ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)

Vercel patched two critical Next.js vulnerabilities enabling unauthenticated remote code execution. The Windows path traversal (CVE-2026-75604, CVSS 9.0) and AVIF heap overflow (GHSA-2xp9-vwfh-vxw4, CVSS 9.5) are fixed in Next.js 15.5.24 and 16.3.3. Vercel-hosted apps need no upgrade.
Tap to vote and see what everyone thinks.
Summary by ByteBrief
CISA warns of hackers exploiting critical MLflow vulnerability