Skip to content
Tech News
clear
Topics: Today This Week This Month This Year
1.
Zero-Touch OAuth for MCP (news.ycombinator.com)
2.
Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks (bleepingcomputer.com)
3.
VS Code zero-day lets hackers steal GitHub tokens in one click (bleepingcomputer.com)
4.
Why the browser is now the front line for AI security (bleepingcomputer.com)
5.
The attack dominating financial services doesn't steal passwords. It resets MFA and steals the token. (venturebeat.com)
6.
FBI warns of Kali365 phishing service targeting Microsoft 365 accounts (bleepingcomputer.com)
7.
5 Steps to Managing Shadow AI Tools Without Slowing Down Employees (bleepingcomputer.com)
8.
Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing (bleepingcomputer.com)
9.
Composer leaks contents of tokens configured as GitHub OAuth tokens (news.ycombinator.com)
10.
Running Claude Code or Claude in Chrome? Here's the audit matrix for every blind spot your security stack misses (venturebeat.com)
11.
ConsentFix v3 attacks target Azure with automated OAuth abuse (bleepingcomputer.com)
12.
Learning from the Vercel breach: Shadow AI & OAuth sprawl (bleepingcomputer.com)
13.
Carrot Disclosure: Forgejo (news.ycombinator.com)
14.
Vercel breach exposes the OAuth gap most security teams cannot detect, scope or contain (venturebeat.com)
15.
The Vercel breach: OAuth attack exposes risk in platform environment variables (news.ycombinator.com)
16.
Vercel Employee's AI Tool Access Led to Data Breach (darkreading.com)
17.
Cloud development platform Vercel was hacked (theverge.com)
18.
Scan your website to see how ready it is for AI agents (news.ycombinator.com)
19.
Is Your Site Agent-Ready? (By Cloudflare) (news.ycombinator.com)
20.
Over 100 Chrome Web Store extensions steal user accounts, data (bleepingcomputer.com)
21.
Over 100 Chrome extensions in Web Store target users accounts and data (bleepingcomputer.com)
22.
Claude Code is locking people out for hours (news.ycombinator.com)
23.
Claude Code Down (news.ycombinator.com)
24.
Device code phishing attacks surge 37x as new kits spread online (bleepingcomputer.com)
25.
New EvilTokens service fuels Microsoft device code phishing attacks (bleepingcomputer.com)
26.
Microsoft fixes bug causing Classic Outlook sync issues with Gmail (bleepingcomputer.com)
27.
Digs: iOS app that syncs your Discogs collection and lets you browse it offline (news.ycombinator.com)
28.
OpenClaw can bypass your EDR, DLP and IAM without triggering a single alert (venturebeat.com)
29.
Apideck CLI – An AI-agent interface with much lower context consumption than MCP (news.ycombinator.com)
30.
Ask HN: Is Claude Down Again? (news.ycombinator.com)
Today's top topics: apple google openai anthropic amazon android authority nasa nvidia spacex china
View all today's topics →