Linuxgram 🐧
72.8K subscribers
1.02K photos
5 files
18.8K links
News and info from the Linux world 🐧
πŸ“¨ linuxgr4m@gmail.com πŸ“¨

πŸ’Έ If you want to support Linuxgram❀️ 🐧
- BTC: 15aVLQeNY18VAaoBXPgLFA4wfwJnecbjC1
Download Telegram
πŸ“° LiteLLM loses game of Trivy pursuit, gets compromised

Python interface for LLMs infected with malware via polluted CI/CD pipeline Two versions of LiteLLM, an open source interface for accessing multiple large language models, have been removed from the Python Package Index (PyPI) following a supply chain attack that injected them with malicious credential-stealing code.…

πŸ”— Source: https://go.theregister.com/feed/www.theregister.com/2026/03/24/trivy_compromise_litellm/

#python #opensource
😱15πŸ’©3
πŸ“° Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure

A critical security vulnerability in Marimo, an open-source Python notebook for data science and analysis, has been exploited within 10 hours of public disclosure, according to findings from Sysdig.The vulnerability in question is CVE-2026-39987 (CVSS score: 9.3), a pre-authenticated remote code execution vulnerability impacting all versions of Marimo prior to and including.

πŸ”— Source: https://thehackernews.com/2026/04/marimo-rce-flaw-cve-2026-39987.html

#opensource #python #security
😱16❀1
πŸ“° PyPI package with 1.1M monthly downloads hacked to push infostealer

An attacker pushed a malicious version of the popular elementary-data package Python Package Index (PyPI) to steal sensitive developer data and cryptocurrency wallets.

πŸ”— Source: https://www.bleepingcomputer.com/news/security/pypi-package-with-11m-monthly-downloads-hacked-to-push-infostealer/

#python
😱32πŸ‘5😒2πŸ’©1