Python packages with malicious code expose secret AWS credentials
Sonatype researchers have discovered Python packages that contain malicious code that peek into and expose secret AWS credentials, network interface information, and environment variables. All those credentials and metadata then get uploaded to one or more endpoints, and anyone on the web can see this. Going up a directory level showed hundreds of TXT files containing sensitive information and secret. In this Help Net Security video, Ax Sharma, Senior Security Researcher at Sonatype, explains the … Continue reading Python packages with malicious code expose secret AWS credentials
Copy and paste this URL into your WordPress site to embed
Copy and paste this code into your site to embed