WebMCP exposes structured website actions for AI agents. See how it works, why it matters, and how to test it in Chrome 146.
APT28 exploited CVE-2026-21513, an MSHTML zero-day (CVSS 8.8), using malicious LNK files to bypass security controls and execute code.