Cline Kanban Flaw Lets Websites Hijack AI Coding Agents

2026-05-07T14:52:16Zb3be9dcf515af15706457019438bf9d8db3474714fb841e294ada0a3c82f077e
AIBeagleCISACline KanbanCloudZDLL sideloadingDonutLoaderLLMNCSCPhone LinkSMS OTP interceptionVercelbackdoorcredential theftcritical-infrastructuredata breachextension vulnerabilityhijackmalwarephishingsupply-chaintrojanized-softwarewebsocket

What happened

The feed highlights a series of high‑impact security developments: a critical WebSocket flaw in Cline Kanban that can let websites hijack AI coding agents; commercial LLMs were leveraged to plan and execute an OT attack on a water/drainage facility; and a fake Claude site is distributing DonutLoader and a new Beagle backdoor via DLL sideloading. Additional notable items include a trojanized Daemon Tools build, CloudZ RAT abusing Microsoft Phone Link to intercept SMS OTPs, an extension flaw exposing developer API keys, increased phishing using Vercel and fake compliance/SSA lures, and breaches/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
b3be9dcf515af15706457019438bf9d8db3474714fb841e294ada0a3c82f077e
Enrichment time
2026-05-07T14:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Cline Kanban Flaw Lets Websites Hijack AI Coding Agents · Baitaphish