
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
zevr-guard
Block ads, trackers, malware & phishing. See who your browser talks to on a live world map. No setup — 100% local, no data sent.
Your browser talks to dozens of companies on every page you visit. Zevr Guard shows you exactly who — on a live world map — and blocks the dangerous ones automatically.
Install once. No setup, no account. Protection starts the moment you add it.
━━━ WHY ZEVR GUARD ━━━
✔ Blocks malware & phishing with a threat list that updates itself daily — no waiting for extension updates ✔ Detects lookalike phishing domains (examp1e.com, exаmple.com, example.com.verify-account.net) with on-device heuristics — caught even before they reach any blocklist ✔ Blocks entire countries with one tap — see a connection you don't like on the map, block everything from that region ✔ Guards password entry: warns before you type a password on an unencrypted page, a suspected lookalike, or a site you've never signed into ✔ Identifies the companies behind 115,000+ tracker signals, not just cryptic domain names ✔ 100% local matching — your browsing URLs never leave your device. No telemetry, ever ✔ Built for Manifest V3 from day one — works today, works after the MV2 shutdown ✔ Fully open source (GPL-3.0) — every claim above is verifiable in the code
━━━ WHAT YOU'LL SEE ━━━
Screenshots use seeded sample data so the popup, side panel, and warning screen can be shown clearly in a single image. The "Dangerous" risk score shown for zevrhq.com (our own site) is a demonstration value — in real use, every score is computed from the actual third-party connections seen on that page. zevrhq.com itself is not classified as malicious; it's used only as a placeholder host.
━━━ HOW IT WORKS ━━━
Zevr Guard never sends your browsing history anywhere. The only automatic outbound request is a daily fetch of threat-list updates from our CDN — it carries no information about you or the sites you visit. The single exception is one you control: clicking "Report as phishing" sends that one domain name to us for review, and nothing else. Don't take our word for it: the code is public.
━━━ OPEN SOURCE ━━━
Source code (GPL-3.0): https://github.com/krystasis/zevr-guard
FAQs
Block ads, trackers, malware & phishing. See who your browser talks to on a live world map. No setup — 100% local, no data sent.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.