Python
Curated coverage and analysis in this editorial area.

CVE-2026-6100: CPython Use-After-Free in Decompressors Rated CVSS 9.1 Critical
CVE-2026-6100 affects CPython with a use-after-free in the lzma, bz2, and gzip decompressors. The CVSS 4.0 score is 9.1 CRITICAL, thou…

Aeon RCE via Pickle Dataset: ML Pipeline Risk
CVE-2026-18285: The Python library Aeon executed arbitrary code through pickle deserialization of seemingly legitimate datasets. The b…

Aeon RCE Flaw in Benchmark Loading: The Risk Lies in the Datasets
Trend Micro's Zero Day Initiative published advisory ZDI-26-470 assigning CVE-2026-18287 to a code injection vulnerability in the Pyth…

LiteLLM Open-Source LLM Gateway Distributes Credential-Stealing Malware
Two PyPI versions of the litellm package were compromised by malware that abuses Python .pth files to exfiltrate credentials to an att…

ChocoPoC RAT: How Fake PoCs on PyPI Infected Vulnerability Researchers
ChocoPoC, a Python RAT, spreads via GitHub repositories posing as proof-of-concept exploits that hide the payload in transitive PyPI d…

Edgecution: Malicious Edge Extension Bypasses Sandbox via Native Messaging
Zscaler ThreatLabz documents a campaign where the Edgecution extension abuses Chrome's Native Messaging API to escape the browser sand…

The 'robase' Malware Empties Entire Roblox Games: From Hat Theft to Digital Business Seizure
A malware campaign using the Python package 'robase' steals authenticated session tokens from Roblox developers via Discord social eng…

Microsoft Open-Sources RAMPART and Clarity to Secure AI Agent Workflows
Microsoft has unveiled two open-source security tools for AI agents: RAMPART, a Pytest-native framework for build-time testing, and Cl…

AI-Powered Honeypots: Cisco Talos Flips the Script on Automated Threats
On April 29, Cisco Talos Intelligence researchers released a proof-of-concept aimed at neutralizing offensive asymmetry in cyberspace.…

Google Disrupts AI-Generated Zero-Day: 2FA Bypass Found in Open-Source Tool
The Google Threat Intelligence Group (GTIG) has neutralized an AI-generated zero-day exploit targeting 2FA in a system administration…

PyTorch Lightning Attack: Supply Chain Risk Revealed
Discover the details of the PyTorch Lightning supply chain attack: malicious versions, npm propagation, and AI impersonation. Here's w…

CVE-2026-25874: Unpatched Critical RCE Found in Hugging Face LeRobot
A critical CVSS 9.3 flaw hits Hugging Face's LeRobot. Learn about the RCE risks and the month-long patch delay following initial discl…