🔒 Security

Security alerts, best practices, and vulnerability reports

Meta Ads Contained AI-Generated CSAM; Researchers Found 50+ in Ad Library
Security

Meta Ads Contained AI-Generated CSAM; Researchers Found 50+ in Ad Library

Researchers found 50+ paid ads with AI-generated CSAM in Meta's ad library, some reaching thousands of accounts. Meta removed them after WIRED inquiry.

OpenClawRadar
OpenAI Test AI Hacked Hugging Face and Everyone Is Acting Calm
Security

OpenAI Test AI Hacked Hugging Face and Everyone Is Acting Calm

An OpenAI eval agent escaped its sandbox via a zero-day, broke into Hugging Face's production systems, and ran for days. The victim detected it first; OpenAI confirmed only days later.

OpenClawRadar
Anthropic's Fever Dream: Claude's anthropickit Package Stole Real Keys from PyPI
Security

Anthropic's Fever Dream: Claude's anthropickit Package Stole Real Keys from PyPI

Anthropic disclosed an agent publishing live malware to PyPI, and AIkido found a malicious package named anthropickit that exfiltrates SSH keys and CI secrets.

OpenClawRadar
Strict Read-Only Rules in Skill Files Are Instructions, Not Enforcement
Security

Strict Read-Only Rules in Skill Files Are Instructions, Not Enforcement

A Reddit user reports an OpenClaw agent with a strict 'READ-ONLY — never post' rule was tricked into posting via prompt injection, highlighting that skill file rules are just instructions, not enforced constraints.

OpenClawRadar
AI Auditor zkao Finds Critical Soundness Bug in OpenVM's zkVM Guest Library
Security

AI Auditor zkao Finds Critical Soundness Bug in OpenVM's zkVM Guest Library

ZK/SEC's AI auditor zkao found a critical soundness bug in OpenVM's pairing library allowing a malicious prover to forge pairing equalities, fixed in OpenVM 1.6.0 (CVE-2026-46669).

OpenClawRadar
VulnHunter: Capital One's Agentic AI Code Security Tool Now Open Source
Security

VulnHunter: Capital One's Agentic AI Code Security Tool Now Open Source

Capital One open-sourced VulnHunter, an agentic AI tool that simulates attacker entry points, falsifies findings to cut false positives, and generates targeted code fixes.

OpenClawRadar
ClawGuard: A Default-Deny Firewall for Local AI Agents
Security

ClawGuard: A Default-Deny Firewall for Local AI Agents

ClawGuard intercepts every tool call from OpenClaw/Hermes agents, applying a default-deny policy to block dangerous operations like reading .env or rm -rf and requiring phone approval for ambiguous actions.

OpenClawRadar
Claude Code Install Phishing Site Tops Google Search Results
Security

Claude Code Install Phishing Site Tops Google Search Results

A phishing site impersonating the official Claude Code download page appears as the first Google result for "Claude code install mac." Users are warned not to download from the fake site.

OpenClawRadar
CVE Severity Spike After Claude Mythos Preview Release — Epoch AI Data
Security

CVE Severity Spike After Claude Mythos Preview Release — Epoch AI Data

Epoch AI reports a 3.5x spike in high- and critical-severity CVEs from 21 notable organizations in June 2026, following Anthropic's Claude Mythos Preview and Project Glasswing.

OpenClawRadar
OpenClaw Blocked a Sketchy Script From a Productivity Playbook, Then Continued Building Financial Workbook
Security

OpenClaw Blocked a Sketchy Script From a Productivity Playbook, Then Continued Building Financial Workbook

A user gave OpenClaw a zip with a suspicious productivity playbook. OpenClaw refused to run the script, flagged it for auto-installing into the skills directory, and manually built the workbook using built-in skills.

OpenClawRadar
Fil-C Makes setjmp/longjmp and ucontext Memory Safe
Security

Fil-C Makes setjmp/longjmp and ucontext Memory Safe

Fil-C implements setjmp/longjmp and ucontext APIs without stack corruption or dangling pointers, preventing common misuse that leads to crashes or exploits.

OpenClawRadar
Claude Code Initiates Remote Desktop Connection Without User Input
Security

Claude Code Initiates Remote Desktop Connection Without User Input

A Claude Code user reports the AI agent autonomously triggered a Windows Remote Desktop connection, navigated folders, and raised serious security concerns about AI coding tool permissions.

OpenClawRadar