Dec 13, 2022Ravie Lakshmanan An active malware campaign is targeting the Python Package Index (PyPI) and npm repositories for Python and JavaScript with typosquatted and fake modules that deploy a ransomware strain, marking the latest security issue to affect software supply chains. The typosquatted Python packages all impersonate the popular requests library: dequests, … [Read more...] about Malware Strains Targeting Python and JavaScript Developers Through Official Repositories
developers
W4SP Stealer Constantly Targeting Python Developers in Ongoing Supply Chain Attack
An ongoing supply chain attack has been leveraging malicious Python packages to distribute malware called W4SP Stealer, with over hundreds of victims ensnared to date. "The threat actor is still active and is releasing more malicious packages," Checkmarx researcher Jossef Harush said in a technical write-up, calling the adversary WASP. "The attack seems related to cybercrime as … [Read more...] about W4SP Stealer Constantly Targeting Python Developers in Ongoing Supply Chain Attack
Researchers Uncover 29 Malicious PyPI Packages Targeted Developers with W4SP Stealer
Cybersecurity researchers have uncovered 29 packages in Python Package Index (PyPI), the official third-party software repository for the Python programming language, that aim to infect developers' machines with a malware called W4SP Stealer. "The main attack seems to have started around October 12, 2022, slowly picking up steam to a concentrated effort around October 22," … [Read more...] about Researchers Uncover 29 Malicious PyPI Packages Targeted Developers with W4SP Stealer
What Does Observability Mean for Developers?
Monitoring is often not the first thing on the mind of the modern developer. Yet, it’s necessary at many points of the software development lifecycle, including: before deprecating an API, before launching a new feature, after launching the feature, and more. In fact, monitoring needs can vary much more than the classic Ops monitoring.My podcast guest Liran Haimovitch is the … [Read more...] about What Does Observability Mean for Developers?
Application Snapshots: A Valuable Observability Signal for Developers
Monitoring is often not the first thing on the mind of the modern developer. Yet, it’s necessary at many points of the software development lifecycle, including: before deprecating an API, before launching a new feature, after launching the feature, and more. In fact, monitoring needs can vary much more than the classic Ops monitoring.There is one type of telemetry data that is … [Read more...] about Application Snapshots: A Valuable Observability Signal for Developers
Researchers Fingerprint Exploit Developers Who Help Several Malware Authors
Writing advanced malware for a threat actor requires different groups of people with diverse technical expertise to put them all together. But can the code leave enough clues to reveal the person behind it? To this effect, cybersecurity researchers on Friday detailed a new methodology to identify exploit authors that use their unique characteristics as a fingerprint to track … [Read more...] about Researchers Fingerprint Exploit Developers Who Help Several Malware Authors
Contrast Community Edition Empowers Developers to Write Secure Code Faster
As software eats the world, the world faces a software security crisis. The movement to modern software such as cloud technologies and microservice architectures is essential to innovate quickly. Yet, nearly three in four developers say that security slows down Agile and DevOps.Neither developers nor security teams are to blame. DevOps speed is held back by a 15-year-old, … [Read more...] about Contrast Community Edition Empowers Developers to Write Secure Code Faster
Facebook Sues Two Android App Developers for Click Injection Fraud
Facebook has filed a lawsuit against two shady Android app developers accused of making illegal money by hijacking users' smartphones to fraudulently click on Facebook ads.According to Facebook, Hong Kong-based 'LionMobi' and Singapore-based 'JediMobi' app developers were distributing malicious Android apps via the official Google Play Store that exploit a technique known as … [Read more...] about Facebook Sues Two Android App Developers for Click Injection Fraud
WWDC 2019 Keynote — Apple
Apple WWDC 2019. One big week. Even bigger announcements. Announcing updates to iOS, watchOS, and macOS. And introducing iPadOS, the all-new Mac Pro and Pro Display XDR. New software and technologies. Hands-on labs. Technical and design focused sessions led by Apple engineers. Anything can happen at the Worldwide Developers Conference where coders, creators and crazy ones … [Read more...] about WWDC 2019 Keynote — Apple
WWDC 2019 — Goodnight Developers — Apple
When the world goes to sleep, developers stay up to chase their dreams. Learn more about WWDC at https://apple.co/wwdc2019 Song: “I Guess I Should Go To Sleep” by Jack White: http://apple.co/IGuessIShouldGoToSleep … [Read more...] about WWDC 2019 — Goodnight Developers — Apple