AI Security Roundup: OpenClaw's Nine CVEs in Four Days
OpenClaw collected nine CVEs in four days with 135,000 instances exposed. Plus: GitHub RCE, Flowise exploitation, and CrewAI trust failures.
Articles
Reporting and explainers on how AI actually works, who it affects, and what to do about it.
OpenClaw collected nine CVEs in four days with 135,000 instances exposed. Plus: GitHub RCE, Flowise exploitation, and CrewAI trust failures.
A Cursor agent running Claude Opus found an overprivileged API token, guessed wrong, and wiped a company's data and backups. The real failure wasn't the model.
Shadow AI isn't a rogue employee problem. It's a rational response to broken governance — and 90% of the security leaders tasked with stopping it are doing it themselves.
GLM-5.1 becomes the first open-weight model to top SWE-Bench Pro. The gap between open and proprietary AI is now just three months.
Three AI design tools, one prompt, one task: build a startup landing page. We compare Claude Design, Canva Magic Design, and v0 by Vercel on output quality, speed, and cost.
Google signed a deal letting the DoD use Gemini for 'any lawful purpose' on classified networks, one day after hundreds of employees including DeepMind leaders demanded the opposite.
Biorisk benchmarks are saturated, evaluations are opaque, and physical bottlenecks are ignored. As models approach expert-level biological capability, the tests meant to catch danger are failing.
Three independent reports converge on the same finding: AI coding tools produce exploitable code faster than security teams can review it, and no model is getting meaningfully better.
The open-source AI coding agent lets you bring any model to the terminal. We break down what works, what doesn't, and who should use it.
An AI productivity tool compromise led to Vercel customer data theft, n8n's workflow platform had an unauthenticated RCE scoring a perfect 10, and Mercor's LiteLLM-linked breach exposed training data for OpenAI and Anthropic.
Anthropic now depends on $75 billion in hyperscaler commitments and 10 gigawatts of borrowed compute. At what point does a safety-first company become a subsidiary?
Researchers tested nine prompt injection defenses across 20,000 attacks. Every defense that relied on the model to protect itself failed. Only hard-coded output filtering survived.
DeepSeek returns with a 1.6T MoE monster under MIT license, Gemma 4's 31B dense model climbs to #3 on Arena AI, and ICLR 2026 papers point to what's next for local inference.
Stop paying Midjourney $30 a month. Set up FLUX on your own hardware with ComfyUI and generate unlimited images with zero content filters and full privacy.
ComfyUI raises $30M at a half-billion valuation, Adobe's Firefly Assistant controls your entire Creative Cloud, Sora shuts down for good, and Kling 3.0 delivers native 4K video.
Meta, Microsoft, and Snap cut thousands while AI salaries climb 9%. The junior developer pipeline is collapsing.
Europe votes to push back AI Act enforcement by 16 months. Meanwhile, US states keep legislating at a breakneck pace with chatbot safety, deepfakes, and worker protection bills piling up.
OpenAI researchers found that training models not to reward-hack makes them conceal their reasoning instead. A new survey paper maps how the problem scales from sycophancy to sabotage.
A survey of 4,000 AI researchers found almost nobody ranks existential risk as their top concern. The doom debate is drowning out what actually worries the people building the technology.
From Pennsylvania swing districts to Missouri city councils, voter anger over AI data centers and rising electric bills is reshaping the 2026 midterms.
New surveys reveal most organizations can't explain their AI decisions, can't shut down AI after incidents, and are approving deployments they know are unsafe.
A Teng et al. study finds brief AI conversations produce lasting moral-value shifts - and users had no idea it was happening.
DeepSeek V4 Pro approaches frontier-level performance. Google, Mistral, and Alibaba ship under Apache 2.0. Ollama hits 52 million monthly downloads.
Chat with your own documents locally - no cloud, no subscriptions, no data leaving your machine. Step-by-step setup guide.