This week’s recap covers exploited flaws, supply chain attacks, phishing kits, AI lures, macOS stealers, urgent CVEs, tools, ...
npm 12 disables install scripts by default, requiring explicit approval to reduce dependency-based code execution risks.
Chrome's WebMCP guidance warns that AI agents can be manipulated through the tools they are built to trust.
Chrome 150 ships June 30 and deletes the last Manifest V2 override flag from Chromium’s codebase, permanently ending dynamic ...