⚠️ Today's browser update (v1.90.128) contains a fix for a Chromium vulnerability that allows websites to plant hidden scripts via the Background Fetch API.
These scripts survive restarts and could be used to track users, run malicious code on their devices, or launch DDoS attacks on others.
You may have already received the automatic Brave update on desktop. If not, you can manually update by visiting 'About Brave' in the browser's settings.
The Android update is waiting on Google Play Store review and should be out soon.
Create a folder called (calc). Shift+Right click « Open PowerShell Window here » and boom you have a command injection.
@podalirius_ found two command injection vulnerabilities in Windows Explorer's context menus, both exploitable since 9 years. https://t.co/LNNTpKeDnJ
Its "Code execution and antivirus evasion lead to potential compromise". My bad. Should have changed my words. But changing words won't change the impact.
@msftsecurity@msftsecresponse
I would like to bring your attention to this issue: PowerShell Script as a C# compiler service
A threat actor can potentially use this for malicious script or shellcode execution
Example script (harmless):
https://t.co/NG4d3G5IZN
HUGE moment for India 🇮🇳
27M devs building on @github in India
2M+ more joined in 2026
1 in 7 new devs are from India
7.5M contributions to open source AI projects on GitHub
Behind India’s economic growth is a relentless community of devs. Grateful we got to celebrate on the ground with so many of them here in Bengaluru.
A big thank you to this community for building with us all these years. ❤️
Calling out for help. We have proof that a threat actor exfiltrated data to a Microsoft Azure Blob, thanks to detailed logs in the *.log files written by azcopy, for example:
C:\Users\compromised_user\.azcopy\1323eb6d-2624-834e-45e0-218454b383be.log
We see the blob name where the data was exfiltrated to, and exactly which files the threat actor copied, thanks to the excessive logging.
We reached out to our Microsoft contacts for a takedown of the blob (and, with it, a takedown of the stolen data), and the answer was, disillusioning, to say the least. Microsoft is sending us down a Kafka-esque road, with the chances of a takedown slim to non-existent.
Is that really the best they can do? Who from Microsoft is reading this message and could potentially speed up our case?
My question for the leetcode interviewer guy: code up chinese checkers in 5 minutes. LIVE.
A bot will keep saying "Make it fast" every 15 seconds.
Language? Any.
Bonus points for the UI.