Related Threat Clusters
-
Jscrambler npm Package Compromised in Supply Chain Attack
On July 11, 2026, multiple malicious versions of the jscrambler npm package were published, exploiting a compromised npm publishing credential. The affected versions (8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.0) included…
18 articles · Updated July 12, 2026 -
Microsoft's Record Patch Tuesday in June 2026 Addresses 206 Vulnerabilities
In June 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including critical flaws in Windows kernel and BitLocker. Notable CVEs include a zero-day in Visual Studio Code that…
229 articles · Updated July 1, 2026 -
Critical Vulnerability in Claude Code GitHub Actions Exposes Repositories to Attacks
A critical supply chain vulnerability in Claude Code’s GitHub Actions, identified by security researcher Ryota K from GMO Flat Security, allows attackers to compromise any repository using Anthropic’s CI/CD workflow.…
18 articles · Updated June 2, 2026 -
NVIDIA NemoClaw Vulnerability Allows AI Model Poisoning via Malicious Webpage
A critical vulnerability (CVE-2026-65105) in NVIDIA's NemoClaw tool enables attackers to gain unauthenticated access to the local Ollama model server through a single visit to a malicious webpage. Discovered by Cyera's…
10 articles · Updated August 25, 2026 -
Malicious AI Skills Campaign Targets 1.7 Million Users, Exposes Major Vulnerabilities
Zenity Labs revealed a malicious skills campaign that has affected over 1.7 million installs through Vercel's skills.sh. The campaign involved credential-stealing skills that were initially benign but later weaponized.…
4 articles · Updated August 6, 2026 -
Evolution of Chinese-Nexus Cyber Operations: Strategic Long-Term Threats
Recent research from Darktrace reveals the evolution of Chinese-nexus cyber operations over the past two decades, highlighting a shift from high-volume attacks to more strategic, identity-centric intrusions. This change…
381 articles · Updated April 2, 2026 -
GitHub Patches Critical RCE Vulnerability CVE-2026-3854
A critical remote code execution vulnerability, tracked as CVE-2026-3854, was discovered in GitHub's internal git infrastructure, allowing authenticated users to execute arbitrary commands via a crafted git push…
49 articles · Updated April 28, 2026 -
AI Tool OpenClaw Faces Security Incident Due to Command Injection
The AI tool OpenClaw has experienced a security incident stemming from a command injection vulnerability. This incident has raised concerns about the potential exploitation of the tool, which could affect various users…
1 article · Updated March 7, 2026 -
High-Risk Vulnerabilities Disclosed in OpenClaw Platform
OpenClaw, a crayfish-themed AI platform, has disclosed high-risk vulnerabilities, including CVE-2026-25253, which allows remote code execution via malicious links. The vulnerabilities pose significant risks to users,…
1 article · Updated March 7, 2026 -
China Enhances AI Governance Amid OpenClaw Vulnerabilities
On May 8, 2026, China announced new guidelines for regulating AI agents due to rising security risks linked to open-source technologies, particularly OpenClaw. The Cyberspace Administration of China (CAC), along with…
5 articles · Updated May 14, 2026
Recent Intelligence Reports
- Inside A Multi Agent Ai Framework Used To Compromise Government Entities In Asia — www.dreamgroup.com · August 29, 2026
- A Cautionary Tale About Data Breach Claims Verification And Carhartt — www.troyhunt.com · August 27, 2026
- NemoClaw's Deployment Wrapper Exposed Local AI Agents to Drive — Forkast.News · August 25, 2026
- Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw — Darkreading · August 25, 2026
- Multi — Gbhackers · August 25, 2026
- AI agents wage near — Csoonline · August 13, 2026
- AI agents used in cyberattacks on Taiwan government websites: MODA — Focustaiwan.Tw · August 13, 2026
- Taiwan Targeted By Autonomous AI Attacks — Silicon · August 13, 2026