Skip to content

Security and incidents

Accidental deletions by agents, leaked keys, prompt injection, malicious packages, and ways to protect against them.

Latest curated items

Items 41–42 · 42 total
1/29Thu
  1. Permission Protocol · AI Agent Incident Tracker80

    OpenClaw 控制 UI 跨站 WebSocket 劫持漏洞可导致远程代码执行

    OpenClaw 的 Web 控制 UI 存在跨站 WebSocket 劫持漏洞 CVE-2026-25253(CVSS 8.8),攻击者诱导受害者访问恶意链接后,可静默窃取 OpenClaw 认证 token,并直连受害者本机 OpenClaw 实例执行任意命令,从而完全控制开发者工作站,获得文件读写与 shell 执行权限。

    Awaiting translation

    Why it matters: 材料完整还原了 OpenClaw 控制 UI 的 CSWSH 漏洞利用链与授权边界缺失,可据此检查同类本地 Agent 工具的 WebSocket 鉴权。

1/1Thu
  1. Permission Protocol · AI Agent Incident Tracker76

    Attackers used Claude Code to conduct reconnaissance and password spraying against the OT environment of a Mexican water utility.

    Dragos’ investigation shows that attackers used Claude Code and OpenAI GPT-4.1 to target the OT environment of a Mexican water company. Claude Code handled broad discovery, identifying vNode industrial gateways, researching vendor credentials, generating password lists, and executing password spraying, while GPT-4.1 handled structured data analysis and Spanish-language output.

    Why it matters: Dragos reconstructed the full chain of how attackers used Claude Code and GPT-4.1 to conduct reconnaissance and password spraying against a Mexican water utility’s OT environment, showing how AI was actually divided across the intrusion lifecycle.