惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

B
Blog RSS Feed
Security Archives - TechRepublic
Security Archives - TechRepublic
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
小众软件
小众软件
V
V2EX
B
Blog
腾讯CDC
D
DataBreaches.Net
H
Hackread – Cybersecurity News, Data Breaches, AI and More
月光博客
月光博客
The Cloudflare Blog
T
The Blog of Author Tim Ferriss
云风的 BLOG
云风的 BLOG
Latest news
Latest news
L
LINUX DO - 最新话题
C
Check Point Blog
Attack and Defense Labs
Attack and Defense Labs
H
Hacker News: Front Page
Forbes - Security
Forbes - Security
H
Help Net Security
S
Securelist
D
Docker
Blog — PlanetScale
Blog — PlanetScale
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
The Last Watchdog
The Last Watchdog
N
News and Events Feed by Topic
G
Google Developers Blog
AI
AI
I
Intezer
L
LangChain Blog
NISL@THU
NISL@THU
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
人人都是产品经理
人人都是产品经理
Hugging Face - Blog
Hugging Face - Blog
罗磊的独立博客
T
Tenable Blog
Jina AI
Jina AI
I
InfoQ
C
Cybersecurity and Infrastructure Security Agency CISA
Cisco Talos Blog
Cisco Talos Blog
C
CERT Recently Published Vulnerability Notes
GbyAI
GbyAI
T
Tailwind CSS Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
O
OpenAI News
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Know Your Adversary
Know Your Adversary
T
Troy Hunt's Blog
Google Online Security Blog
Google Online Security Blog

Ars Technica - All content

Pentagon wants $54B for drones, more than most nations’ military budgets Mozilla: Anthropic's Mythos found 271 security vulnerabilities in Firefox 150 Supreme Court arguments make it clear that FCC fines are "nonbinding" Silo S3 teaser hints at the wasteland's origins Framework's CEO on the RAM crisis and creating a "MacBook Pro for Linux users" Florida probes ChatGPT role in mass shooting. OpenAI says bot "not responsible." Report: Meta will train AI agents by tracking employees' mouse, keyboard use Microsoft removes Call of Duty from Game Pass, lowers subscription pricing Framework Laptop 13 Pro is a major overhaul for the modular, upgradeable laptop Framework Laptop 16 upgrades make it look less like an unfinished prototype Internal emails show how Amazon raises prices across the Internet, lawsuit says Anthropic gets $5B investment from Amazon, will use it to buy Amazon chips CATL's new LFP battery can charge from 10 to 98% in less than 7 minutes AMD Ryzen 9 9950X3D2 Dual Edition review: Tons of cache for tons of dollars What's the deal with spacesuits for the Moon? Will they be ready in time? Loneliness in older adults can often lead to memory impairment Contrary to popular superstition, AES 128 is just fine in a post-quantum world Pentagon pulls the plug on one of the military's most troubled space programs John Ternus will replace Tim Cook as Apple CEO Blue Origin's rocket reuse achievement marred by upper stage failure I’ve fired one of America’s most powerful lasers—here’s what a shot day looks like Great white sharks are overheating US-sanctioned currency exchange says $15 million heist done by "unfriendly states" Man with @ihackedthegovernment Instagram account tells judge, “I made a mistake" Trump picks qualified, normal health leader to head CDC; experts still cautious $25,000 buys plenty of used EVs: Here are some options Satellite and drone images reveal big delays in US data center construction Amazon won’t release Fire Sticks that support sideloading anymore Ridley Scott's post-apocalyptic The Dog Stars drops first trailer Artemis II pilot talks about what it was really like to fly and land in Orion Meta's AI spending spree is helping make its Quest headsets more expensive Rocket Report: Starship V3 test-fired; ESA's tentative step toward crew launch Recent advances push Big Tech closer to the Q-Day danger zone After a saga of broken promises, a European rover finally has a ride to Mars Lucasfilm drops The Mandalorian and Grogu final trailer at CinemaCon Intel refreshes non-Ultra Core CPUs with new silicon for the first time OpenAI starts offering a biology-tuned LLM As they got close to the Moon, Artemis II astronauts were eager to land Mozilla launches Thunderbolt AI client with focus on self-hosted infrastructure Ad firms settle with Trump FTC over claims they boycotted conservative media New Codex features include the ability to use your computer in the background The Ukraine war's deep impact on Metro 2039’s development, story New undersea cable cutter risks Internet’s backbone Microsoft and Stellantis want to use AI to help car owners Gemini can now create personalized AI images by digging around in Google Photos RFK Jr. forces FDA to reconsider 12 unproven peptides after 2023 ban First look: Also's upcoming e-bike disconnects the pedals and wheels Meet the Quantum Kid The race to Shackleton Crater is on—will Jeff Bezos or China get there first? Florida surgeon charged with killing man after removing liver instead of spleen Jury finds Live Nation/Ticketmaster is illegal monopoly that overcharged fans "TotalRecall Reloaded" tool finds a side entrance to Windows 11's Recall database Google releases new apps for Windows and MacOS Boston Dynamics’ robot dog now reads gauges and thermometers with Google's AI Prime Video shows “technical difficulties” sign instead of NBA game in overtime New teaser gives us first look at Godzilla Minus Zero Vulcan woes will "absolutely" be a factor in Pentagon's next rocket competition Adobe takes Creative Cloud into Claude Code-esque territory Good Omens S3 trailer sets up a blessed conclusion Bubble watch: Fashion brand Allbirds pivots hard to become AI services company New 3D map of Universe could solve dark energy mystery What’s the deal with Alzheimer’s disease and amyloid? Blue Origin has a new employee stock plan, but not everyone is happy It's Tax Day, and no one knows how to file for prediction market winnings Ukraine’s military robot surge aims to offset drone risks to humans Sony killing features for antenna, set-top box users of Bravia smart TVs in May Americans ask AI for health care. Hospitals think the answer is more chatbots. NASA chose the right crew to launch a new era of human space exploration Google will begin punishing sites for back button hijacking in June Retro Rewind re-creates the glorious drudgery of working a '90s video store Google shoehorned Rust into Pixel 10 modem to make legacy code safer NZXT agrees to let customers keep their rental PCs in class-action settlement Your tech support company runs scams. Stop—or disguise with more fraud? Sunrise on the Reaping teaser brings us a Second Quarter Quell IBM folds to Trump anti-DEI push, admits no misconduct but pays $17M penalty Slate Auto raises $650 million as production gets closer and closer Meta spins up AI version of Mark Zuckerberg to engage with employees To teach in the time of ChatGPT is to know pain Shock from Iran war has Trump's vision for US energy dominance flailing The Artemis II mission has ended. Where does NASA go from here? AI models are terrible at betting on soccer—especially xAI Grok Four astronauts are back home after a daring ride around the Moon Californians sue over AI tool that records doctor visits New paper argues history, not mantle plume, powers Yellowstone F1 moves a step closer to fixing its 2026 hybrid problem Report: US demands Reddit unmask ICE critic, summons firm to grand jury Microsoft's "commitment to Windows quality" starts with overhaul of beta program "Oobleck" still holds some surprises YouTube increases Premium price again, says 90-second unskippable ads are a bug Oldest octopus fossil found to not be an octopus What leaked "SteamGPT" files could mean for the PC gaming platform's use of AI Here's what to expect from the fiery, 14-minute return of Artemis II Pro-Iran Explosive Media trolls Trump with AI-generated Lego cartoons Dad stuck in support nightmare after teen lied about age on Discord Rocket Report: Chinese version of Falcon 9 fails; Artemis depends on rapid heavy lift Orion helium leak no threat to Artemis II reentry but will require redesign RFK Jr. rewrites CDC panel's charter, opening door to anti-vaccine quacks AI on the couch: Anthropic gives Claude 20 hours of psychiatry Clinical trial shows gene editing works for β-Thalassaemia, too “Negative” views of Broadcom driving thousands of VMware migrations, rival says
Open source package with 1 million monthly downloads stole user credentials
Dan Goodin · 2026-04-28 · via Ars Technica - All content

