Python Supply-Chain Compromise

2026-04-08T19:23:48Z1fe284ee111b4ca2272e69e26c55c1102b402d66d41343f34f704cfd4569e974
.pth-fileconsumer-routerscorunaencryption-compulsionend-to-end-encryptionfccgooglehong-kongios-exploitlegal-riskmalicious-packagepost-quantum-cryptographyprivacypypipythonsbomsigstoreslsasoftware-supply-chainstate-sponsoredsupply-chainsupply-chain-vulnerabilitywebinartv-recording","hackbackzero-dayzoom-recording

What happened

Collection of Schneier blog posts (Apr 2026) covering multiple high-impact security and privacy developments: a PyPI supply-chain compromise (litellm v1.82.8) where a malicious .pth file auto-executes on Python startup; Google disclosure of a likely state-sponsored iPhone exploit kit (“Coruna”) chaining 23 iOS vulnerabilities to achieve silent device compromise; legal and policy changes affecting encryption and surveillance (Hong Kong police can compel encryption keys; New Mexico ruling raises E2EE liability concerns; US Cyber Strategy language suggesting private-sector offensive actions/hack‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
schneier_blog
Record identifier
1fe284ee111b4ca2272e69e26c55c1102b402d66d41343f34f704cfd4569e974
Enrichment time
2026-04-08T19:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Python Supply-Chain Compromise · Baitaphish