Incident CVE-2026-LGTM
A malicious package named foxhole-lz4 bypassed seven AI-powered security gates on the creats.io registry, exfiltrating credentials for 96 hours before being resolved by treaty. The incident, which aff…
A malicious package named foxhole-lz4 bypassed seven AI-powered security gates on the creats.io registry, exfiltrating credentials for 96 hours before being resolved by treaty. The incident, which aff…
A new guide walks users through deploying an OpenClaw AI agent on a virtual private server, balancing cost, availability, and privacy. The tutorial covers server configuration, system requirements, an…
A public security test of an AI assistant powered by Anthropic's Claude Opus 4.6 withstood over 6,000 prompt injection attempts without leaking secrets, but revealed infrastructure vulnerabilities inc…
An AI assistant named Fiu, built on OpenClaw and powered by Claude Opus 4.6, withstood over 6,000 email-based prompt injection attacks from more than 2,000 people without leaking its secrets.env file,…
Developer Bas Nijholt launched MindRoom, an open-source system that embeds AI agents in the Matrix communication protocol, enabling them to operate across platforms like Slack, Telegram, and Discord w…
Snyk security researchers found that 13.4% of 3,984 AI agent skills from ClawHub and skills.sh contain critical security flaws, with 36.82% having at least one security issue, including malware, crede…
SchedPilot, a social media scheduler with an API for AI agents, launched to help creators and entrepreneurs automate posting across 10+ platforms. The tool supports integration with AI assistants like…
Kaspersky reported a sharp rise in cyberattacks targeting small and medium-sized businesses with fake AI tool lures, detecting over 33,300 such attacks in the first four months of 2026—nearly five tim…
Two open-source agent runtimes, OpenClaw and Hermes Agent, are competing for control of the agent layer. OpenClaw, backed by OpenAI, Nvidia, and Microsoft, focuses on broad channel connectivity and en…
A developer built My Virtual Office, a self-hosted pixel workspace that visualizes local AI agents in a virtual office environment. The tool makes agent activity legible at a glance, showing when agen…
Loop engineering, a new trend in software development, allows engineers to design autonomous coding agents that operate without human intervention, freeing them from manual prompting. The concept, pop…
An AI agent named Sol, collaborating with human Amre, built a skills marketplace with 39 production-grade tools across 9 categories. The most technically interesting skill is a self-learning capabilit…
A new architecture using Azure Bot Service, Azure Functions, and Azure Service Bus enables secure Telegram connectivity for AI agents without exposing local machines to the internet. The approach elim…
OpenClaw-memgpt, a new plugin for the OpenClaw agent framework, implements MemGPT's three-tier memory architecture—core, recall, and archival memory—to provide persistent, searchable memory across ses…
Unit 42 researchers discovered a malicious campaign between February and May 2026 targeting OpenClaw's ClawHub marketplace, where attackers published skills like 'tradingview-ai-indicator-assistant' t…
Four projects share the name 'SkillsGuard', but only one—AgentGuard by GoPlus Security—is a verifiable, installable runtime guard. A scanner called 'SkillGuard' was flagged as malicious and pulled fro…
Greptile's analysis of OpenClaw, an open-source repository, reveals pull requests surged from two per week to 3,400 per week, while merge rates plummeted from 48% to below 9.3%, with one contributor s…
Rahul of Greptile reports that AI-generated pull request spam is overwhelming open-source projects like OpenClaw, where PRs surged from 2 to 3,400 per week and merge rates dropped from 48% to 9.3%. Th…
Jesse Genet, a former startup founder turned stay-at-home parent, uses a team of agentic AIs named Claire, Sylvie, Clark, Dan, and Chloe to manage household tasks, homeschooling, paperwork, and softwa…
A developer outlines a method for transforming a local skill library into agent-ready documentation. By grouping skills into a capability map with concrete triggers, agents can make better decisions a…