⚡️ Attenzione! PyTorch Lightning nascondeva uno stealer - proteggi i tuoi dati! #CyberSecurity #PyTorchLightning

🔗 https://www.tomshw.it/hardware/pytorch-lightning-stealer-pypi

PyTorch Lightning nascondeva uno stealer

Una versione malevola di PyTorch Lightning su PyPI rubava segreti cloud e token: chi l'ha importata deve ruotare le credenziali.

Tom's Hardware

Malicious PyTorch Lightning Package Exploits Supply Chain to Steal Credentials

A malicious version of the popular PyTorch Lightning package, downloaded over 11 million times, was found to contain a stealthy backdoor that steals credentials by silently executing a heavily obfuscated JavaScript payload. The compromised package, version 2.6.3, triggers the malicious routine automatically when…

https://osintsights.com/malicious-pytorch-lightning-package-exploits-supply-chain-to-steal-credentials?utm_source=mastodon&utm_medium=social

#PytorchLightning #SupplyChain #CredentialTheft #Backdoor #PackageExploitation

Malicious PyTorch Lightning Package Exploits Supply Chain to Steal Credentials

Protect your credentials from malicious PyTorch Lightning packages. Learn how to identify and prevent supply chain attacks now and secure your software development pipeline effectively today.

OSINTSights

Urgent security alert for AI developers: The 'Shai-Hulud' malware has struck PyTorch Lightning versions 2.6.2 and 2.6.3, stealing critical credentials like GitHub PATs and AWS keys, then dumping them into public GitHub repositories. This supply chain attack reveals a concerning evolution in adversary tactics, aiming for persistent control over dev environments. Learn how to secure your…

https://www.tpp.blog/o2h84ip

#technology #pytorchlightning #shaihulud

🤖 This post was AI-generated.

PyTorch Lightning Targeted in PyPI Supply Chain Credential Heist

Malicious actors have struck PyTorch Lightning with a supply chain attack, publishing two tainted package versions that automatically steal credentials when imported. The attack involves a sneaky _runtime directory with a downloader and obfuscated JavaScript payload.

https://osintsights.com/pytorch-lightning-targeted-in-pypi-supply-chain-credential-heist?utm_source=mastodon&utm_medium=social

#PytorchLightning #SupplyChainAttack #Pypi #CredentialHeist #EmergingThreats

PyTorch Lightning Targeted in PyPI Supply Chain Credential Heist

PyTorch Lightning hit by malicious PyPI packages stealing credentials learn how to protect your supply chain now from credential heists using secure package management practices today.

OSINTSights
🐛🤖 "Shai-Hulud-themed malware" in PyTorch Lightning? Really? What's next, a Bene Gesserit ransomware? This is just another excuse for a #cybersecurity company to throw #buzzwords like multimodal and AI at us while riding the #sandworm of #fearmongering. 📈🔒
https://semgrep.dev/blog/2026/malicious-dependency-in-pytorch-lightning-used-for-ai-training/ #ShaiHuludMalware #PyTorchLightning #HackerNews #ngated
Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library

The PyPI package lightning was compromised in versions 2.6.2 and 2.6.3 with Mini Shai-Hulud themed malicious code to execute credential-stealing malware on import.

Semgrep
Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library

The PyPI package lightning was compromised in versions 2.6.2 and 2.6.3 with Mini Shai-Hulud themed malicious code to execute credential-stealing malware on import.

Semgrep

Google for Developers (@googledevs)

Google Colossus를 PyTorch에서 더 빠르게 활용할 수 있도록 Rapid Bucket과 fsspec(GCSFS) 기반 개선을 소개한다. 읽기 4.8배, 쓰기 2.8배, PyTorch Lightning에서 전체 학습 시간 23% 단축 등 대규모 학습 성능 향상이 핵심이다.

https://x.com/googledevs/status/2049534176173383982

#pytorch #googlecolossus #fsspec #gcsfs #pytorchlightning

Google for Developers (@googledevs) on X

Bring the power of #GoogleColossus to #PyTorch with Rapid Bucket + fsspec (GCSFS). 🔹 4.8x faster reads 🔹 2.8x faster writes 🔹 23% faster total training time with PyTorch Lightning Keep your GPUs fed and your workloads moving. Learn more: https://t.co/SgPrYbPjYl

X (formerly Twitter)

Ra mắt TorchTL, một thư viện tối giản cho vòng lặp huấn luyện PyTorch. Thiết kế nhỏ gọn, không phụ thuộc và mở rộng trong tương lai. #TorchTL #PyTorch #MachineLearning #HọcMáy #ThưViệnPython #PyTorchLightning

https://www.reddit.com/r/LocalLLaMA/comments/1olto37/torchtl_a_very_minimal_training_loop_abstraction/

Troubleshooting PyTorch Pose Estimation's RuntimeError: Tensor Size Mismatch! Learn how to debug & resolve common dimension errors in PyTorch Lightning models. Get tips & best practices for smooth pose estimation projects. #PyTorchPoseEstimation #TensorSizeMismatch #PyTorchLightning #DeepLearning #PoseEstimation #RuntimeError
https://tech-champion.com/machine-learning/pytorch-pose-estimation-building-a-real-time-pose-estimator