Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
•
Podcasts & Audio BriefingsIBM Technology: Are AI labs ignoring cybersecurity experts?(23.09.2026 um 12:00 Uhr)
•
AI & KI NachrichtenIBM Technology: You Can't Keep Powerful AI Secret for Long🤖(23.09.2026 um 18:00 Uhr)
••
Sicherheitslücken (CVE)Security Weekly - A CRA Resource: Two People Can’t Do Everything(24.09.2026 um 16:00 Uhr)
•
AI & KI NachrichtenLiveOverflow: They Hacked OpenAI! #shorts(24.09.2026 um 12:00 Uhr)
••
Podcasts & Audio BriefingsSecurity-Insider: Klein anfangen ist der Schlüssel! #podcast #cybersecurity(21.09.2026 um 08:00 Uhr)
•
Podcasts & Audio BriefingsSecurity-Insider: Die Zukunft der digitalen Welt! #podcast #cybersecurity(22.09.2026 um 08:00 Uhr)
•
Reverse EngineeringGitHub Release: icsharpcode/ILSpy v11.1 (23.09.2026)(23.09.2026 um 08:43 Uhr)
••
Podcasts & Audio BriefingsIBM Technology: Are AI labs ignoring cybersecurity experts?(23.09.2026 um 12:00 Uhr)
•
AI & KI NachrichtenIBM Technology: You Can't Keep Powerful AI Secret for Long🤖(23.09.2026 um 18:00 Uhr)
••
Sicherheitslücken (CVE)Security Weekly - A CRA Resource: Two People Can’t Do Everything(24.09.2026 um 16:00 Uhr)
•
AI & KI NachrichtenLiveOverflow: They Hacked OpenAI! #shorts(24.09.2026 um 12:00 Uhr)
••
Podcasts & Audio BriefingsSecurity-Insider: Klein anfangen ist der Schlüssel! #podcast #cybersecurity(21.09.2026 um 08:00 Uhr)
•
Podcasts & Audio BriefingsSecurity-Insider: Die Zukunft der digitalen Welt! #podcast #cybersecurity(22.09.2026 um 08:00 Uhr)
•
Reverse EngineeringGitHub Release: icsharpcode/ILSpy v11.1 (23.09.2026)(23.09.2026 um 08:43 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

GitHub Release: cline/cline vsdk/sdk/v0.0.86 (24.09.2026)

Release sdk/sdk/v0.0.86 von cline/cline auf GitHub: A text-only turn truncated at the output-token limit now gets one compact-and-retry attempt per run before…

0
↗ Quelle (GitHub · cline/cline)
Reagiere als Erste:r — dein Feedback zählt!
cline/clinevsdk/sdk/v0.0.8624.09.2026@github-actions[bot]

  • A text-only turn truncated at the output-token limit now gets one compact-and-retry attempt per run before the existing nudge-and-retry recovery. Local OpenAI-compatible servers (llama.cpp, Ollama, LM Studio) cap generation at whatever context remains regardless of the requested output budget, so long sessions died mid-answer even with sensible limits. The runtime now routes that finish through the same forced-compaction path prepareTurn uses for context-window overflow; if compaction has nothing to remove or the retry truncates again, the loop's nudge-and-retry takes over and the original max-tokens error still surfaces with the partial answer persisted. Turns that produced tool calls, or provider-executed tool activity, are never replayed. A new task.max_tokens_recovery lifecycle event (started, retried, failed) measures how often it helps

  • Hub startup failures now say why. ensureCompatibleLocalHubUrl swallowed the error from ensureDetachedHubServer, so every failure read as "No compatible hub runtime is available"; the cause is now appended to that message and attached as cause, and the daemon reports its own startup failure (hub.daemon.startup) before flushing telemetry. The wait for a freshly spawned hub also goes from 8 to 15 seconds for every client, because the first launch after an install or update regularly takes 8 to 13 seconds on Windows while the new binary is scanned

  • Session renames made through the hub now persist. HubRuntimeHost.updateSession folded the new title into metadata.title, but the persistence layer only treats an explicit title as a rename, so the name reverted on relaunch, and wholesale metadata replacement dropped other keys such as pinned state. session.update now carries prompt and title as their own fields and leaves untouched metadata alone

  • Errors shown in a session now survive navigation and resume. Terminal failures, including those recorded after retries are exhausted, are persisted as display-only history entries that hosts render when a session is reopened, and those entries are excluded from compaction and from what the model sees

