Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Introducing universal sign-in: a seamless solution for every way you login

Today we're releasing universal sign-in, a new experience from 1Password that provides a seamless and secure way to sign into any site with your preferred method. It's currently available to all customers in the latest version of the 1Password browser extension.

Top 10 Business Logic Security Companies in 2026

For business logic attacks, prioritize runtime behavioral detection over API discovery alone, tools that map workflows and catch abuse mid-sequence, not just at the request level. AppSentinels leads with a purpose-built Business Logic Graph plus behavioral fraud detection; Salt Security and Cequence are also strong runtime-behavioral options. Picture this: someone applies the same discount code 40,000 times in a row, or slides a decimal point in a checkout request to buy a $500 item for $5. No malware.

MECCHA CHAMELEON can't hide from the RCE

TL;DR: We found another delayed RCE in MECCHA CHAMELEON. When playing on an attacker’s map, they can abuse an exposed function to arbitrarily write files to the victim’s system. This can lead to remote code execution on the victim’s system after a restart. We reported the issue to the game’s maintainers, and they fixed the vulnerability in the 4.0.0 update. This update is automatically installed before launching the game.

Exploitability Without Exploitation: When Attention Is the Signal

Nucleus Insights flagged 14 vulnerabilities with real-world exploitation activity that looked risky before CISA added them to KEV. The key takeaway: all 14 were later listed in KEV. Acting on those signals would have been the right call every time, just earlier.

Ten Years, Two Photos, and One Bet That Got Much Bigger

These two photos were taken almost ten years apart. The first is from 2016, with Sam Altman at Y Combinator. The second came from an unexpected encounter in Silicon Valley almost a decade later. I’ll come back to it at the end. With Sam Altman at Y Combinator in 2016. I was 22 when I arrived in Silicon Valley on a one-way ticket, with a little bit of cash that was barely enough for one month of living there, and a thesis I wanted to prove.

From Hotspots to Lookalike Domains: 3 Phishing Tactics to Watch

In our previous “ABC’s of ‘ishing” posts, we explored how attackers use social media, calendar invites, fake CAPTCHA challenges, and other trusted tools to deceive users. This next installment looks at three phishing techniques that continue to put organizations and individuals at risk: evil twin phishing, domain spoofing, and email phishing.