Linux
2.14K subscribers
4.28K photos
20 videos
17.9K links
Новости Линукс Linux

По всем вопросам @evgenycarter
Download Telegram
📰 LiteLLM loses game of Trivy pursuit, gets compromised

Python interface for LLMs infected with malware via polluted CI/CD pipeline Two versions of LiteLLM, an open source interface for accessing multiple large language models, have been removed from the Python Package Index (PyPI) following a supply chain attack that injected them with malicious credential-stealing code.…

🔗 Source:

#python #opensource

👉@sysadminoff

https://go.theregister.com/feed/www.theregister.com/2026/03/24/trivy_compromise_litellm/
📰 Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure

A critical security vulnerability in Marimo, an open-source Python notebook for data science and analysis, has been exploited within 10 hours of public disclosure, according to findings from Sysdig.The vulnerability in question is CVE-2026-39987 (CVSS score: 9.3), a pre-authenticated remote code execution vulnerability impacting all versions of Marimo prior to and including.

🔗 Source: https://thehackernews.com/2026/04/marimo-rce-flaw-cve-2026-39987.html

#opensource #python #security

👉@sysadminoff
📰 PyPI package with 1.1M monthly downloads hacked to push infostealer

An attacker pushed a malicious version of the popular elementary-data package Python Package Index (PyPI) to steal sensitive developer data and cryptocurrency wallets.

🔗 Source:

#python

👉@sysadminoff

https://www.bleepingcomputer.com/news/security/pypi-package-with-11m-monthly-downloads-hacked-to-push-infostealer/