91.
93.
94.
Malicious NuGet packages drop disruptive 'time bombs'
(bleepingcomputer.com)
95.
Supply chain attacks are exploiting our assumptions
(news.ycombinator.com)
97.
Gootloader malware is back with new tricks after 7-month break
(bleepingcomputer.com)
98.
The Top 3 Browser Sandbox Threats That Slip Past Modern Security Tools
(bleepingcomputer.com)
99.
Fake Solidity VSCode extension on Open VSX backdoors developers
(bleepingcomputer.com)
100.
Open VSX rotates access tokens used in supply-chain malware attack
(bleepingcomputer.com)
101.
The security paradox of local LLMs
(news.ycombinator.com)
102.
CISA: High-severity Windows SMB flaw now exploited in attacks
(bleepingcomputer.com)
103.
Malicious crypto-stealing VSCode extensions resurface on OpenVSX
(bleepingcomputer.com)
105.
Hackers can steal 2FA codes and private messages from Android phones
(arstechnica.com)
106.
CRDT and SQLite: Local-First Value Synchronization
(news.ycombinator.com)
107.
108.
Modern Font Stacks
(news.ycombinator.com)
109.
110.
Signal Protocol and Post-Quantum Ratchets
(news.ycombinator.com)
111.
Signal's New PQ Ratchet
(news.ycombinator.com)
112.
"DSEG": Original 7-segment and 14-segment fonts (2014)
(news.ycombinator.com)
113.
"DSEG": Original 7-segment and 14-segment fonts
(news.ycombinator.com)
114.
Open Social
(news.ycombinator.com)
115.
Malicious Rust packages on Crates.io steal crypto wallet keys
(bleepingcomputer.com)
116.
Python-Style Kwargs in TypeScript
(news.ycombinator.com)
117.
NPM package caught using QR Code to fetch cookie-stealing malware
(bleepingcomputer.com)
118.
119.
Hidden risk in Notion 3.0 AI agents: Web search tool abuse for data exfiltration
(news.ycombinator.com)
120.
CISA exposes malware kits deployed in Ivanti EPMM attacks
(bleepingcomputer.com)