Oasis Security — ClawJacked OpenClaw WebSocket takeover
Oasis Security details ClawJacked, a localhost WebSocket attack chain that let any website hijack OpenClaw agents and brute-force gateway passwords, fixed in v2026.2.25+.
High-signal AI/security/automation notes.
Oasis Security details ClawJacked, a localhost WebSocket attack chain that let any website hijack OpenClaw agents and brute-force gateway passwords, fixed in v2026.2.25+.
A new survey maps jailbreak attacks and defenses across LLMs and VLMs, proposing a unified, layered defense model.
ServiceNow patches CVE-2026-0542, an unauthenticated RCE in the ServiceNow AI Platform sandbox, with updates for hosted and self-hosted deployments.
A vLLM config path instantiates classes from auto_map without honoring trust_remote_code, enabling remote code execution when loading model configs.
CVE-2026-27896 in the MCP Go SDK breaks JSON-RPC field strictness via case-insensitive and Unicode-folded matching, enabling method/params confusion.
CVE-2026-27735 allows path traversal in mcp-server-git’s git_add tool, letting attackers stage files outside the repo boundary for potential exfiltration.
The 2025 AI Agent Index surveys 30 deployed agents and finds major gaps in safety disclosures, testing transparency, and accountability.
Orca Security details RoguePilot, a passive prompt injection in GitHub Codespaces that can coerce Copilot to exfiltrate GITHUB_TOKENs.
A new arXiv study benchmarks prompt-injection and jailbreak robustness across open-source LLMs and finds lightweight defenses are bypassable.
Endor Labs details six patched OpenClaw vulnerabilities (SSRF, auth bypass, path traversal) found via agentic data-flow analysis, with CVEs and GHSAs covering tool and webhook attack paths.
SD Times highlights MCP security and privacy gaps, including prompt injection risk, server verification challenges, and runtime policy enforcement needs.
A new arXiv paper maps agentic AI runtime supply-chain threats, from context injection to tool supply-chain abuse, and proposes zero-trust runtime defenses.
Silent Egress shows how URL preview prompt injection can trigger stealthy data exfiltration in tool-using LLM agents, and why network egress controls matter.
IBM’s 2026 X-Force Threat Intelligence Index flags AI-accelerated attacks, dark‑web trading of AI chatbot credentials, and a surge in exploitation of public‑facing apps.
IronCurtain proposes MCP-proxy sandboxing with policy enforcement and isolated execution modes for personal AI agents.
Researchers propose a circuit-level jailbreak method (HMNS) that suppresses attention heads and injects nullspace perturbations to bypass safety defenses with fewer queries.
A survey of LLM agent ecosystem threats that unifies input-level prompt attacks with protocol-level exploits and maps real incidents to a single threat model.
Check Point details Claude Code project configuration flaws enabling hook/MCP command execution and API key exfiltration when opening untrusted repos.
CrowdStrike’s 2026 Global Threat Report highlights prompt-injection abuse of GenAI tools, LLM-enabled malware, and faster breakout times.
Trail of Bits details how prompt injection against Perplexity’s Comet browser could exfiltrate Gmail data via agentic browsing tools.