Critical Patches, Supply Chain Risks, and a New Ransomware Campaign
Microsoft and Check Point patch maximum-severity flaws, researchers expose a plugin-pinning bypass in AI coding agents and a credential-stealing npm campaign tied to bogus bug bounty claims, and a ransomware actor chains Confluence and 1C exploits into full compromises.