Tag
PyPI
Every PyPI story we've curated in Bowl of Data, newest issue first — part of our weekly digest across AI, security, blockchain, and engineering.
Week 27 · 2026
Read the issue →-
Aikido acquires Root to backport open source fixes without forcing upgrades
Aikido Security has completed a $70 million acquisition of Root to introduce automated backporting of security patches. The move aims to remediate critical vulnerabilities in existing open source dependencies without forcing developers to undergo complex version upgrades.
Week 24 · 2026
Read the issue →-
For the 2nd time in weeks, Microsoft packages laced with credential stealer
Threat actors have successfully compromised dozens of Microsoft-owned repositories to deploy the Miasma malware via supply-chain attacks. The malware is designed to steal cloud credentials and spread laterally through developer environments by exploiting AI coding agents.
Week 23 · 2026
Read the issue →-
Red Hat npm packages compromised to steal developer credentials
More than 30 Red Hat npm packages were compromised in a supply-chain attack using the Miasma malware to steal developer credentials. The attack was executed via a compromised GitHub account and targeted various cloud and infrastructure secrets.
Free weekly digest
Get next Saturday’s issue in your inbox
The week’s most relevant AI, security, blockchain, and engineering stories — curated, summarised, and reviewed by humans. No spam, unsubscribe anytime.
Subscribe — it’s free