the.bay.news

Critical CVE issued for hallucinated SQLite vulnerability

research.jfrog.com
Critical CVE issued for hallucinated SQLite vulnerability
The JFrog security research team recently identified a supply chain attack targeting the `xinference` package on PyPI. Versions 2.6.0, 2.6.1, and 2.6.2 were compromised and yanked by maintainers after users reported suspicious behavior. If you installed or imported these versions, you must assume your environment is compromised.

0 comments

Sign in to join the discussion — your thebay.events account works here.

No comments yet.