driven-vulnerability-surges-and-uat-11795-starland-rat-campaign</guid><description>Analysis of a record Patch Tuesday driven by AI vulnerability research, alongside Cisco Talos findings on UAT-11795 deploying Starland RAT.</description><pubDate>Sat, 08 Aug 2026 08:31:29 GMT</pubDate><category>Threat Intel</category><category>Zero-Day</category><category>Ransomware</category><category>Remcos</category><category>Python</category></item><item><title>GitHub and PyPI Time-Based Defenses Against Supply Chain Attacks</title><link>https://runtimerebel.com/blog/github-and-pypi-time-based-defenses-against-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-and-pypi-time-based-defenses-against-supply-chain-attacks</guid><description>GitHub and PyPI introduce time-based delays in Dependabot to mitigate supply chain attacks by preventing the immediate ingestion of malicious packages.</description><pubDate>Sun, 26 Jul 2026 17:03:02 GMT</pubDate><category>GitHub</category><category>PyPI</category><category>Dependabot</category><category>Supply Chain Security</category><category>Python</category></item><item><title>Shai-Hulud Attack: Trojanized PyPI Packages Steal Developer Secrets</title><link>https://runtimerebel.com/blog/shai-hulud-attack-trojanized-pypi-packages-steal-developer-secrets</link><guid isPermaLink="true">https://runtimerebel.com/blog/shai-hulud-attack-trojanized-pypi-packages-steal-developer-secrets</guid><description>New Shai-Hulud supply chain attack compromises 19 science-focused PyPI packages, distributing malware to steal developer credentials and secrets.</description><pubDate>Mon, 08 Jun 2026 20:57:57 GMT</pubDate><category>Shai Hulud</category><category>PyPI</category><category>Supply Chain Attack</category><category>Malware</category><category>Developer Secrets</category><category>Python</category><category>Open Source Security</category></item><item><title>PyPI Supply Chain Threat: Deceptive Packages Target Developers</title><link>https://runtimerebel.com/blog/pypi-supply-chain-threat-deceptive-packages-target-developers</link><guid isPermaLink="true">https://runtimerebel.com/blog/pypi-supply-chain-threat-deceptive-packages-target-developers</guid><description>Analysis of malicious Python packages such as cryptography-util using deceptive naming to exfiltrate Discord tokens and system metadata via webhooks.</description><pubDate>Mon, 11 May 2026 05:25:24 GMT</pubDate><category>PyPI</category><category>Python</category><category>Supply Chain Attack</category><category>Malware</category><category>Discord Webhooks</category></item><item><title>Backdoored PyTorch Lightning Package Drops Credential Stealer</title><link>https://runtimerebel.com/blog/backdoored-pytorch-lightning-package-drops-credential-stealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/backdoored-pytorch-lightning-package-drops-credential-stealer</guid><description>A malicious PyTorch Lightning package on PyPI delivers a credential stealer, targeting browser data, environment variables, and cloud service credentials.</description><pubDate>Mon, 04 May 2026 20:35:32 GMT</pubDate><category>PyTorch Lightning</category><category>PyPI</category><category>Credential Stealer</category><category>Supply Chain Attack</category><category>Python</category><category>Malware</category></item><item><title>Marimo RCE via CVE-2024-41663 Exploited to Deliver NKAbuse Malware</title><link>https://runtimerebel.com/blog/marimo-rce-via-cve-2024-41663-exploited-to-deliver-nkabuse-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/marimo-rce-via-cve-2024-41663-exploited-to-deliver-nkabuse-malware</guid><description>Attackers are exploiting a critical RCE in Marimo Python notebooks (CVE-2024-41663) to deploy NKAbuse malware via Hugging Face. Update to version 0.7.5.</description><pubDate>Thu, 16 Apr 2026 20:21:05 GMT</pubDate><category>CVE-2024-41663</category><category>NKAbuse</category><category>Marimo</category><category>Hugging Face</category><category>Python</category></item><item><title>Marimo RCE via CVE-2024-52271 — Active Exploitation Mitigation Guide</title><link>https://runtimerebel.com/blog/marimo-rce-via-cve-2024-52271-active-exploitation-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/marimo-rce-via-cve-2024-52271-active-exploitation-mitigation-guide</guid><description>Critical pre-auth RCE vulnerability in Marimo (CVE-2024-52271) is under active exploitation for credential theft. Update to version 0.9.11 immediately.