Category Security

User Sign-Ups and Package Uploads Temporarily Halted

May 21, 2023Ravi LakshmananSoftware security/malware The maintainers of the Python Package Index (PyPI), the official third-party software repository for the Python programming language, have temporarily disabled the ability for users to sign up and upload new packages until further notice.…

KeePass Flaw Exposes Master Passwords

A vulnerability has been discovered in the KeePass password manager software (v2.X) that allows an attacker to dump the master password from the program’s memory. This vulnerability (CVE-2023-32784) was discovered by security researcher Dominik Reichl and will be resolved in…

NPM Packages for Node.js Hiding Dangerous TurkoRat Malware

Two malicious packages found in the npm package repository turned out to be hiding an open-source information-stealing malware called TurkoRat. Together, these packages (named nodejs-encrypt-agent and nodejs-cookie-proxy-agent) were downloaded about 1,200 times and were available for over two months before…

Experts Warn of Voice Cloning-as-a-Service

Security experts have warned of a surge in attacker interest in voice cloning as a service (VCaaS) on the dark web designed to streamline deepfake-based fraud. Recorded Future’s latest report, I have no mouth so I have to commit a…