OpenClaw's Security Nightmare: 341 Malicious Skills, RCE Vulnerabilities, and the GlassWorm Campaign
The open-source AI agent with 135,000+ GitHub stars has become the center of 2026's first major AI security crisis
Tag
The open-source AI agent with 135,000+ GitHub stars has become the center of 2026's first major AI security crisis
A self-propagating malware campaign steals developer credentials via malicious VS Code extensions, then force-pushes cryptocurrency-stealing code into legitimate Python projects.
A prompt injection attack against Cline's AI triage bot escalated into a supply chain compromise - installing unauthorized software on thousands of developer systems.
Two vulnerabilities in the popular Chainlit AI framework allow attackers to steal cloud credentials, API keys, and user data from enterprise chatbots.
UNH team built an AI that extracted magnetic data from 67,573 papers, identifying 25 new high-temperature magnets to replace rare earths in EVs.
The viral AI agent went from 135K GitHub stars to enterprise blacklists in three weeks. Here's what went wrong and why it matters for every AI agent.
AI data-center demand is squeezing DRAM supply, raising memory and device prices as manufacturers prioritize higher-margin HBM.
Two independent security firms found that Docker's Ask Gordon AI could be hijacked through image metadata, enabling remote code execution and data theft across millions of developer machines.
OpenClaw's skills marketplace was weaponized to steal passwords and crypto wallets. A single attacker published 314 fake tools. This is what happens when AI agents get app stores.
Security researchers discovered hundreds of malware-laced OpenClaw skills stealing crypto wallets, passwords, and API keys. The AI agent ecosystem just got its npm moment.
A Docker AI vulnerability let attackers embed commands in image labels. Patched months ago, the pattern keeps recurring.