Cyber Security

Infostealers added Clawdbot to their target lists before most security teams knew it was running

Clawdbot’s implementation of the Managed Conversational Platform (MCP) lacks mandatory authentication, allowing for prompt injection and providing shell access intentionally. An article published by VentureBeat on Monday highlighted these architectural vulnerabilities. By Wednesday, security researchers had confirmed these three attack …

Infostealers added Clawdbot to their target lists before most security teams knew it was running Read More »

Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code

Malicious VS Code Extensions Found Harvesting Developer Data î „Ravie Lakshmananî ‚Jan 26, 2026 AI Security / Vulnerability Cybersecurity researchers have uncovered two malicious Microsoft Visual Studio Code (VS Code) extensions that pose as AI-powered coding assistants but secretly send developer data …

Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code Read More »