AI Security Roundup: OpenClaw's Nine CVEs in Four Days
OpenClaw collected nine CVEs in four days with 135,000 instances exposed. Plus: GitHub RCE, Flowise exploitation, and CrewAI trust failures.
Tag
OpenClaw collected nine CVEs in four days with 135,000 instances exposed. Plus: GitHub RCE, Flowise exploitation, and CrewAI trust failures.
Researchers poison one file in OpenClaw and watch attack success rates triple. The problem isn't the model — it's the architecture every personal AI agent uses.
OpenClaw went from one CVE to nine in four days, with 12% of its marketplace confirmed malicious. Plus: ChatGPT's patched DNS exfiltration flaw.
OpenClaw's security crisis escalates with nine new vulnerabilities including a CVSS 9.9 admin bypass, plus researchers confirm nearly 1 in 8 marketplace skills steal user data.
After 12% of ClawHub skills turned out to be malware and 135,000 instances were exposed, Cisco releases DefenseClaw and OpenClawd adds verified skill screening. The AI agent ecosystem is racing to catch up.
135,000+ GitHub stars. Four critical CVEs. 12% of its marketplace poisoned with malware. OpenClaw's rise to fame came with a security crisis that every AI agent user needs to understand.
The AI agent that couldn't stop getting hacked now has 4 critical and 52 high-severity flaws. Here's the latest wave of March 2026 CVEs.
The open-source AI agent with 135,000+ GitHub stars has become the center of 2026's first major AI security crisis
One in five packages in OpenClaw's ClawHub registry contain malicious code. The first coordinated attack on AI agent infrastructure reveals systemic vulnerabilities that enterprises are only beginning to understand.
Ollama's new OpenClaw integration lets you run AI agents locally through WhatsApp, Telegram, or Slack. Here's how it works, what you need, and the security risks nobody mentions.
ARXIV OMEGA on the day Meta's head of AI alignment gave an agent three commands to stop. It ignored all of them.
Former Google and Stripe security head Niels Provos built an open source sandbox that assumes AI agents will go rogue. Here's how it works.
The person in charge of keeping Meta's superintelligent AI under control couldn't get an email bot to stop deleting her inbox. This is either hilarious or terrifying.
The popular local inference tool now installs and configures OpenClaw automatically, giving desktop users access to AI agents running Kimi-K2.5 and GLM-5 with a single command.
The viral AI agent went from 135K GitHub stars to enterprise blacklists in three weeks. Here's what went wrong and why it matters for every AI agent.
Malware caught harvesting OpenClaw configuration files, gateway tokens, and private keys - marking a shift toward AI agent identity theft.
Peter Steinberger built the most popular open-source AI agent. Now he's joining OpenAI, raising questions about the future of independent AI tools and Europe's brain drain.
Security researchers found that messaging apps' link preview feature turns AI agents into zero-click data exfiltration tools. Teams, Slack, Discord, and Telegram are all affected.
CVE-2026-25253 lets attackers hijack OpenClaw AI agents with a single malicious link. Over 135,000 instances are exposed online, many still unpatched.
OpenClaw's skills marketplace was weaponized to steal passwords and crypto wallets. A single attacker published 314 fake tools. This is what happens when AI agents get app stores.
A vibe-coded Reddit clone for bots exposed 1.5 million API keys, let anyone hijack any agent, and turned prompt injection into a contagion. Here's how it happened.
Security researchers discovered hundreds of malware-laced OpenClaw skills stealing crypto wallets, passwords, and API keys. The AI agent ecosystem just got its npm moment.