BragJack: When a Browser Extension Reaches the AI Agent
Researchers demonstrated five ways a malicious extension could cross into browser AI features. The impact varies by product, but extension governance is the shared control.
In-depth red team tactics, blue team strategy — and privacy-first security tools that run entirely in your browser. No accounts. No telemetry. No data leaves your machine.
Researchers demonstrated five ways a malicious extension could cross into browser AI features. The impact varies by product, but extension governance is the shared control.
Picus Labs found evasion, persistence and command-and-control techniques in eight of its 2026 top ten malware behaviors. What defenders can take from the data.
How attackers turn GitHub Actions' shared build cache into a supply chain weapon — real cases, attack mechanics, detection logic, and mitigations.
GitHub says an employee device was compromised through a poisoned third-party VS Code extension and internal repositories were exfiltrated. Here is the fact-checked breakdown for defenders.
A pre-authentication SQL injection in Roundcube's virtuser_query plugin has been reported in active use. Check whether your installation is exposed, update it, and investigate suspicious activity.
Two critical vCenter flaws threaten authentication and code execution. Use this practical plan to patch, isolate, detect, and recover safely.
Checkmarx found malicious code hidden in an npm library method rather than an install script. Here's what the trigger means for dependency review and incident response.