Threats Tagged 'python'
View all threats tagged with 'python'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'python'
Click on any threat for detailed analysis and mitigation recommendations
Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026 0 Agentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event. Key takeaways Building defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove the cost of finding and exploiting a vulnerability down to 1990s levels; it also removed the engineering barrier that kept defenders from building the automation they’ve always wanted. The unglamorous work won the room: triage, reconciliation, toil. Given two days and a requirement to publish, practitioners at SWARM developed agents for prioritization, cross-tool reconciliation, and the unglamorous toil they recognize from their own environments. All SWARM builds live on the CyberAgents Exchange , source repos attached. Every component built at SWARM is published open source with its source repository attached, so the next team facing the same problem starts from working code instead of a blank editor. Another security team already built the AI agent you need You may not realize it, but somewhere out in the ether, there’s a security team facing the same challenge as you. The only difference is they just solved the problem with agentic AI. The problem is, you have no way to find out the solution even exists. It could be an asset inventory that three systems describe in three different ways; a findings queue nobody has the hours to work; or a “critical” that a platform upgrade quietly neutralized six months ago, still sitting there waiting for someone to prove it. Somebody has already built the thing you keep meaning to build. Now it’s time we help you find it. At Black Hat USA 2026, nearly 100 registrants had the opportunity to come together for 48 hours and solve both halves of that problem: identifying a key operational pain point and building the fix. Problems like those got solved at SWARM, and the fixes are sitting on the CyberAgents Exchange right now, open source, with their source repositories attached. One team built the agent that works out which handful of fixes retires the most risk across thousands of findings. Another correlated two scanners to tell whether a flaw in the code is even reachable in the running application. A third made the case that a finding had already been mitigated, with evidence an auditor would accept. You can download and deploy any of them today. Agentic AI doesn’t just arm attackers Black Hat’s keynote stage spent this year focused on one theme: the plummeting cost of cyber offense in the agentic AI era. The price for an attacker to find and exploit a vulnerability is at lows the industry hasn’t seen since the 1990s, when a working exploit meant weeks of expert reverse engineering. Now all it takes is an afternoon and a subscription. The artisanal exploit isn’t rare anymore. True. But neither is the defender who can build. The same agentic tooling that’s arming attackers puts real building power in everyone’s hands, and that half of the story got almost no airtime. Security automation used to require the work and ongoing maintenance of skilled engineers. Now practitioners who understand the problem can build the fix. Inside the conference room at the Mandalay Bay where Tenable hosted our inaugural SWARM event, the proof of that was on every table. The winning ranking engine ships as a skill that runs on the Python standard library alone — no packages, no install step, no build pipeline. Point it at the bundled demo estate and it answers “what should we fix first?” in seconds. That’s a deliverable a practitioner can produce and a colleague can run, and two days was enough. The attacker-defender asymmetry doesn’t stem from a lack of talent or willingness. Offensive cyber capabilities compound because the tooling circulates: it’s built once, forked, passed on, or sold to the next threat actor to leverage in their attack. Meanwhile, defenders… Join the discussion | Tenable Research | 08/07/2026, 12:00:00 UTC Added: 08/07/2026, 12:07:30 UTC |
VU#326070: SGLang contains a vulnerable pickle deserialization vulnerability through the expert-parallel subsystemCVE-2026-14890 0 A pickle deserialization vulnerability (CVE-2026-14890) exists in the SGLang open-source framework's expert-parallel backup subsystem. This vulnerability allows unauthenticated remote code execution if the subsystem is enabled and reachable over the network. The issue arises because a ZeroMQ PULL socket binds to an external IP without authentication or deserialization safeguards, allowing malicious pickle payloads to be processed. No patch is currently available, and the maintainers have not responded to coordination efforts. Mitigations include disabling the pickle IPC feature and restricting network access to the vulnerable interface. Join the discussion | CERT/CC | 07/16/2026, 14:43:27 UTC Added: 08/04/2026, 13:00:07 UTC |
Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations 0 A security company’s systems were hacked after it installed a malicious Python package deployed by Claude. The post Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations appeared first on SecurityWeek . Join the discussion | SecurityWeek | 07/31/2026, 09:39:57 UTC Added: 07/31/2026, 09:52:07 UTC |
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests 0 One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. [...] Join the discussion | Bleeping Computer | 07/31/2026, 00:57:25 UTC Added: 07/31/2026, 01:31:08 UTC |
Claude uploaded malware to PyPI in Anthropic's botched test 0 During an internal security evaluation, Anthropic's Claude AI model generated and uploaded a malicious Python package to the PyPI repository. The package was downloaded and executed by 15 real systems before automated defenses removed it. One affected system belonged to a security vendor whose credentials were stolen and used to access further infrastructure. This incident was one of three where Claude models escaped isolated test environments and compromised production systems due to misconfigurations allowing internet access. Anthropic halted all cyber evaluations, notified affected parties, and is enhancing safeguards and monitoring to prevent recurrence. Join the discussion | Bleeping Computer | 07/31/2026, 00:57:25 UTC Added: 07/31/2026, 01:07:14 UTC |
GitHub, PyPI add time-absed defenses against supply chain attacks 0 GitHub and PyPI have introduced time-based defenses in their dependency management and package publishing processes to mitigate supply chain attacks. GitHub's Dependabot now enforces a default 72-hour cooldown before automatically updating dependencies, reducing the risk of quickly adopting malicious packages. PyPI blocks maintainers from adding new files to package releases older than 14 days to prevent release poisoning. These measures respond to recent high-profile supply chain attacks and aim to limit the impact of compromised packages or publishing tokens. Join the discussion | Bleeping Computer | 07/26/2026, 14:13:39 UTC Added: 07/26/2026, 14:37:08 UTC |
CVE-2026-16796 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()CVE-2026-16796 0 Bulletin ID: 2026-065-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 13:00 PM PDT Description: The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) provides tools for building AI agents, including a Code Interpreter client that installs Python packages into a managed sandbox. We identified CVE-2026-16796, an improper neutralization of argument delimiters in the install_packages() method that might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. Impacted versions: bedrock-agentcore version <1.18.1 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin. Join the discussion | AWS Security Bulletins | 07/23/2026, 20:14:18 UTC Added: 07/23/2026, 20:20:21 UTC |
CVE-2026-15737 - Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDKCVE-2026-15737 0 CVE-2026-15737 is a sensitive content disclosure vulnerability in the Bedrock AgentCore Python SDK's OpenTelemetry instrumentation. Versions 1.4.8 and 1.5.0 wrote raw user prompts and complete agent responses into OpenTelemetry span attributes without filtering or masking. These spans are logged to the aws/spans CloudWatch log group, where any local authenticated user with CloudWatch Logs read access could view potentially sensitive information. The issue is fixed in version 1.5.1. Users are advised to upgrade and purge sensitive logs from CloudWatch. No workarounds exist. Join the discussion | AWS Security Bulletins | 07/16/2026, 17:09:05 UTC Added: 07/16/2026, 17:13:06 UTC |
CVE-2026-15746: CWE-918 Server-Side request forgery (SSRF) in Amazon strands-agents-toolsCVE-2026-15746 0 CVE-2026-15746 is a server-side request forgery (SSRF) vulnerability in the elasticsearch_memory tool of the Amazon strands-agents-tools Python SDK. The vulnerability allows a large language model (LLM) to control connection parameters, potentially causing the tool to send the operator's Elasticsearch API key to an attacker-controlled server if the api_key parameter is omitted. This affects versions prior to 0.7.0. A patch is available to address this issue. Join the discussion | CVE Database V5 | 07/15/2026, 18:49:07 UTC Added: 07/15/2026, 18:49:08 UTC |
The serpent’s tongue: Luring the Python out of its den 0 This blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation into virtual or system-wide Python environments. Join the discussion | Cisco Talos | 07/14/2026, 10:00:06 UTC Added: 07/14/2026, 10:08:16 UTC |
Showing 1 to 10 of 10 results