This week’s recap covers exploited flaws, supply chain attacks, phishing kits, AI lures, macOS stealers, urgent CVEs, tools, ...
npm 12 disables install scripts by default, requiring explicit approval to reduce dependency-based code execution risks.
Chrome's WebMCP guidance warns that AI agents can be manipulated through the tools they are built to trust.
Google is finally killing Manifest V2 extensions for good, either with Chrome 150 or 151, by the end of June 2026.