The malicious version of Cline's npm package — 2.3.0 — was downloaded more than 4,000 times before it was removed.
Four serious new vulnerabilities affect Microsoft Visual Studio Code, Cursor and Windsurf extensions, three of which remain ...
Self-hosted agents execute code with durable credentials and process untrusted input. This creates dual supply chain risk, ...