The malicious version of Cline's npm package — 2.3.0 — was downloaded more than 4,000 times before it was removed.
A hacker tricked a popular AI coding tool into installing OpenClaw — the viral, open-source AI agent OpenClaw that “actually does things” — absolutely everywhere. Funny as a stunt, but a sign of what ...
A critical vulnerability in Grandstream GXP1600 series VoIP phones allows a remote, unauthenticated attacker to gain root privileges and silently eavesdrop on communications.
Self-hosted agents execute code with durable credentials and process untrusted input. This creates dual supply chain risk, ...