cmsguru

PyPI Users Email Phishing Attack

Read the follow-up post: Phishing Attack Follow-Up(Ongoing, preliminary report)PyPI has not been hacked, but users are being targeted by a…

1 year ago

inbox.ru Domain Prohibition Follow-up

A follow-up to the previous post.We have since learned that the campaign was orchestratedby the company that owns the inbox.ru…

1 year ago

Prohibiting inbox.ru email domain registrations

A recent spam campaign against PyPI has prompted an administrative action,preventing using the inbox.ru email domain.This includes new registrations as…

1 year ago

Incident Report: Organizations Team privileges

On April 14, 2025 security@pypi.org was notified of a potential security concernrelating to privileges granted to a PyPI User via…

1 year ago

Introducing our new Terms of Service

We're introducing a newTerms of Serviceto formalize our relationship to usersand enable us to move forward with providing new features…

1 year ago

PyPI Now Supports Project Archival

Support for marking projects as archived has landed on PyPI. Maintainers can nowarchive a project to let users know that…

1 year ago

Project Quarantine

Earlier this year, I wrote briefly about new functionality added to PyPI, theability to quarantine projects.This feature allows PyPI administrators…

1 year ago

Supply-chain attack analysis: Ultralytics

Last week, the Python project “ultralytics” suffered a supply-chain attack through a compromise of the projects’ GitHub Actions workflows and…

1 year ago

Website Builder Software Updates for 2017

It's a tool for you to build a site. The site and its tools and integrations derive from Django. For…

9 years ago

This website uses cookies.