Skip to content
Intelligibberish
  • News
  • Articles
  • Guides
  • Tools
  • About

Tag

#security

← All articles

Privacy Mar 23, 2026

Langflow Under Attack: Critical RCE Exploited Within 20 Hours of Disclosure

A single HTTP request can own your AI workflow server. CVE-2026-33017 shows why authentication shouldn't be optional.

Analysis Mar 23, 2026

Your Customer Service Chatbot Is a Security Hole

IEEE S&P research finds 10,000+ websites running vulnerable AI chatbot plugins. Attackers can forge conversations, hijack tools, and extract system prompts.

Privacy Mar 23, 2026

OpenClaw's CVE Avalanche: 156 Security Advisories, 28 Published Vulnerabilities, and Counting

The AI agent that couldn't stop getting hacked now has 4 critical and 52 high-severity flaws. Here's the latest wave of March 2026 CVEs.

Privacy Mar 21, 2026

AI Security Roundup: Meta's Rogue Agent, PleaseFix Vulnerabilities, and LRMs That Jailbreak Other AIs

A rogue AI agent triggers Sev 1 at Meta, agentic browsers leak passwords, and researchers prove AI can autonomously jailbreak other AI with 97% success.

Privacy Mar 19, 2026

OpenClaw's Security Nightmare: 341 Malicious Skills, RCE Vulnerabilities, and the GlassWorm Campaign

The open-source AI agent with 135,000+ GitHub stars has become the center of 2026's first major AI security crisis

Privacy Mar 18, 2026

GlassWorm Attack Hijacks Hundreds of Python Repos Through Stolen GitHub Tokens

A self-propagating malware campaign steals developer credentials via malicious VS Code extensions, then force-pushes cryptocurrency-stealing code into legitimate Python projects.

Privacy Mar 17, 2026

PleaseFix: The Vulnerability That Lets Attackers Hijack Your AI Agent Through a Calendar Invite

Zenity Labs discloses critical flaws in agentic browsers like Perplexity Comet. A zero-click attack can steal local files and passwords without user interaction.

Privacy Mar 15, 2026

OpenClaw's Supply Chain Collapse: How 1,184 Malicious Skills Poisoned the AI Agent Ecosystem

One in five packages in OpenClaw's ClawHub registry contain malicious code. The first coordinated attack on AI agent infrastructure reveals systemic vulnerabilities that enterprises are only beginning to understand.

Analysis Mar 15, 2026

OpenAI Buys Promptfoo to Lock Down Enterprise AI Agents

The acquisition brings 25% Fortune 500 penetration and security testing that enterprises demand before deploying AI agents in production

Privacy Mar 14, 2026

AI Security Roundup: Critical Flaws in vLLM, AnythingLLM, and MS-Agent, Plus Rogue Agents Gone Wild

A busy week for AI vulnerabilities: video-based RCE, chat injection leading to full system compromise, and research showing AI agents autonomously bypass security controls.

Privacy Mar 14, 2026

Perplexity's Personal Computer Wants 24/7 Access to Your Files

A $200/month Mac mini running an always-on AI agent with full file system access raises serious privacy questions - especially after Perplexity's recent security track record.

Analysis Mar 9, 2026

Claude AI Found 22 Firefox Vulnerabilities in Two Weeks That Decades of Fuzzing Missed

Anthropic's Claude Opus 4.6 discovered 14 high-severity bugs in Firefox including a CVSS 9.8 JIT flaw, demonstrating that AI security research can find logic errors traditional tools overlook.

Analysis Mar 8, 2026

Clinejection: How a GitHub Issue Title Compromised 4,000 Developer Machines

A prompt injection attack against Cline's AI triage bot escalated into a supply chain compromise - installing unauthorized software on thousands of developer systems.

Privacy Mar 8, 2026

Critical MS-Agent Vulnerability Lets Attackers Hijack AI Agents for Full System Control

CVE-2026-2256 in ModelScope's MS-Agent framework enables command injection through prompt manipulation, with no vendor patch available.

Analysis Mar 7, 2026

Agents of Chaos: 38 Researchers Red-Teamed AI Agents With Real System Access. Here's What Broke.

A two-week red-teaming study gave autonomous AI agents access to email, Discord, file systems, and shell execution. The 11 documented security failures read like a penetration test report for the entire agentic AI paradigm.

Analysis Mar 7, 2026

The Accountability Gap: AI Agents Are Acting Without Permission - and No One Knows Who's Responsible

88% of organizations report AI agent security incidents. Only 14% deploy agents with full security approval. When autonomous systems cause harm, traditional accountability breaks down.

Analysis Mar 6, 2026

JetStream Raises $34M to Fix Enterprise AI's Visibility Problem

Most companies have no idea what their AI systems are actually doing. A CrowdStrike-backed startup thinks it can change that.

Privacy Mar 6, 2026

Your AI Browser Can Steal Your Passwords via a Calendar Invite

Zenity Labs reveals how a malicious calendar event could let attackers hijack Perplexity's Comet browser to exfiltrate local files and take over your 1Password account.

Privacy Mar 5, 2026

AI Security This Week: Cursor RCE, 8,000 Exposed MCP Servers, and LLMs Jailbreaking LLMs

Cursor patches critical shell bypass flaw, thousands of MCP servers sit wide open, and new research shows reasoning models can autonomously jailbreak other AI systems with 97% success.

Privacy Mar 5, 2026

Chrome's AI Panel Had a Hole Big Enough to Hijack Your Camera and Microphone

A patched Chrome vulnerability let malicious extensions hijack Gemini's access to your camera, microphone, and files. Here's what happened.

Local AI Mar 3, 2026

Lobster Trap: The Open-Source Tool That Watches What Your AI Agents Say

Veea releases a sub-millisecond security proxy for AI agents under MIT license as new research shows 88% of organizations have experienced agent security incidents.

Privacy Mar 2, 2026

Google's Quantum-Safe HTTPS: How Merkle Trees Will Keep the Web Secure

Google and Cloudflare are deploying Merkle Tree Certificates to protect HTTPS against quantum computer attacks without breaking the internet

Local AI Mar 2, 2026

IronCurtain: The Open-Source 'Firewall' for AI Agents That Might Actually Work

A veteran Google security engineer built a sandbox system that treats AI agents as fundamentally untrusted - and it could be the model for safe agent deployment.

Privacy Mar 1, 2026

Ni8mare: Critical n8n Vulnerability Exposes 100,000 AI Workflow Servers to Takeover

A perfect 10.0 CVSS vulnerability in the popular workflow automation platform lets attackers hijack self-hosted instances used for AI agent automation without authentication.

← Newer3 / 5Older →
Intelligibberish

Making sense of AI overwhelm. Independent, self-hosted, no trackers.

News Articles Guides Tools About Disclosure Privacy RSS

© 2026 Intelligibberish. Making sense of AI overwhelm.