
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
yt-untrack
Watch YouTube signed in with Premium and no ads without the video being saved to your history or shaping your recommendations.
yt-untrack lets you watch YouTube videos while staying fully signed in (Premium, no ads, downloads intact) without those videos being recorded to your watch history or influencing your recommendations.
It works per container: mark any Firefox container as "untracked" in the toolbar popup, then open a video in a tab in that container. The extension cancels YouTube's watch-tracking requests (youtube.com/api/stats/*) only for tabs in the containers you've chosen, so the "I watched this" signal never reaches YouTube's servers. Tabs in every other container behave normally and record as usual.
A red dot on the toolbar icon shows when the current tab is in an untracked container, so you always know whether the video you're watching is being recorded.
No data is collected or sent anywhere. The extension only blocks requests locally in your browser.
FAQs
Watch YouTube signed in with Premium and no ads without the video being saved to your history or shaping your recommendations.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.