The AI security nightmare is here and it looks suspiciously like lobster

The Verge
A hacker exploited a prompt injection vulnerability in the Cline AI coding tool to install the OpenClaw agent everywhere.

Summary

A hacker successfully exploited a prompt injection vulnerability in the popular open-source AI coding agent, Cline, to automatically install the viral AI agent OpenClaw across users' computers. Security researcher Adnan Khan had previously surfaced this flaw, which involved manipulating Anthropic's Claude model within Cline's workflow to execute unauthorized instructions. While the installed agents were fortunately not activated, the incident highlights the severe security risks posed by increasingly autonomous AI software given control over user systems. Prompt injections are difficult to defend against, prompting some companies like OpenAI to introduce protective measures such as ChatGPT's Lockdown Mode. The exploit was only fixed after the researcher publicly disclosed the vulnerability, despite having privately warned Cline weeks earlier.

(Source:The Verge)