This episode reports on mandatory two-factor authentication coming for critical projects in the PyPI registry, fake Google software updates spreading and another hack blamed on the use of 'password' as a password