Blog

Insights on software development, security, and technology from our team.

Showing posts taggedjavascript

A polluted prototype can hijack your axios traffic. Upgrade to 1.18.0.

axios just disclosed CVE-2026-67320, a prototype pollution flaw in its Node.js HTTP adapter that can reroute your server's outbound requests through an attacker-controlled proxy and leak credentials over plaintext HTTP. It's a sharp reminder that a dependency you barely configure is still attack surface. Here's what to patch, and what to change beyond the patch.

A Chrome zero-day is being exploited right now. Here's what your dev team should actually do.

CVE-2026-3910 targets Chrome's V8 JavaScript engine and is already being used in real attacks. It affects every Chromium-based browser your team uses. We break down what happened, why it matters beyond "just update Chrome," and the practical steps most teams are still skipping.