Hidden VS Code MCP Settings Let Install Links Run Attacker Code
CVE-2026-41613 let crafted MCP install links persist settings that the VS Code preview did not show. Version 1.119.1 fixes the preview.
Reader edition
CVE-2026-41613 let crafted MCP install links persist settings that the VS Code preview did not show. Version 1.119.1 fixes the preview.
TP-Link TL-WR940N hardware revision 6 can let an unauthenticated attacker turn a LAN client's outbound RTSP session into code execution inside the router kernel.
Flare found that BTMOB's official operation now sits among resellers, source-code buyers, private servers, and offers of uncertain authenticity, weakening infrastructure-only detection.
The service preloads a payload-bearing PNG, copies a browser-specific command, and keys the final in-memory stage to the victim's public IP address.
A compromised maintainer account published Keyv-family packages with valid provenance, an install-time credential stealer, and code that could poison more npm releases.
Gitea 1.22.1 through 1.27.0 can let an anonymous request read files as the service account, expose the internal token, and plant a Git hook that executes during a clone.
Unit 42 showed three post-compromise paths from Chrome's local passkey state to silent assertions, substituted verification keys, or the master secret protecting synced credentials.
INC ransomware activity requires SMA 1000 operators to investigate logs and configuration as well as apply the hotfix.
Chrome fixed more security bugs in two milestones than in the previous 23 while using AI across discovery, triage and fix preparation.
N-central operators need Hotfix 2 build 2026.3.1.10 and a downstream endpoint hunt because the new release supersedes the first hotfix.
An integration error routed wallet entropy through MicroPython's deterministic Yasmarang fallback. Updating prevents new weak seeds, but existing ones still require migration.
A compromised Adform tracking file used browser events, DOM observers and form-field hooks to keep substituting Bitcoin, Ethereum and Tron addresses.
A crafted image can reach unsafe libvips operations through Active Storage, exposing files and process credentials that a Rails-only update cannot recover.