Six Malicious Python Packages in the PyPI Targeting Windows UsersMalicious packages on PyPI copy W4SP attacks to steal users’ credentials and crypto wallet data. This incident illustrates issues in open-source ecosystems.#unit42#EN#2023#PyPI#W4SP#attacks#packages#Supply-Chain-Attack·unit42.paloaltonetworks.com·Jul 11, 2023Six Malicious Python Packages in the PyPI Targeting Windows Users
Realtek SDK Vulnerability Attacks Highlight IoT Supply Chain ThreatsWe observed a recent spate of supply chain attacks attempting to exploit CVE-2021-35394, affecting IoT devices with chipsets made by Realtek.#unit42#EN#2023#CVE-2021-35394#IoT#devices#supplychain#attacks#Realtek·unit42.paloaltonetworks.com·Jan 24, 2023Realtek SDK Vulnerability Attacks Highlight IoT Supply Chain Threats
Realtek SDK Vulnerability Attacks Highlight IoT Supply Chain ThreatsWe observed a recent spate of supply chain attacks attempting to exploit CVE-2021-35394, affecting IoT devices with chipsets made by Realtek.#unit42#EN#2023#CVE-2021-35394#IoT#devices#supplychain#attacks#Realtek·unit42.paloaltonetworks.com·Jan 24, 2023Realtek SDK Vulnerability Attacks Highlight IoT Supply Chain Threats