High-signal AI/security/automation notes.
Acronis TRU identified 575+ malicious OpenClaw skills across 13 accounts and Hugging Face repositories used as multi-stage infection chains for trojans, cryptominers, and infostealers.
LayerX discovered a Chrome extension vulnerability (ClaudeBleed) that lets any extension hijack Claude in Chrome for data exfiltration, email abuse, and document sharing.
CISA, NSA, NCSC-UK, NCSC-NZ, Canadian Cyber Centre, and ASD/ACSC co-authored guidance urging slow, careful adoption of agentic AI, warning that the interconnected attack surface amplifies organizational security gaps.
Zscaler ThreatLabz details a supply-chain campaign where a deceptive OpenClaw skill delivers Remcos RAT on Windows and GhostLoader stealer on macOS/Linux via hidden installer commands.
PyPI prompt template library banks <= 2.4.1 uses unsandboxed Jinja2, allowing Server-Side Template Injection and full RCE when user-supplied templates reach Prompt().
Federal Reserve and Treasury officials warned bank CEOs about automated zero-day discovery after Claude Mythos found thousands of flaws — as Bloomberg reports unauthorized access via a contractor account.
CVSS 10.0 RCE in Postiz, an AI social media scheduling tool: a malicious PR Dockerfile triggers code execution in GitHub Actions and exfiltrates a write-all GITHUB_TOKEN.
CLI-Anything auto-generates AI agent skill files (SKILL.md) that no SAST or SCA scanner can detect, creating a new supply-chain attack surface across all major coding agents.
Four SSRF-related CVEs disclosed in FastGPT, an open-source AI agent platform: unauthenticated SSRF, MCP tool URL bypass, DNS rebinding, and inconsistent SSRF protection.
Forcepoint researchers discovered 10 real-world indirect prompt injection payloads hidden in web content, targeting AI agents for financial fraud, data destruction, and API key theft.