Industry
Hackers can use 9 of the most popular AI tools to assemble massive botnets
Researchers discovered a HalluSquatting attack that exploits AI tools' tendency to hallucinate package names, which attackers can register to trick AI assistants into running malicious code and assemb
Researchers discovered a HalluSquatting attack that exploits AI tools' tendency to hallucinate package names, which attackers can register to trick AI assistants into running malicious code and assembling botnets across multiple machines. The attack successfully targeted nine popular AI coding tools including Cursor, Windsurf, GitHub Copilot, Cline, Google Gemini CLI, and the OpenClaw family of assistants.
Source: Ars Technica | 2026-07-08