Vulnerabilities in PDF platforms from Foxit and Apryse could have been exploited for account takeover, data exfiltration, and other attacks.
Three of the four vulnerabilities remained unpatched months after OX Security reported them to the maintainers.
The malicious version of Cline's npm package — 2.3.0 — was downloaded more than 4,000 times before it was removed.
The module targets Claude Code, Claude Desktop, Cursor, Microsoft Visual Studio Code (VS Code) Continue, and Windsurf. It also harvests API keys for nine large language models (LLM) providers: ...