A weekly look at exploited flaws, exposed systems, supply-chain attacks, browser abuse, malware campaigns, and the security risks that mattered most.
A spoofed CCleaner download site is spreading a multi-stage malware that hijacks Chrome to steal credentials, cookies, and authentication tokens while recording keystrokes and screenshots.
The critical zero-day can provide direct SQL access to Metabase’s underlying database, potentially exposing credentials, API keys, and other sensitive data.
Development environments have evolved into toolkits for directing coding models and coordinating agents. GitHub Copilot, ...
At Black Hat USA 2026, Zenity Labs today released new research demonstrating zero-click PleaseFix exploit chains across leading agentic browsers.
GitGuardian found 321 n8n instances accepting leaked GitHub tokens that could expose workflows, data, and downstream ...
Any data that enters your system from outside a trust boundary should be treated as untrusted until proven otherwise. That includes form fields, API payloads, file uploads, headers, cookies, queue ...