AuthMind — OpenClaw’s 230 malicious skills expose agentic supply-chain risk
AuthMind highlights how OpenClaw’s community skill ecosystem enabled malware-like behavior, data exfiltration, and prompt injection via popular skills and extensions.
High-signal AI/security/automation notes.
AuthMind highlights how OpenClaw’s community skill ecosystem enabled malware-like behavior, data exfiltration, and prompt injection via popular skills and extensions.
Radware’s ZombieAgent technique shows how indirect prompt injection can silently exfiltrate data from ChatGPT connector targets using pre-built URLs and long-term memory persistence.
Darktrace 2026 report finds 76% of security professionals concerned about AI agent security implications, launches Darktrace/SECURE AI for enterprise AI governance and agent monitoring.
A critical sandbox escape in n8n (CVE-2026-25049, CVSS 9.4) bypasses the December 2025 fix for CVE-2025-68613, letting any workflow author execute arbitrary system commands and steal every stored credential.
A critical flaw in Docker Ask Gordon AI assistant lets attackers embed prompt-injection payloads in Docker image LABEL fields, which the MCP Gateway executes without validation — enabling RCE and data exfiltration.
ChatInject shows that formatting malicious payloads to mimic chat templates can significantly raise prompt-injection success rates in LLM agents, including multi-turn persuasion variants.
Two critical vulnerabilities in Chainlit (CVE-2026-22218 arbitrary file read, CVE-2026-22219 SSRF) let attackers steal cloud API keys and pivot into enterprise environments—no user interaction required.
A deep dive into the security risks of autonomous AI agents like OpenClaw (formerly Moltbot/Clawdbot), detailing attack surfaces and hardening strategies.
The 2026 International AI Safety Report finds that criminals actively use AI in cyberattacks, underground markets sell pre-packaged AI exploit tools, and frontier models can now detect when they are being evaluated.
CVE-2026-0755: a CVSS 9.8 zero-day in gemini-mcp-tool allows unauthenticated remote code execution through command injection in the execAsync method. No patch available.
UCSC researchers demonstrate CHAI, a physical-world indirect prompt injection attack that uses printed road signs to hijack vision-language models driving autonomous vehicles and drones.
CVE-2026-22778: a critical RCE chain in vLLM lets attackers execute arbitrary commands on AI serving infrastructure by sending a crafted video URL.
AgentDoG introduces a three-dimensional risk taxonomy and open-source guardrail models (4B–8B) that diagnose root causes of unsafe AI agent actions across tool use, planning, and environmental interaction.
A new survey introduces the SENTINEL framework for securing AI agents in cyber-physical systems, covering deepfake-driven attacks, MCP vulnerabilities, and defense-in-depth strategies validated against a real-world smart grid deployment.
Clutch Security analyzed MCP server deployments across enterprise environments and found 95% run on developer endpoints with no MCP-specific detection, 38% are unofficial packages from unknown authors, and 3% ship with hardcoded credentials.