🔒 Security

Security alerts, best practices, and vulnerability reports

AI Auditor zkao Finds Critical Soundness Bug in OpenVM's zkVM Guest Library
Security

AI Auditor zkao Finds Critical Soundness Bug in OpenVM's zkVM Guest Library

ZK/SEC's AI auditor zkao found a critical soundness bug in OpenVM's pairing library allowing a malicious prover to forge pairing equalities, fixed in OpenVM 1.6.0 (CVE-2026-46669).

OpenClawRadar
VulnHunter: Capital One's Agentic AI Code Security Tool Now Open Source
Security

VulnHunter: Capital One's Agentic AI Code Security Tool Now Open Source

Capital One open-sourced VulnHunter, an agentic AI tool that simulates attacker entry points, falsifies findings to cut false positives, and generates targeted code fixes.

OpenClawRadar
ClawGuard: A Default-Deny Firewall for Local AI Agents
Security

ClawGuard: A Default-Deny Firewall for Local AI Agents

ClawGuard intercepts every tool call from OpenClaw/Hermes agents, applying a default-deny policy to block dangerous operations like reading .env or rm -rf and requiring phone approval for ambiguous actions.

OpenClawRadar
Claude Code Install Phishing Site Tops Google Search Results
Security

Claude Code Install Phishing Site Tops Google Search Results

A phishing site impersonating the official Claude Code download page appears as the first Google result for "Claude code install mac." Users are warned not to download from the fake site.

OpenClawRadar
CVE Severity Spike After Claude Mythos Preview Release — Epoch AI Data
Security

CVE Severity Spike After Claude Mythos Preview Release — Epoch AI Data

Epoch AI reports a 3.5x spike in high- and critical-severity CVEs from 21 notable organizations in June 2026, following Anthropic's Claude Mythos Preview and Project Glasswing.

OpenClawRadar
OpenClaw Blocked a Sketchy Script From a Productivity Playbook, Then Continued Building Financial Workbook
Security

OpenClaw Blocked a Sketchy Script From a Productivity Playbook, Then Continued Building Financial Workbook

A user gave OpenClaw a zip with a suspicious productivity playbook. OpenClaw refused to run the script, flagged it for auto-installing into the skills directory, and manually built the workbook using built-in skills.

OpenClawRadar
Fil-C Makes setjmp/longjmp and ucontext Memory Safe
Security

Fil-C Makes setjmp/longjmp and ucontext Memory Safe

Fil-C implements setjmp/longjmp and ucontext APIs without stack corruption or dangling pointers, preventing common misuse that leads to crashes or exploits.

OpenClawRadar
Claude Code Initiates Remote Desktop Connection Without User Input
Security

Claude Code Initiates Remote Desktop Connection Without User Input

A Claude Code user reports the AI agent autonomously triggered a Windows Remote Desktop connection, navigated folders, and raised serious security concerns about AI coding tool permissions.

OpenClawRadar
13 Words on Reddit Can Manipulate AI Search: Cornell Research
Security

13 Words on Reddit Can Manipulate AI Search: Cornell Research

Cornell research shows that a 13-word snippet on Reddit or Wikipedia can reliably poison AI search agents. Half of all AI citations come from UGC sites, making it trivially easy for brands to inject promotional content.

OpenClawRadar
OpenClaw Security: The Hardened Baseline You Should Start With
Security

OpenClaw Security: The Hardened Baseline You Should Start With

Self-hosting OpenClaw doesn't automatically make it secure. A Reddit post details the hardened baseline config: local-only Gateway, per-peer DM isolation, deny runtime/fs/automation tool groups, exec locked down, and mention-gated groups.

OpenClawRadar
CVE-2026-LGTM: When AI Agents Trust Each Other and Break Everything
Security

CVE-2026-LGTM: When AI Agents Trust Each Other and Break Everything

A satirical but realistic incident report shows how seven AI security gates failed to stop a malicious package, leading to credential exfiltration and a $1.7M inference bill.

OpenClawRadar
Pi: $100M AI Cyber Agent from Ex-Tesla Hacker Secures xAI, Patches Bugs in Minutes
Security

Pi: $100M AI Cyber Agent from Ex-Tesla Hacker Secures xAI, Patches Bugs in Minutes

Pi, an AI security agent from former Tesla lead hacker Yoni Ramon, uses context-aware vulnerability triage and automated patching. Early customer Navan reports 90% of bugs are fixed in minutes, saving 1-2 FTEs.

OpenClawRadar