Security researchers report an expanded GlassWorm campaign using malicious Open VSX extensions and hidden Unicode code to target developers and steal sensitive data.
China’s CNCERT warns that OpenClaw AI agent security weaknesses could enable prompt injection attacks, endpoint compromise, and sensitive data exfiltration.