According to Socket, the extensions (complete list here) are published under five distinct publisher identities – Yana ...
A Grafana AI flaw enables zero-click data exfiltration by hiding malicious prompts in URLs, said a Noma Security report.
LinkedIn is facing two lawsuits over its practice of scanning users’ browsers to determine which extensions they’re running.
A newly disclosed vulnerability reveals how AI assistants can become invisible channels for data exfiltration — and why ...
The design flaw in Flowise’s Custom MCP node has allowed attackers to execute arbitrary JavaScript through unvalidated ...
Hackers are exploiting a maximum-severity vulnerability, tracked as CVE-2025-59528, in the open-source platform Flowise for ...
Jamf finds a ClickFix variant that swaps copy-paste Terminal lures for Script Editor execution, tightening delivery of Atomic ...