Get the latest tech news

SQLite Critical CVEs or LLM Slop?


The JFrog security research team recently identified a supply chain attack targeting the `xinference` package on PyPI. Versions 2.6.0, 2.6.1, and 2.6.2 were compromised and yanked by maintainers after users reported suspicious behavior. If you installed or imported these versions, you must assume your environment is compromised.

None

Get the Android app

Or read this on Hacker News

Read more on:

Photo of Critical CVE

Critical CVE