Researchers managed to steal GitHub OAuth tokens by abusing a command injection vulnerability.
Apple has introduced a security feature in macOS Tahoe 26.4 that blocks pasting and executing potentially harmful commands in Terminal and alerts users to possible risks.