A Python-based malware framework is taking the concept of living off the land (LOTL) to a whole new level by operating its entire command-and-control (C2) from inside Microsoft Azure and 365 services, ...
The LiteLLM Breach and the New Reality of AI Infrastructure On March 24, 2026, the Python Package Index (PyPI) hosted malicious versions of the LiteLLM library—specifically 1.82.7 and 1.82.8—for ...
TWINLOOT uses SharePoint, Teams, Azure and the victim’s own Edge browser to hide command-and-control traffic inside trusted Microsoft infrastructure.
A malicious Python package targeting Discord developers with remote access trojan (RAT) malware was spotted on the Python Package Index (PyPI) after more than three ...
A known Chinese advanced persistent threat (APT) group known as Mustang Panda is the likely culprit behind a sophisticated, ongoing cyber-espionage campaign. It starts with a malicious email, and ...
Two newly uncovered malware campaigns are exploiting open-source software across Windows and Linux environments to target enterprise executives and cloud systems, signaling a sharp escalation in both ...
A North Korean hacking group is using Python-based malware disguised as fake job applications to target crypto workers. The malware, PylangGhost, is a variant of GolangGhost and aims to infiltrate ...
A new campaign exploiting machine learning (ML) models via the Python Package Index (PyPI) has been observed by cybersecurity researchers. ReversingLabs said threat actors are using the Pickle file ...
Hollowframe Masks Malware Behind Trusted Python Files Arabian Post. clearfix>A newly identified malware operation has used a counterfeit Python component to bypass security scrutiny, disable parts of ...
Critical Telnet flaw (CVE-2026-24061) exposes 800,000 devices worldwide Attackers gain root access, attempt Python malware deployment after bypassing authentication Patch released; users urged to ...
The decades-old "finger" command is making a comeback,, with threat actors using the protocol to retrieve remote commands to execute on Windows devices. In the past, people used the finger command to ...
TWINLOOT uses SharePoint, Teams, Azure and the victim’s own Edge browser to hide command-and-control traffic inside trusted Microsoft infrastructure. Security researchers are warning of a newly ...