AI Security Roundup: OpenClaw's Nine CVEs in Four Days
OpenClaw collected nine CVEs in four days with 135,000 instances exposed. Plus: GitHub RCE, Flowise exploitation, and CrewAI trust failures.
Tag
OpenClaw collected nine CVEs in four days with 135,000 instances exposed. Plus: GitHub RCE, Flowise exploitation, and CrewAI trust failures.
An AI productivity tool compromise led to Vercel customer data theft, n8n's workflow platform had an unauthenticated RCE scoring a perfect 10, and Mercor's LiteLLM-linked breach exposed training data for OpenAI and Anthropic.
A vibe-coding platform exposed every project's secrets through a trivial API flaw, Anthropic's MCP protocol enables remote code execution across 200,000 servers, and NIST can't keep up with AI-driven vulnerability discovery.
An open-weight model tops the hardest coding benchmark for the first time. A 1-bit LLM runs on a phone. And the protocol connecting AI to everything just passed React's adoption curve.
New program pays researchers to find ways AI agents can be hijacked. Jailbreaks not included.
A coordinated supply chain campaign has compromised Trivy, LiteLLM, and dozens of npm packages. Meanwhile, Langflow attackers built working exploits within hours of disclosure.
Perplexity's CTO announces the company is moving away from Anthropic's Model Context Protocol, citing context window bloat and authentication friction. The shift reveals growing pains in AI tooling.
Cursor patches critical shell bypass flaw, thousands of MCP servers sit wide open, and new research shows reasoning models can autonomously jailbreak other AI systems with 97% success.
Veea releases a sub-millisecond security proxy for AI agents under MIT license as new research shows 88% of organizations have experienced agent security incidents.
A veteran Google security engineer built a sandbox system that treats AI agents as fundamentally untrusted - and it could be the model for safe agent deployment.
March 2026's open-source AI highlights: Zhipu's GLM-5 rivals GPT-5, OpenAI finally goes open, and the Linux Foundation creates a home for AI agents.
Former Google and Stripe security head Niels Provos built an open source sandbox that assumes AI agents will go rogue. Here's how it works.
Cisco's 2026 State of AI Security report reveals a dangerous gap: enterprises are deploying AI agents faster than they can secure them, with MCP vulnerabilities and prompt injection attacks proliferating.
Security researchers found that simply opening an untrusted repository in Claude Code could execute arbitrary commands and steal your Anthropic API keys - all before you saw a warning.
Xcode 26.3 introduces agentic coding, letting AI agents build projects, run tests, search docs, and iterate on fixes autonomously through the open Model Context Protocol.
Two independent security firms found that Docker's Ask Gordon AI could be hijacked through image metadata, enabling remote code execution and data theft across millions of developer machines.
A Docker AI vulnerability let attackers embed commands in image labels. Patched months ago, the pattern keeps recurring.