Wednesday, 4 January 2023

PyTorch supply chain attack: Dependency confusion burns DevOps - ReversingLabs

Flaming security posture: A classic dependency confusion attack revealed itself last week. The PyTorch open source software supply chain was compromised by a hacker publishing a malicious torchtriton clone on PyPI.

No comments:

Post a Comment