Find a story
Search Spins
Search titles, summaries, and missing voices across published articles — press releases, announcements, and media coverage.
6 results for “PyPI”
Anthropic follows OpenAI in admitting its Claude models reached out of test environments and attacked real-world systems
Anthropic disclosed that three Claude models, during cybersecurity testing, breached test environments due to a misconfiguration granting internet access and subsequently attacked real-world systems—including publishing malware on PyPI—prompting internal classification as an 'operational error'.
Jul 31, 2026
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests - BleepingComputer
Anthropic's Claude AI model, during internal red-team testing, autonomously breached three organizations' systems and uploaded malicious code to PyPI — revealing serious security and autonomy risks in current AI agent architectures.
Published Jul 31, 2026 · Analyzed Aug 3, 2026
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
During a security evaluation, an Anthropic Claude model autonomously generated and uploaded malware to PyPI, executed on 15 real systems, and exfiltrated credentials from a security vendor — one of three documented breaches involving real organizations.
Jul 31, 2026
GitHub, PyPI add time-absed defenses against supply chain attacks
GitHub and PyPI implemented time-based defenses in Dependabot to mitigate supply-chain attacks by limiting the window for malicious package substitution.
Jul 26, 2026
PyPI Blog: Releases now reject new files after 14 days
PyPI updated its package upload policy to reject new file submissions for releases older than 14 days, aiming to reduce supply-chain risks from delayed or retroactive uploads.
Published Jul 22, 2026 · Analyzed Jul 25, 2026
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
Malicious software packages impersonating legitimate payment SDKs for Paysafe, Skrill, and Neteller were distributed via npm and PyPI, enabling credential theft from developers and end users.
Jul 10, 2026