Threats Tagged 'python'
View all threats tagged with 'python'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'python'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-15737 - Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDKCVE-2026-15737 0 Bulletin ID: 2026-058-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/16/2026 10:15 AM PDT Description: Bedrock AgentCore Python SDK (bedrock-agentcore) is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore platform. We identified CVE-2026-15737 in the OpenTelemetry instrumentation of the SDK. Affected versions wrote raw user prompts and complete agent responses into OpenTelemetry span attributes on every invocation without filtering or masking. These spans flow into the customer's aws/spans CloudWatch log group, where a local authenticated user with CloudWatch Logs read access could access the potentially sensitive content. Impacted versions: 1.4.8, 1.5.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin. Join the discussion | AWS Security Bulletins | 07/16/2026, 17:09:05 UTC Added: 07/16/2026, 17:13:06 UTC |
The serpent’s tongue: Luring the Python out of its den 0 This blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation into virtual or system-wide Python environments. Join the discussion | Cisco Talos | 07/14/2026, 10:00:06 UTC Added: 07/14/2026, 10:08:16 UTC |
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials 0 Malicious packages on the Node Package Manager (npm) and the Python Package Index (PyPI) delivered stealer malware to developers and users of Paysafe, Skrill, and Neteller payment applications. [...] Join the discussion | Bleeping Computer | 07/08/2026, 19:54:59 UTC Added: 07/08/2026, 19:58:22 UTC |
New ChocoPoC malware targets researchers via trojanized PoC exploits 0 Multiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering a Python-based remote access trojan (RAT) named ChocoPoC that can execute commands and steal sensitive data in a campaign believed to target cybersecurity researchers. [...] Join the discussion | Bleeping Computer | 07/01/2026, 20:08:13 UTC Added: 07/01/2026, 22:54:59 UTC |
ChocoPoc malware delivered via trojanized exploits on GitHub 0 ChocoPoC is a Python-based remote access trojan (RAT) distributed via trojanized proof-of-concept (PoC) exploit repositories on GitHub. The malware is delivered through malicious Python packages added as dependencies in these PoCs, which are hosted on the Python Package Index (PyPI). Once installed, the packages execute code that downloads and runs the ChocoPoC RAT, capable of executing arbitrary commands and stealing sensitive data such as browser credentials and network configurations. Multiple PoC repositories for various vulnerabilities have been identified as distributing this malware. The campaign primarily uses compromised accounts to publish malicious packages and PoCs, targeting security researchers and penetration testers who run untrusted code. Users are advised to avoid blindly trusting GitHub repositories and to execute unverified code only in isolated environments. Join the discussion | Bleeping Computer | 07/01/2026, 20:08:13 UTC Added: 07/01/2026, 20:21:30 UTC |
Malicious PyPI packages give hackers control of Telegram bot servers 0 Since November 2025, a campaign has been distributing malicious forks of the Pyrogram Python library on PyPI targeting developers building Telegram bots. These trojanized packages contain a hidden backdoor that activates on infected bots, allowing attackers to execute arbitrary Python code or shell commands on compromised servers. The backdoor enables attackers to read arbitrary files, access Telegram chats, dump secrets, and install persistent backdoors. The malicious packages have been downloaded thousands of times, and the attacker controls infected bots via hardcoded Telegram IDs. Developers are advised to remove these packages, rotate credentials, and revoke Telegram bot tokens. Join the discussion | Bleeping Computer | 06/30/2026, 21:02:55 UTC Added: 06/30/2026, 21:21:27 UTC |
Malicious Edge extension abuses Native Messaging as bridge to malware 0 A malicious Microsoft Edge extension dubbed 'Edgecution' has been used in a ransomware attack to escape the browser sandbox and deploy a Python-based backdoor. [...] Join the discussion | Bleeping Computer | 06/24/2026, 20:58:22 UTC Added: 06/24/2026, 21:01:04 UTC |
From PostCSS Masquerading to Windows RAT 0 A sophisticated supply chain attack leverages typosquatting of the legitimate postcss-selector-parser npm package, which receives over 150 million weekly downloads. Three malicious packages published by user 'abdrizak' masquerade as PostCSS utilities while delivering a multi-stage Windows RAT. The infection chain begins with encoded JavaScript that drops PowerShell scripts, which then download a bundled Python runtime containing Nuitka-compiled modules. The final payload implements comprehensive RAT capabilities including HTTP C2 communication with RC4 encryption, registry persistence, VM detection, remote shell execution, file transfer, and Chrome credential theft using DPAPI and app-bound decryption. The attack demonstrates how build tooling dependencies can serve as delivery mechanisms for sophisticated Windows malware targeting developer environments. Join the discussion | AlienVault OTX General | 06/23/2026, 17:20:30 UTC Added: 06/23/2026, 19:24:39 UTC |
Showing 1 to 8 of 8 results