Oasis Security disclosed CVE-2026-65105, a DNS rebinding flaw in NVIDIA's NemoClaw stack that let a single malicious webpage seize control of a local Ollama server and plant a hidden, persistent instruction inside the model's chat template.
Oasis Security disclosed CVE-2026-65105, a DNS rebinding flaw in NVIDIA's NemoClaw stack that let a single malicious webpage seize control of a local Ollama server and plant a hidden, persistent instruction inside the model's chat template.
Unit 42 researchers found five malicious skills on ClawHub that slipped past automated scanners, delivering AMOS malware and running agentic financial scams. The AI agent skill marketplace is the new npm — and it has the same supply chain problem.
A new research paper describes an automated attack that poisons an AI agent's durable memory through a single email, with success rates above 70% against current frontier models. The planted lie loads into every subsequent session until manually audited.
Three high-severity vulnerabilities in the OpenClaw AI assistant allow a remotely-sent WhatsApp message to trigger host code execution, SSH key theft, and Docker socket escape. All three are patched in version 2026.6.6.