  • Plugin slash commands are now a shared core service. createPluginCommandService in @cline/core owns plugin command discovery, loading, name and result normalization, and execution, and both the CLI and the desktop sidecar consume it. A plugin that fails to load (an invalid manifest, a sandbox startup timeout) no longer rejects the service: the failure is logged, the empty command set is cached for the current plugin set, and the load is retried after 30 seconds instead of spawning a sandbox on every prompt. Handler exceptions still propagate

  • Model lists for endpoint-owned providers now report failures instead of returning an empty list. For private-catalog providers (LiteLLM, Baseten, Hicap, Poolside) and providers backed by a modelsSourceUrl (Ollama, LM Studio), an unreachable host, TLS rejection, or bad key now propagates from getLocalProviderModels when the caller asks for errors, so hosts can show the cause rather than "no models". The hub guards its initial model load so a failing default provider no longer aborts peer setup

  • Aborting a request now takes effect during the empty-response backoff. The retry middleware slept through its backoff without watching the AbortSignal and then re-dialed with an already-aborted signal, so cancellation surfaced up to one backoff late. createGatewayApiHandlerAsync also ignored setAbortSignal() because it captured the signal at construction; it now reads the live one like the sync handler

  • The yolo-mode system prompt replaces the vague "always show your planning process" rule with concrete output guidance: keep plans to one short paragraph, act once the next step is clear, put code and edit payloads in tool arguments rather than drafting them in text, skip preambles for routine tool calls, and resolve repeated uncertainty with a focused check instead of more speculation

  • New built-in provider aiand (ai&), an OpenAI-compatible endpoint serving open-weight models from Japan. It reads AIAND_API_KEY and defaults to zai-org/glm-5.3

  • Streaming transcription in @cline/llms now covers native OpenAI (gpt-realtime-whisper with a transcription-bound client secret), Vercel AI Gateway, and ElevenLabs, exposed through the new getBuiltinStreamingTranscriptionModels. Gateway and OpenAI-compatible batch transcription use AI SDK transcription with retries, cancellation, and providerOptions, detect the audio format from the bytes, and return segments and warnings alongside the text. Voice model discovery validates audio-to-text capability and keeps realtime-only models separate

  • @cline/core has a new ./cloud subpath export with the shared cloud session runtime (API client, controller, snapshots, state) that hosts previously each implemented. The cron spec watcher also resolves its directory with realpathSync.native before watching, avoiding a fatal libuv assertion on Windows when the path contains a short-name segment like RUNNER~1

  • @cline/shared exports toPosixSeparators, replacing four copies of the same helper across core and the VS Code extension. No behavior change

  • Refreshed the model catalog: still 209 providers, 6,237 to 6,386 models. The bundled Cline catalog drops z-ai/glm-5.3-flash, cline-free/solar-pro4, and poolside/laguna-s-2.1:free, and adds cline-free/mimo-v2.6-flash. The resolved default model changes for 19 providers that do not pin one in builtins.ts: 11 land on Claude Opus 5.5 (Cortecs, CrossModel, DigitalOcean, Eden AI, GitHub Copilot, both LLM Gateway providers, Ofox, Requesty, Vertex, Vivgrid), both StepFun providers move to Step 5 Preview, Above to MiMo V2.6 Flash, Fireworks to Ember-1, Kenari to DeepSeek V4.1 Flash, NanoGPT to Aion 3.5, OpenCode Go to Space Bunny Free, and Pioneer to GLiNER 2.5 Multi. If you use one of those providers without pinning a model, expect a different default


Full Changelog: sdk/sdk/v0.0.85...sdk/sdk/v0.0.86

SOC Incident Playbook: Remote Code Execution (RCE) Defense
title: Detect Exploitation - GitHub Release: cline/cline vsdk/sdk/v0.0.86 (24.09.2026)
id: 9cf3803a-a95e-4090-b5fc-431ccf849520
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-24
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-24"
        description = "YARA Signature for "
    strings:
        $str = "GitHub Release: cline/cline vs" ascii wide
    condition:
        any of them
}
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich GitHub Release: cline/cline vsdk/sdk/v0..... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

⚡ Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-97360 | HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary fil…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel • Rechts: nächster Artikel • unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel TTP ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger • Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick