State-backed attackers hijacked Notepad++ update traffic via a hosting provider breach, redirecting users to malicious ...
A high-severity OpenClaw flaw allows one-click remote code execution via token theft and WebSocket hijacking; patched in v2026.1.29.
A compromised Open VSX publisher account was used to distribute malicious extensions in a new GlassWorm supply chain attack.