In yet another software supply chain attack, threat actors
have managed to compromise the popular Python package Lightning to
push two malicious versions to conduct credential theft. According
to Aikido Security, OX Security, Socket, and StepSecurity, the two
malicious versions are versions 2.6.2 and 2.6.3, both of which were
published on April 30, 2026. The campaign is assessed to be
an
Read more https://thehackernews.com/2026/04/pytorch-lightning-compromised-in-pypi.html