</description><pubDate>Sun, 12 Apr 2026 16:14:41 GMT</pubDate><category>CVE-2024-52271</category><category>Marimo</category><category>RCE</category><category>Python</category><category>Vulnerability</category></item><item><title>litellm 1.82.8 Supply Chain Compromise via Malicious .pth File</title><link>https://runtimerebel.com/blog/litellm-1-82-8-supply-chain-compromise-via-malicious-pth-file</link><guid isPermaLink="true">https://runtimerebel.com/blog/litellm-1-82-8-supply-chain-compromise-via-malicious-pth-file</guid><description>Security analysis of a supply chain compromise in litellm 1.82.8 on PyPI, where a malicious .pth file enables automatic code execution on Python startup.</description><pubDate>Wed, 08 Apr 2026 12:29:28 GMT</pubDate><category>LiteLLM</category><category>PyPI</category><category>Supply Chain Attack</category><category>Python</category><category>RCE</category></item><item><title>Telnyx PyPI Package Compromised by TeamPCP via Steganography</title><link>https://runtimerebel.com/blog/telnyx-pypi-package-compromised-by-teampcp-via-steganography</link><guid isPermaLink="true">https://runtimerebel.com/blog/telnyx-pypi-package-compromised-by-teampcp-via-steganography</guid><description>TeamPCP threat actors distributed malicious Telnyx Python package versions 4.87.1 and 4.87.2 on PyPI to harvest credentials using hidden WAV files.</description><pubDate>Fri, 27 Mar 2026 20:15:00 GMT</pubDate><category>Telnyx</category><category>PyPI</category><category>TeamPCP</category><category>Python</category><category>Steganography</category><category>Credential Theft</category></item><item><title>ForceMemo: Credential Theft Compromises Python Repositories</title><link>https://runtimerebel.com/blog/forcememo-credential-theft-compromises-python-repositories</link><guid isPermaLink="true">https://runtimerebel.com/blog/forcememo-credential-theft-compromises-python-repositories</guid><description>Researchers reveal ForceMemo, a campaign exploiting credentials stolen via GlassWorm to compromise hundreds of GitHub accounts and Python repositories.</description><pubDate>Mon, 16 Mar 2026 12:24:53 GMT</pubDate><category>ForceMemo</category><category>GlassWorm</category><category>GitHub</category><category>Python</category><category>Supply Chain Attack</category><category>Credential Theft</category></item><item><title>AI-Generated Slopoly Malware Linked to Interlock Ransomware Attacks</title><link>https://runtimerebel.com/blog/ai-generated-slopoly-malware-linked-to-interlock-ransomware-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-generated-slopoly-malware-linked-to-interlock-ransomware-attacks</guid><description>Analysis of the AI-generated Slopoly malware and its role in Interlock ransomware operations, including technical details and detection strategies.</description><pubDate>Thu, 12 Mar 2026 20:13:39 GMT</pubDate><category>Slopoly</category><category>Interlock</category><category>Ransomware</category><category>AI Generated Malware</category><category>Python</category></item><item><title>Over 100 GitHub Repositories Distributing BoryptGrab Stealer</title><link>https://runtimerebel.com/blog/over-100-github-repositories-distributing-boryptgrab-stealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/over-100-github-repositories-distributing-boryptgrab-stealer</guid><description>A large-scale campaign on GitHub utilizes over 100 repositories to distribute BoryptGrab, an info-stealer targeting crypto wallets and browser data.</description><pubDate>Sat, 07 Mar 2026 16:09:43 GMT</pubDate><category>BoryptGrab</category><category>GitHub</category><category>Infostealer</category><category>Python</category><category>Malware Campaign</category></item><item><title>Arkanix Stealer: Rapid Disappearance of C++ &amp; Python Malware</title><link>https://runtimerebel.com/blog/arkanix-stealer-rapid-disappearance-of-c-python-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/arkanix-stealer-rapid-disappearance-of-c-python-malware</guid><description>Arkanix Stealer, a C++ and Python-based info-stealer, emerged briefly, exfiltrating system data, browser credentials, and files before vanishing. Analysis of its TTPs.</description><pubDate>Wed, 25 Feb 2026 04:42:27 GMT</pubDate><category>Arkanix Stealer</category><category>Infostealer</category><category>Malware</category><category>C</category><category>Python</category><category>Data Exfiltration</category><category>Discord Webhooks</category><category>Cyfirma</category></item></channel></rss>