Attackers exploited Anthropic's Claude Code source leak to create malicious GitHub repos promising 'enterprise features.' The ZIP archive installs Vidar info-stealer and GhostSocks proxy malware. A direct consequence of the March npm leak.
Credit card data from 28 million U.S. consumers shows Anthropic gaining paid subscribers at record rates, fueled by Super Bowl ads, the Pentagon feud, Claude Code, and Computer Use. What this means for the AI platform race and OpenClaw users.
AI agent search demand jumped 7.5x in a quarter. Office workers in South Korea are paying premium prices for Claude Code courses and custom agent installation. The fear: fall behind, get laid off.
DryRun Security tested Claude Code, OpenAI Codex, and Google Gemini on realistic app builds. Across 30 pull requests, 87% contained at least one vulnerability. The pattern: broken access control, missing WebSocket auth, weak JWT secrets, and unmounted rate limits.
Two critical CVEs in Anthropic's Claude Code exploited MCP configuration to achieve remote code execution and API key theft. What OpenClaw users should know about supply chain attacks on AI agents.