Python developers targeted with new password-stealing phishing attacks – here’s how to stay safe




  • PyPI warns phishing attacks will persist using fake domains and urgent email tactics
  • Victims are tricked into verifying accounts via typosquatted sites like pypi-mirror.org
  • Users and maintainers urged to adopt phishing-resistant 2FA and domain-aware password managers

Phishing attacks against PyPI users and maintainers are going to continue, the foundation is warning, as it urged members to tighten up on security and remain vigilant.

A new blog post, published by the foundation’s security developer-in-residence, Seth Larson,noted the most recent attacks are a continuation of a months-long campaign that uses convincing emails and typosquatted domains to steal people’s login credentials.

https://cdn.mos.cms.futurecdn.net/4HQfMQ7ScfTqv5RDukfnYA.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img