Welp, just found a 1-click RCE in @pewdiepie's
Odysseus Chat... more like Odysseus Hack amirite?
CSRF + Command Injection allows you to pwn a users server in a single click including adding your own backdoored admin account (sound on).
Will share full breakdown soon.
Meet Miora ✨your AI creative agent studio, now in international beta.
💡 Here's the idea: Images, video, UI/UX, 3D - all generated right there, on the same canvas
🪄No tool-switching. No context loss. The whole creative project lives in one place.
The agents aren't basic:
* they understand design context, reason through problems, call tools on their own
* inpaint, edit locally, split backgrounds
* skills system: use ours, build yours, share with the community
* they read what's on your canvas and remember what you like
* a crew of built-in Specialists, each owning their craft: brand, storyboards, illustration, UI/UX, video, 3D
👉https://t.co/MFloEuYWAQ
Two weeks ago, we quietly launched OpenHuman.
Today: 100+ paid users who use the product daily. 200+ stars on GitHub. #7 trending.
Time to introduce it properly.
⸻
OpenHuman is an open-source, local-first AI assistant.
You connect your tools like Gmail, Slack, Notion, Calendar, Drive, Telegram, Discord, and it builds a private memory of your digital life on your machine.
It drafts replies in your voice, surfaces what you missed, and acts on your behalf.
⸻
OpenClaw and Hermes Agent are excellent, but they live in the terminal. They assume you're comfortable with config files, Python environments, and the command line.
OpenHuman doesn't. Download the app, sign in to the tools you already use, done. No keys to manage. No environments to set up. No CLI.
⸻
What we're building toward: an AI that knows you well enough to act on your behalf, without ever sending your data to a server.
The cloud-first AI era is ending. Local is the next decade.
Codex now works directly in Chrome on macOS and Windows.
It’s even better at working with apps and sites in Chrome, and now works in parallel across tabs in the background without taking over your browser.
To get started, install the Chrome plugin in the Codex app.
This is why I stay away from these "skill hubs" unless it's a serious team that has security as #1 priority just avoid, your agent and your pc will thank you
⚠️ Attackers poisoned Hugging Face & ClawHub (OpenClaw) with 575+ malicious skills from just 13 accounts.
🔸 Fake helpful AI tools that install trojans, miners & stealers (Windows + macOS)
🔸 Use hidden commands & indirect prompt injection
Quick action: Never install random AI skills or models. Always verify the source.
Read: https://t.co/CmdDBXuzTy