HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks you first. It installs in about a minute, runs on your own machine, and a typical check takes under 50 milliseconds. Your files are never uploaded, and the whole thing works with no internet connection. The people exposed here ar

HOL has released HOL Guard, an open-source antivirus tool designed to operate between an AI assistant and the host computer. The tool, which installs locally and does not require an internet connection, aims to protect users from risky actions by AI agents by pausing potentially dangerous commands and seeking user approval. HOL Guard is compatible with several AI assistants, including Claude Code, Cursor, Codex, Gemini CLI, OpenCode, Hermes, and OpenClaw.
The software processes commands in under 50 milliseconds and does not upload user files. It offers four security settings: Gentle, Balanced, Strict, and Paranoid. The default setting, Balanced, is designed to prompt users for confirmation on actions such as secret or data exfiltration access, destructive or encoded execution, prompt injection attempts, dangerous MCP calls, malicious skills, and persistence mechanisms. It also warns about network egress and package scripts, and blocks attempts to bypass HOL Guard itself.
Strict mode adds warnings for low-confidence signals, while Paranoid mode interrupts any unfamiliar action originating from an external tool server. Michael Kantor, president of HOL, stated that the design goal was to provide protection without rendering the AI agent unusable. He acknowledged that while some detection signatures are simple and publicly visible in the source code, the system also relies on behavioral analysis. This includes parsing command structures across wrappers, pipelines, redirects, and embedded commands, as well as monitoring executable and environment provenance, sensitive-path access, network destinations, artifact identity and hash changes, and explicit bypass attempts. Kantor clarified that the tool still incorporates pattern matching as one of several inputs.
HOL Guard's effectiveness relies on continuous operation, and the company recognizes that tools that generate too many interruptions may be uninstalled. Due to its privacy-centric design, which disables local telemetry and cloud sync by default, HOL cannot track user adoption rates for different security modes or determine how many users keep the product active after downloading. Users can review a local history of allowed and blocked actions to adjust their settings.
The tool checks commands, secret access, and plugin installations before execution. HOL Guard is not presented as a complete solution for prompt injection prevention, and its companion plugin scanner does not guarantee safety. The package has accumulated over 552,000 downloads, though this figure represents total fetches rather than active installations. HOL Guard is freely available on GitHub.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]