Skip to content
Intelligibberish
  • News
  • Articles
  • Guides
  • Tools
  • About

Tag

#security

← All articles

Analysis Apr 2, 2026

Anthropic Accidentally Leaked 512,000 Lines of Claude Code Source — Then DMCA'd 8,000 Repos Trying to Clean Up

A missing .npmignore entry exposed Claude Code's full TypeScript codebase, revealing hidden features, anti-distillation tricks, and an unreleased always-on daemon called Kairos.

Privacy Apr 1, 2026

9 CVEs in 4 Days: OpenClaw's Security Crisis Deepens

OpenClaw went from one CVE to nine in four days, with 12% of its marketplace confirmed malicious. Plus: ChatGPT's patched DNS exfiltration flaw.

Privacy Mar 31, 2026

OpenClaw: The AI Agent That Broke Every Record and Then Broke Security

The fastest-growing open source project in GitHub history has become 2026's first major AI security disaster, with 135,000+ exposed instances, 9 CVEs in 4 days, and malware-laced skills.

Privacy Mar 29, 2026

TeamPCP Goes Nuclear: Iran-Targeted Kubernetes Wiper, WAV File Steganography, LAPSUS$ Partnership

The supply chain attackers behind Trivy are now wiping Iranian infrastructure, hiding malware in audio files, and extorting enterprises with help from LAPSUS$.

Privacy Mar 29, 2026

AI Security Roundup: TeamPCP Strikes Telnyx, LangChain/LangGraph Vulnerabilities Expose Enterprise Data

TeamPCP's supply chain campaign continues with a WAV file steganography attack on Telnyx. Meanwhile, three vulnerabilities in LangChain and LangGraph can leak files, secrets, and conversation histories.

Privacy Mar 28, 2026

Anthropic Accidentally Leaks 'Claude Mythos': A Step-Change AI Model With 'Unprecedented Cybersecurity Risks'

A misconfigured CMS exposed 3,000 internal documents revealing Anthropic's most powerful model yet—one the company says could 'exploit vulnerabilities in ways that far outpace defenders.'

Privacy Mar 28, 2026

Cal AI Breach Exposes 3 Million Users' Health Data - Child Records Included

A calorie tracking app trusted with your weight, meals, and fitness goals was wide open. The Firebase misconfiguration let anyone read the entire database without credentials.

Privacy Mar 28, 2026

OpenClaw Security Crisis: Industry Rallies as Cisco and OpenClawd Ship Emergency Defenses

After 12% of ClawHub skills turned out to be malware and 135,000 instances were exposed, Cisco releases DefenseClaw and OpenClawd adds verified skill screening. The AI agent ecosystem is racing to catch up.

Privacy Mar 28, 2026

AI Coding Tools Are Flooding Open Source With Security Holes

Georgia Tech researchers tracking real CVEs find 35 vulnerabilities from AI-generated code in March alone—and estimate the actual number is 10x higher.

Privacy Mar 27, 2026

OpenClaw: How the Hottest AI Agent Became a Security Nightmare in Three Weeks

135,000+ GitHub stars. Four critical CVEs. 12% of its marketplace poisoned with malware. OpenClaw's rise to fame came with a security crisis that every AI agent user needs to understand.

Tools Mar 26, 2026

Claude Code Auto Mode: When Your AI Decides Its Own Permissions

Anthropic's new auto mode lets Claude Code approve its own actions, using an ML classifier to block risky operations. It's convenient, but is it safe?

Privacy Mar 25, 2026

AI Security Roundup: TeamPCP's Supply Chain Rampage, LiteLLM Poisoned, Langflow Exploited in 20 Hours

A coordinated supply chain campaign has compromised Trivy, LiteLLM, and dozens of npm packages. Meanwhile, Langflow attackers built working exploits within hours of disclosure.

Privacy Mar 25, 2026

AI Security Roundup: Trivy Supply Chain Attack Spawns Self-Spreading Worm, Langflow Exploited in 20 Hours

Security scanners become attack vectors, AI agent platforms get RCE'd before patches exist, and 400+ GitHub repos fall to GlassWorm. Plus: a new secrets scanner built for AI coding agents.

Tools Mar 25, 2026

Betterleaks: The Open-Source Secrets Scanner Built for AI Coding Agents

The creator of Gitleaks releases a faster, more accurate successor with 98.6% recall and native AI agent integration. Here's why it matters.

Analysis Mar 25, 2026

Reasoning Models Now Jailbreak Other AI Systems With 97% Success

Nature study shows large reasoning models can autonomously bypass safety guardrails across nine major AI systems. No human expertise required.

Privacy Mar 23, 2026

Images That Hijack AI: Visual Prompt Injection Achieves 90% Attack Success

New research reveals multimodal LLMs are vulnerable to hidden instructions embedded in images. Mind maps, steganography, and physical signage all bypass text-based safety filters.

Privacy Mar 23, 2026

Langflow Under Attack: Critical RCE Exploited Within 20 Hours of Disclosure

A single HTTP request can own your AI workflow server. CVE-2026-33017 shows why authentication shouldn't be optional.

Analysis Mar 23, 2026

Your Customer Service Chatbot Is a Security Hole

IEEE S&P research finds 10,000+ websites running vulnerable AI chatbot plugins. Attackers can forge conversations, hijack tools, and extract system prompts.

Privacy Mar 23, 2026

OpenClaw's CVE Avalanche: 156 Security Advisories, 28 Published Vulnerabilities, and Counting

The AI agent that couldn't stop getting hacked now has 4 critical and 52 high-severity flaws. Here's the latest wave of March 2026 CVEs.

Privacy Mar 21, 2026

AI Security Roundup: Meta's Rogue Agent, PleaseFix Vulnerabilities, and LRMs That Jailbreak Other AIs

A rogue AI agent triggers Sev 1 at Meta, agentic browsers leak passwords, and researchers prove AI can autonomously jailbreak other AI with 97% success.

Privacy Mar 19, 2026

OpenClaw's Security Nightmare: 341 Malicious Skills, RCE Vulnerabilities, and the GlassWorm Campaign

The open-source AI agent with 135,000+ GitHub stars has become the center of 2026's first major AI security crisis

Privacy Mar 18, 2026

GlassWorm Attack Hijacks Hundreds of Python Repos Through Stolen GitHub Tokens

A self-propagating malware campaign steals developer credentials via malicious VS Code extensions, then force-pushes cryptocurrency-stealing code into legitimate Python projects.

Privacy Mar 17, 2026

PleaseFix: The Vulnerability That Lets Attackers Hijack Your AI Agent Through a Calendar Invite

Zenity Labs discloses critical flaws in agentic browsers like Perplexity Comet. A zero-click attack can steal local files and passwords without user interaction.

Privacy Mar 15, 2026

OpenClaw's Supply Chain Collapse: How 1,184 Malicious Skills Poisoned the AI Agent Ecosystem

One in five packages in OpenClaw's ClawHub registry contain malicious code. The first coordinated attack on AI agent infrastructure reveals systemic vulnerabilities that enterprises are only beginning to understand.

← Newer2 / 5Older →
Intelligibberish

Independent analysis and commentary on artificial intelligence.

News Articles Guides Tools About Disclosure Privacy RSS

© 2026 Intelligibberish. Signal, not noise.