Kage, a new role-focused website shadowing tool, is being tested to help small software teams track platform changes quickly. Development is ongoing.
Browsing Category
IT services
28 posts
Three Public Vulnerabilities. Chained.
A chain of three public vulnerabilities was exploited in the TanStack npm packages, leading to a major supply-chain compromise on May 11, 2026.
The Roblox Cheat That Broke Vercel.
A Roblox auto-farm script downloaded by a Vercel employee via a compromised Context.ai account enabled a breach exposing customer data across multiple platforms.
ShinyHunters · The New APT Model.
ShinyHunters has evolved into a distributed, AI-enabled threat actor operating as a collective with a new operational model, scaling cyber extortion and data breaches.
The OAuth Permission Apocalypse.
An analysis of the ‚Allow All‘ OAuth permission pattern, its risks, and why it represents the most significant attack surface of 2026, with implications for enterprise security.
732 Bytes to Root. One Hour of Scan Time.
A new Linux kernel flaw allows root access via a 732-byte script, discovered by Theori in just one hour of scanning, collapsing previous security cost assumptions.
The $9 Billion Signature Tax: How DocuSign’s Business Model Survives on One Assumption
A new open source project, DocuSeal, challenges DocuSign’s dominant market position by offering a free, self-hosted digital signature solution, raising questions about industry sustainability.
Incident postmortem builder for managed service providers
A new incident postmortem builder is being tested for small managed service providers to improve post-incident communication and efficiency.