ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)

An npm package named @copilot-mcp/apex installs a macOS infostealer that harvests browser credentials, crypto wallets, and SSH keys. A fake VS Code extension called Markdown All Pro beacons machine details to an attacker. A GhostCommit technique steals repository secrets by hiding instructions inside a PNG image processed by an LLM reviewer.
Tap to vote and see what everyone thinks.
Summary by ByteBrief