ThreatsDay Bulletin tracks active exploits, phishing waves, AI risks, major flaws, and cybercrime crackdowns shaping this week’s threat landscape.
The malicious version of Cline's npm package — 2.3.0 — was downloaded more than 4,000 times before it was removed.
Notepad++ has adopted a "double-lock" design for its update mechanism to address recently exploited security gaps that ...
Self-hosted agents execute code with durable credentials and process untrusted input. This creates dual supply chain risk, ...
Researchers say an AI-powered code scanner traced untrusted data across layers of OpenClaw, exposing exploitable weaknesses including SSRF, authentication bypass, and path traversal.