OpenClaw's Security Nightmare: 341 Malicious Skills, RCE Vulnerabilities, and the GlassWorm Campaign
The open-source AI agent with 135,000+ GitHub stars has become the center of 2026's first major AI security crisis
Tag
The open-source AI agent with 135,000+ GitHub stars has become the center of 2026's first major AI security crisis
A busy week for AI vulnerabilities: video-based RCE, chat injection leading to full system compromise, and research showing AI agents autonomously bypass security controls.
A two-week red-teaming study gave autonomous AI agents access to email, Discord, file systems, and shell execution. The 11 documented security failures read like a penetration test report for the entire agentic AI paradigm.
Zenity Labs reveals how a malicious calendar event could let attackers hijack Perplexity's Comet browser to exfiltrate local files and take over your 1Password account.
Cursor patches critical shell bypass flaw, thousands of MCP servers sit wide open, and new research shows reasoning models can autonomously jailbreak other AI systems with 97% success.
While enterprises focus on training data and model safety, inference - where AI actually processes requests - has become an overlooked security frontier with critical vulnerabilities.
GitHub patches critical Copilot takeover flaw, Microsoft warns of AI memory manipulation attacks, and thousands of Gemini API keys are found in public code.
Cisco's 2026 State of AI Security report reveals a dangerous gap: enterprises are deploying AI agents faster than they can secure them, with MCP vulnerabilities and prompt injection attacks proliferating.
This week in AI security: Chat & Ask AI exposes 300 million messages, Microsoft patches Copilot email vulnerability, and vibe-coded apps prove trivially hackable.
Microsoft Semantic Kernel has back-to-back CVSS 10.0 vulnerabilities enabling remote code execution and arbitrary file writes through AI agent function calls
A CVSS 9.8 flaw in the popular AI inference engine allows unauthenticated remote code execution through malicious video URLs. Patch now if you're running multimodal models.
Two vulnerabilities in the popular Chainlit AI framework allow attackers to steal cloud credentials, API keys, and user data from enterprise chatbots.
The viral AI agent went from 135K GitHub stars to enterprise blacklists in three weeks. Here's what went wrong and why it matters for every AI agent.