One Click, Full Compromise: Critical OpenClaw Flaw Exposes 135,000 AI Agents to Remote Takeover
CVE-2026-25253 lets attackers hijack OpenClaw AI agents with a single malicious link. Over 135,000 instances are exposed online, many still unpatched.
Articles
Reporting and explainers on how AI actually works, who it affects, and what to do about it.
CVE-2026-25253 lets attackers hijack OpenClaw AI agents with a single malicious link. Over 135,000 instances are exposed online, many still unpatched.
Companies are using your browsing history, location, and shopping habits to charge you more than the person next to you. California just launched an investigation. Here's how it works.
Six of xAI's twelve co-founders have departed in eighteen months. Musk announced a four-division restructure, unveiled 'Macrohard,' and blamed the exits on performance reviews - all while preparing for a SpaceX IPO.
Austin startup raises nearly $1 billion with backing from Google, Mercedes-Benz, John Deere, and Qatar's sovereign wealth fund to bring its Apollo humanoid to factories and warehouses.
Security researchers found that Bondu's AI plush toy left its entire admin console open, exposing kids' names, birthdays, and intimate conversations. A senator wants answers.
Two independent security firms found that Docker's Ask Gordon AI could be hijacked through image metadata, enabling remote code execution and data theft across millions of developer machines.
Microsoft patches three critical command injection vulnerabilities in GitHub Copilot affecting VS Code, Visual Studio, and JetBrains. Over 20 million developers at risk from unsanitized shell inputs.
ARXIV OMEGA on how a handful of AI product launches triggered the largest non-recessionary software wipeout in 30 years - and why the humans who built these tools are running for the exits.
Perplexity launched Model Council, running your queries through Claude, GPT, and Gemini simultaneously. Multi-model consensus could reduce hallucinations, but it triples your data exposure and costs $200 a month.
University of Michigan researchers built Prima, a vision language model trained on 200,000 brain scans that diagnoses 52 neurological conditions with up to 97.5% accuracy and triages emergencies in real time.
A Firebase misconfiguration exposed 300 million messages from 25 million users. A wider scan found data leaks across 196 of 198 AI apps.
European regulators charged Meta with antitrust violations for blocking competing AI chatbots from WhatsApp's 3 billion users - while Meta AI gets exclusive access to the platform.
Google's new agentic browsing feature streams every page you visit to its servers. Here's what that means for your privacy.
A watchdog group says OpenAI classified GPT-5.3-Codex as 'high' cybersecurity risk, then released it without the safeguards their own framework requires. It could be the first test of SB 53.
Salesforce quietly laid off nearly 1,000 workers across marketing, product, and its own Agentforce AI unit. The cuts came weeks after CEO Marc Benioff said AI agents would replace most of the company's workforce.
Google DeepMind spinoff claims its unified AI system can identify hidden binding sites and predict drug interactions faster than physics-based methods
ARXIV OMEGA on how Microsoft proved that AI safety alignment can be shattered with a single training example - and what that means for the illusion of control.
An Oxford study found AI chatbots diagnose conditions correctly 94.9% of the time on paper, but only 34.5% when talking to actual people. The implications for AI benchmarks extend far beyond medicine.
OpenAI started showing ads in ChatGPT conversations on February 9. Ad personalization is on by default, targeting uses your conversation topics, and opting out may cost you message limits. The era of ad-funded AI is here.
GLM-5, Kimi K2.5, Qwen 3.5, Doubao 2.0, and MiniMax M2.2 arrive in the most concentrated wave of Chinese AI releases. Some are open-source. Here's what matters.
Claude Cowork's industry plugins crashed software stocks by 25% in a week. But the real story is a known file-stealing vulnerability Anthropic shipped anyway, and safety guidance that contradicts its own marketing.
Tiiny AI says its 300-gram Pocket Lab runs 120B models locally. The design is plausible, but performance and privacy claims remain unverified.
Apple's deal to power Siri with Google's Gemini raises questions about where your data actually goes -- especially as the two CEOs contradict each other.
A DOJ task force challenges state AI laws while the administration threatens broadband funding. The fight isn't between companies -- it's between governments.