PyPl is blocking hundreds of expired domains to halt malware attacks




  • Domain resurrection attacks allow cybercriminals to exploit the trust users have in PyPI
  • By scanning for expired domains, PyPI aims to put a stop to these attacks
  • Users are still advised to turn on 2FA and add secondary emails

The Python Package Index (PyPI) is putting a stop to so-called “domain resurrection attacks” that have been observed in the wild before to launch cyberattacks.

Domain resurrection is a supply chain attack where a threat actor registers, or re-registers, a domain that was once owned by a legitimate package maintainer, but has since expired.

https://cdn.mos.cms.futurecdn.net/JqCaVi7J7avcuKZHmHeMgF.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img