
npm adds a 72-hour hold after recovery-code sign-in
All npm accounts now receive a 72-hour hold after recovery-code authentication to slow account takeovers.
Topic
Vulnerabilities, ransomware, phishing and incident response.
This topic connects security alerts with operational decisions: actual exposure, patch priorities, identity protection and the ability to restore systems after an incident.

All npm accounts now receive a 72-hour hold after recovery-code authentication to slow account takeovers.

Android 8 and later can transfer passwords and passkeys directly between compatible managers without creating a plaintext export.

Docker outlines an approach built on verified images, isolation, least privilege and end-to-end traceability for the agent software supply chain.

WhatsApp now supports multiple passkeys, replaces the verification PIN and displays more context for calls from unknown numbers.

Docker Hub can exchange a signed GitHub job identity for a short-lived token. Here is how to scope rules and migrate from PATs.

Windows 11 is preparing its August update with broader Windows Hello support, a removable AI component and several fixes. What to check before installing it.

WebMCP lets websites expose structured actions to AI agents. API design, the Chrome 149 trial, use cases, security risks and a practical test plan.

Enterprises can govern the MCP servers used by GitHub Copilot. How allowlists, matching, deployment and complementary security controls work.

Node.js fixes eleven vulnerabilities across releases 22, 24 and 26. Patched versions, HTTP/2, TLS and Permission Model risks, and a deployment plan.

Google is adding selfie video to account recovery. How it works, eligible accounts, privacy choices and the backup methods to retain.

Android 17 is rolling out first to Pixel devices. Features, security, compatibility and backups: the checklist before installing the update.

GitHub Actions now holds some suspicious workflows for review. What this automatic control protects and what maintainers must still inspect.

Immutable images, secrets, healthchecks, networks, migrations and rollback: a complete method for operating Docker Compose on one server.

Strengths, limits, recovery and use cases: a practical method for combining password managers, passkeys and MFA according to risk.

Tasks, metrics, security, costs and decision gates: a reproducible framework for comparing AI coding assistants on a real repository.

An urgency-based method to regain control of an account, limit fraud and respond properly when your personal data has been exposed.

A pragmatic method for protecting accounts, devices, backups and critical services without turning a small business into a security operations centre.

A practical guide to selecting an AI use case, evaluating an assistant, protecting data and measuring value before scaling.

GitHub now separates its public program from a better-paid VIP tier. The platform wants to reward deep research instead of submission volume.

NVIDIA, AMD, IBM, Microsoft and other companies are backing a security alliance for open-weight models as the debate becomes harder to avoid.

An incident involving a research agent shows why autonomous systems need real incident procedures, not only prompt-level guardrails.

More than 1,200 AI lab employees are calling for tools to pace the development of systems that could automate AI research.

Apple fixes dozens of vulnerabilities in iOS and iPadOS 26.6. Even without a flashy feature, this update matters for everyday users.

Critical SharePoint vulnerabilities show a hard rule: after likely compromise, patching must be paired with key rotation and incident hunting.

Fake troubleshooting tips are pushing gamers to paste PowerShell commands. Here is how to spot the trap and what to do if you already ran one.

Recent cyber alerts point in the same direction: AI and automation amplify attacks that still rely on very familiar social and technical patterns.

Before adding an AI component to a product, teams need to frame data, outputs, permissions and monitoring like any other critical system.

Not every vulnerability deserves the same urgency. Actively exploited flaws should move up the queue.

Companies talk a lot about backups. In a crisis, the real indicator is the ability to restore quickly and cleanly.

Windows 11 versions have different end-of-support dates. For small companies, tracking the calendar prevents rushed migrations.

An extension installed to save time can read sensitive pages. Teams should treat the browser as a critical surface.

LLM applications mix instructions, documents and actions. Prompt injection exploits that confusion of roles.

Customers want to understand what they install. The SBOM turns software dependency into a concrete discussion object.

QR codes move users to their phones, outside many usual enterprise protections.

Useful logs cannot be improvised during a crisis. Teams need to decide in advance what must be visible.