Posts
High-signal AI/security/automation notes.
OpenAI — GPT-5.4-Cyber lowers refusal boundary for defensive cybersecurity
OpenClaw Claude Bridge — Sandbox bypass allows arbitrary tool execution in spawned subprocesses (CVE-2026-39398)
CVE-2026-39398 exposes critical sandbox bypass vulnerability in openclaw-claude-bridge where --allowed-tools flag fails to restrict CLI tool access, enabling potential arbitrary command execution with CVSS 7.5 severity.
OpenClaw — Critical privilege escalation vulnerability CVE-2026-33579
OpenClaw CVE-2026-33579 allows attackers with basic pairing privileges to gain full administrative access, enabling complete instance takeover and data exfiltration — CVSS 8.1-9.8 severity.
OpenClaw Security Crisis — What 346K Stars & 135K Exposed Instances Teach Us
OWASP — GenAI Exploit Round-up Report Q1 2026
OWASP GenAI Security Project publishes its quarterly exploit round-up for Q1 2026, covering eight major AI security incidents from Claude-assisted government breaches to Flowise RCE and supply chain attacks.
Praetorian — Indirect Prompt Injection Bypasses LLM Supervisor Agents
Praetorian researchers demonstrate how indirect prompt injection via user profile fields bypasses supervisor agent detection in multi-model AI customer service systems.
PraisonAI — Four critical vulnerabilities expose multi-agent AI systems to sandbox escape, RCE, and data exfiltration
CVE-2026-39888 through CVE-2026-39891 reveal critical vulnerabilities in PraisonAI multi-agent systems enabling sandbox escape, remote code execution, and unauthorized data access.
PraisonAI — execute_code() vulnerability allows arbitrary Python code execution in multi-agent systems
CVE-2026-34938 exposes critical vulnerability in PraisonAI multi-agent systems where execute_code() function can run attacker-controlled Python code, enabling full system compromise.
Red Hat OpenShift AI — Kubernetes Token Disclosure (CVE-2026-5483)
CVE-2026-5483 (CVSS 8.5) in Red Hat OpenShift AI odh-dashboard exposes Kubernetes Service Account tokens via NodeJS endpoint, enabling unauthorized cluster access.
Steganographic Canaries — arXiv:2603.28655 LLM Misuse Detection
arXiv:2603.28655 — First framework combining symbolic and linguistic steganography into layered canary documents for detecting unauthorized LLM processing and AI-driven malware.
Token Security — Azure MCP RCE vulnerability enables cloud takeover
Token Security researchers discovered a critical Remote Code Execution vulnerability in Azure MCP server enabling unauthenticated attackers to compromise Azure environments and steal Entra ID credentials.
ToxSec — AI-Generated Code Leaks Hardcoded Secrets at Scale
Unit 42 — Chrome Gemini Live panel hijack vulnerability enables camera/mic access
Unit 42 — Vertex AI P4SA overprivileged agents expose Google Cloud data
Varonis — STARTAGENT: Architectural Vulnerabilities in Agentic LLM Browsers
Varonis Threat Labs analyzes Perplexity Comet, OpenAI Atlas, Edge Copilot, and Brave Leo — revealing how XSS escalates to full agent hijack in agentic LLM browsers.
arXiv — VibeGuard: Security Gate Framework for AI-Generated Code
VibeGuard addresses security blind spots in AI-generated code workflows, detecting packaging misconfigurations, source map exposure, and supply chain risks that traditional tools miss.
Vitalik Buterin — Warns against AI agent security risks, shares private LLM stack
Ethereum co-founder Vitalik Buterin abandoned cloud AI services, running Qwen3.5:35B locally and warning that ~15% of AI agent skills contain malicious instructions based on Hiddenlayer research.
Wiz Research — Axios npm Supply Chain Compromise Delivers Cross-Platform RAT
Critical supply chain attack on axios npm package introduces plain-crypto-js dependency delivering remote access trojan targeting Windows, macOS, and Linux systems — impacting AI/ML infrastructure relying on HTTP client libraries.
WordPress TTS Plugin — CVE-2026-1233 Database Exposure
RedPacket Security — WordPress Text-to-Speech plugin (AI Voices by Mementor) exposes database credentials via hardcoded password in all versions ≤1.9.8 — CVE-2026-1233.