Mozilla's PACT design rethinks web rate limiting as a zero-knowledge exchange where a site learns exactly one bit about you, under the limit or not, with CAPTCHA as the fallback instead of identity or device attestation.
1 source
Astro 7.1 ships first-class Content Security Policy support with granular script and style directives, so you can tighten your policy without the classic migration pain.
1 source
CVE-2026-44907 (CVSS 7.5) allows unauthenticated remote attackers to trigger CPU exhaustion and OOM conditions via crafted HTTP requests to Server Function endpoints.
2 sources
Next.js shipped its first pre-announced monthly security release on July 20, patching 9 vulnerabilities (4 high severity) across v16.2.11 and v15.5.21.
1 source
Vite patches CVE-2026-39363 (arbitrary file read via dev server WebSocket) and CVE-2026-39364 (server.fs.deny bypass), affecting versions 6.x, 7.x, and 8.x. Fixed in 6.4.2, 7.3.2, and 8.0.5.
2 sources
The threat group behind the Miasma worm has expanded its attack surface to VS Code extensions, using them as a vector to compromise GitHub accounts and inject malicious code into open source projects.
2 sources
Coming in July 2026, npm v12 disables automatic install scripts, git dependencies, and remote URL resolution by default. Every frontend team needs an allowlist before the upgrade lands.
1 source
HackerOne launched an AI platform that autonomously discovers and validates security vulnerabilities. It combines agentic AI with the company's existing bug bounty triage data to reduce false positives and speed up remediation.
1 source
CVE-2026-11645 is the fifth Chrome zero-day exploited in 2026, an out-of-bounds read/write in the V8 JavaScript/WebAssembly engine. CVSS 8.8. Patch is in Chrome 149. The pace of Chrome zero-days is accelerating.
2 sources
CVE-2026-42826 lets unauthenticated attackers extract sensitive data from Azure DevOps with zero user interaction. CVSS score of 10.0, the highest possible. Here's what's exposed and how to check if you're patched.
2 sources
A coordinated campaign injected malicious code into 14 widely-used npm packages last week. We break down the affected packages, detection steps for your lockfile, and the one CI flag that catches this.
1 source