Jan. 4, 2023, 5 p.m. | Cedric Pernet

Security on TechRepublic www.techrepublic.com

A nightly build version of a machine-learning framework dependency has been compromised. The package ran malicious code on affected systems and stole data from unsuspecting users.


The post Machine-Learning Python package compromised in supply chain attack appeared first on TechRepublic.

attack build code compromised data data theft dependency developer framework linux foundation machine machine learning malicious nightly package package compromise pypi python python package pytorch security supply supply chain supply chain attack systems version

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Information Security Manager & ISSO

@ Federal Reserve System | Minneapolis, MN

Forensic Lead

@ Arete | Hyderabad

Lead Security Risk Analyst (GRC)

@ Justworks, Inc. | New York City

Consultant Senior en Gestion de Crise Cyber et Continuité d’Activité H/F

@ Hifield | Sèvres, France