PyTorch is one of the most popular and widely-used machine learning toolkits out there. Originally developed and released as an open-source project by Facebook, now Meta, the software was handed over to the Linux Foundation in late 2022, which now runs it under the aegis of the PyTorch Foundation. . Unfortunately, the project was compromised by means of a supply-chain attack during the holiday season at the end of 2022, between Christmas Day [2022-12-25] and the day before New Year’s Eve [2022-12-30]. The attackers malevolently created a Python package called torchtriton on PyPI, the popular Python Package Index repository. . The TensorFlow framework encountered a security incident during the New Year of 2023 caused by an infected Ruby gem.. PyTorch Security, Supply Chain Attack, Machine Learning Risks. . LinuxSecurity.com Team
Malicious hackers and other assorted bad guys looking for new tools for plying their trade this upcoming holiday season will have plenty of toys and services to choose from. As we get closer to the holidays, I look forward to ogling / wishing / debating over the items listed in any "top holiday buys" catalogs. However, it looks like there are other people wishing to be on Santa's naughty list AND get gifts - check out the article for a look into a recent trend with organized cyber crime. When do you think they'll have their own Home Shopping Network time slot? . The link for this article located at PC World is no longer available. . As the festive season nears, cyber criminals adapt tactics targeting consumer behavior and online vulnerabilities, using phishing schemes disguised as holiday sales to steal sensitive data.. malicious hacking tools, holiday crime trends, cybercriminal resources. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.