The developers are urging all developers who installed version 0.23.3 to take the following steps immediately:

1. Check your installed version:

pip show elementary-data | grep Version

2. If the version is 0.23.3, uninstall it and replace it with the safe version:

pip uninstall elementary-data

pip install elementary-data==0.23.4

In your requirements and lockfiles, pin explicitly to elementary-data==0.23.4.

3. Delete your cache files to avoid any artifacts.

4. Check for the malware’s marker file on any machine where the CLI may have run: If this file is present, the payload executed on that machine.

macOS / Linux: /tmp/.trinny-security-update

Windows: %TEMP%\\.trinny-security-update

5. Rotate any credentials that were accessible from the environment where 0.23.3 ran – dbt profiles, warehouse credentials, cloud provider keys, API tokens, SSH keys, and the contents of any .env files. CI/CD runners are especially exposed because they typically have broad sets of secrets mounted at runtime.

6. Contact your security team to hunt for unauthorized usage of exposed credentials. The relevant IOCs are at the bottom of this post.

Over the past decade, supply-chain attacks on open source repositories have become increasingly common. In some cases, they have achieved a chain of compromises as the malicious package leads to breaches of users and, from there, breaches resulting from the compromise of the users’ environments.

HD Moore, a hacker with more than four decades of experience and the founder and CEO of runZero, said that user-developed repository workflows, such as GitHub actions, are notorious for hosting vulnerabilities.

It’s “a major problem for open source projects with open repos,” he said. “It’s really hard to not accidentally create dangerous workflows that can be exploited by an attacker’s pull request.”

He said this package can be used to check for such vulnerabilities.