News

Python's ctx library and a fork of PHP's phpass have been compromised. 3 million users combined. The malicious code sends all the environment variables to a heroku app, likely to mine AWS credentials.
To make everyone's job easier, Paris even published a Python script that checks the SHA1 hashes of a user's PHP modules. Mitigate attack by scanning Apache module file hashes ...
Software in Python Package Index (PyPI) and Hypertext Preprocessor (PHP) repositories have been targeted in supply-chain attacks, which researchers say are aimed at stealing users' Amazon Web ...