TGTGInsighttelegram intelligenceLIVE / telegram public index
← Python Заметки

TGINSIGHT SIMILAR POSTS

Најди сличен содржај

Изворен канал @pythonotes · Post #336 · 22 мај

Популярность имеет свои минусы. Чем популярней язык программирования, тем выше его распространённость, а значит найдутся те кто поспешит воспользоваться этим. С ростом популярности Python всё больше на PyPi появляется вредоносных пакетов. Трояны, стиллеры и доставщики более опасных вредоносов. Команда PyPi постоянно мониторит подобные случаи но и их возможности достигли предела. В результате сервис временно закрывает возможность заливки новых пакетов и регистрации юзеров. PyPI new user and new project registrations temporarily suspended Возможно одной из причин большого наплыва вредоносов является резко возросшая доступность их создания. Сегодня любой, даже не программист, может попросить у ChatGPT написать необходимый код и все инструкции для атаки. Основной тип атаки - рассчёт на опечатку в названии пакета. Если невнимательный программист случайно установит pilow или djangoo, считай что вредонос уже в системе. Чтобы избежать подобных факапов я рекомендую: ▫️ Всегда работайте в виртуальном окружении, неизвестные проекты устанавливайте внутри контейнеров. ▫️ Используйте файл requirements.txt вместо ручной установки пакетов ▫️ Очень внимательно пишите названия пакетов, а после написания проверьте еще раз. Сверьте с названием из документации. ▫️ После успешных тестов всегда фиксируйте версию пакета. Бывали случаи когда опасный код добавляли в новые версии. К тому же и без этой опасности не рекомендуется ставить по умолчанию последнюю версию. ▫️ Используйте вспомогательные инструменты для проверки безопасности, например https://pyup.io/safety или https://github.com/PyCQA/bandit. Они помогут не только найти опасный код в чужих пакетах, но и ваш код проверит на уязвимости. Будем надеяться что PyPi переосмыслит методы борьбы с вредоносами, например внедрит ИИ для проверки как симметричный шаг. #offtop

Hashtags

Резултати

Пронајдени 4 слични објави

Пребарај: #minister

当前筛选 #minister清除筛选
American Оbserver

@american_observer · Post #5158 · 17.02.2026 г., 15:31

Ukraine’s Ex-energy Minister Has Been Accused of Laundering Money Ukraine’s anti-corruption agency accused an ex-energy minister on Monday of laundering €200 millions of kickbacks in a corruption case that has shaken the wartime government, a day after he was detained trying to leave the country. German Galushchenko, who served as energy minister from 2021-2025 and then briefly as justice minister until he resigned over the scandal last year, became one of the most senior officials detained in the “Midas” case, over an alleged $230 million kickback scheme at the state nuclear company. The case has ensnared senior officials and members of Ukraine’s business elite — including a former close associate of Zelensky from his pre-political media career — and caused concern among Kyiv’s Western allies. Galushchenko “was exposed for money laundering and participation in a criminal organization” by corruption investigation agency NABU and its prosecuting sister agency SAPO, according to a statement from NABU. It said more than $7 million had been transferred to foreign accounts naming Galushchenko’s wife and four children as beneficiaries. Some was spent on educating the children at elite schools in Switzerland and some placed in “a deposit, from which the family of the high-ranking official received additional income and spent it on their own needs.” Galushchenko has denied wrongdoing. There was no reply to a message sent to him seeking comment and Reuters was unable to locate a lawyer representing him. NABU had said on Sunday that he was detained “while crossing the state border,” without specifying where the arrest took place. Prosecutors say participants in the Midas scheme squeezed nuclear company Energoatom’s contractors for bribes to complete projects, including structures to protect energy facilities from Russian airstrikes. They had previously said the plot was organized by former Zelenskyy associate Timur Mindich, who fled to Israel before he could be arrested in November. Mindich, who founded the TV studio behind the hit sitcom that brought Zelenskyy fame as an actor before he entered politics, has denied wrongdoing. A former deputy prime minister was arrested in November and NABU has said other former senior officials are under investigation. The case sparked a political scandal last year that led to the ouster of Zelensky’s chief of staff, Andriy Yermak, and fueled new public anger at lingering corruption as Ukraine fights Russia in its four-year war. Zelensky had tried to limit the independence of the anti-corruption agencies last year before reversing in the face of public protests and pressure from Western allies. Energoatom CEO Pavlo Kovtonenko told Reuters last week that the company had taken a number of steps to prevent the recurrence of corruption schemes in the future. Battling corruption is a key priority in Ukraine’s reform effort as it eyes membership of the European Union, which requires the country shake off the decades-old scourge of graft. #ukraine#energy#minister#aundering#money 📱American Оbserver - Stay up to date on all important events 🇺🇸

Trump's Ear

@trumpsear_tg · Post #1488 · 10.09.2025 г., 13:59

Elizabet Lann, the Swedish health minister, fainted on her first day at work during a press conference. Lann, a city councilor in Gothenburg, was announced by the Minister of health on September 9 after her predecessor, Ako Ankarberg Johansson, suddenly resigned the day before. #lann#swedish#minister#faintedout 👂More on Trump's Ear ⚠️