<?xml version="1.0" encoding="UTF-8"?>
    <rss version="2.0">
      <channel>
        <title>Armorer Threat Intel</title>
        <link>https://armorerlabs.com/threat-intel</link>
        <description>Evidence-backed agent security findings, controls, and timeline signals from Armorer Labs.</description>
        <language>en-us</language>
        <lastBuildDate>Sat, 12 Sep 2026 00:00:00 GMT</lastBuildDate>
        
        <item>
          <title>Apply Microsoft Security Exposure Management Secure Now agentic containment guidance</title>
          <link>https://armorerlabs.com/threat-intel/microsoft-exposure-management-secure-now-agentic-containment-2026-08</link>
          <guid>https://armorerlabs.com/threat-intel/microsoft-exposure-management-secure-now-agentic-containment-2026-08</guid>
          <description>[Control] Operators of autonomous or semi-autonomous AI agents should apply the Microsoft Security Exposure Management Secure Now containment pattern: constrain agent-initiated actions without explicit user approval, harden attack surfaces, limit blast radius, govern agent identities and permissions, and increase visibility into agent activity.</description>
          <author>Armorer Labs</author>
          <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Microsoft Security adds Secure Now agentic containment guidance under Security Exposure Management</title>
          <link>https://armorerlabs.com/threat-intel/microsoft-security-exposure-management-agentic-containment-2026-08</link>
          <guid>https://armorerlabs.com/threat-intel/microsoft-security-exposure-management-agentic-containment-2026-08</guid>
          <description>[Article] Microsoft Security Blog&apos;s August 2026 roundup announces a new &quot;Secure Now&quot; guidance under Microsoft Security Exposure Management focused on constraining autonomous agent action, hardening attack surfaces, limiting impact, governing identities and permissions, and increasing visibility.</description>
          <author>Armorer Labs</author>
          <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>COPA: Continual Preference Optimization for Adaptive Prompt Injection Defense</title>
          <link>https://armorerlabs.com/threat-intel/copa-continual-preference-optimization-prompt-injection-2026-08</link>
          <guid>https://armorerlabs.com/threat-intel/copa-continual-preference-optimization-prompt-injection-2026-08</guid>
          <description>[Article] The COPA preprint proposes continual preference optimization as a defensive paradigm against evolving prompt injection attacks, using GRPO-based optimization on newly observed attacks and margin-weighted experience replay to retain defenses against prior attack classes.</description>
          <author>Armorer Labs</author>
          <pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Post-training least-privilege restraint for tool-using agents</title>
          <link>https://armorerlabs.com/threat-intel/post-training-least-privilege-tool-using-agents-2026-08</link>
          <guid>https://armorerlabs.com/threat-intel/post-training-least-privilege-tool-using-agents-2026-08</guid>
          <description>[Control] Operators of tool-using agents in terminal and MCP environments should treat learned restraint as an additional control layer that complements, not replaces, permission gates, sandboxing, and runtime interception.</description>
          <author>Armorer Labs</author>
          <pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>arXiv preprint: Task-conditioned least-privilege learning for terminal and MCP agents</title>
          <link>https://armorerlabs.com/threat-intel/arxiv-task-conditioned-least-privilege-mcp-2026-08</link>
          <guid>https://armorerlabs.com/threat-intel/arxiv-task-conditioned-least-privilege-mcp-2026-08</guid>
          <description>[Article] This arXiv preprint (arXiv:2608.18351, submitted 2026-08-18, submitted to IEEE) proposes post-training a 4B-parameter model (Qwen3.5-4B) to choose task-conditioned authority when executing in terminal and Model Context Protocol (MCP) environments, with each action audited before execution and again from observed effects across six risk dimensions.</description>
          <author>Armorer Labs</author>
          <pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts</title>
          <link>https://armorerlabs.com/threat-intel/404media-meta-ai-instagram-account-takeover-2026-06</link>
          <guid>https://armorerlabs.com/threat-intel/404media-meta-ai-instagram-account-takeover-2026-06</guid>
          <description>[Article] 404 Media article (Jason Koebler, June 1 2026) reporting that hackers used Meta&apos;s AI support chatbot to break into high-profile Instagram accounts, including the Barack Obama White House account, the Chief Master Sergeant of Space Force&apos;s account, and Sephora&apos;s account. The exploit shows the extreme risk of offloading technical support to AI.</description>
          <author>Armorer Labs</author>
          <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Meta AI support chatbot abused to take over high-profile Instagram accounts</title>
          <link>https://armorerlabs.com/threat-intel/meta-ai-support-bot-instagram-account-takeovers-2026-06</link>
          <guid>https://armorerlabs.com/threat-intel/meta-ai-support-bot-instagram-account-takeovers-2026-06</guid>
          <description>[Finding] Threat actors used Meta&apos;s AI support chatbot to take over high-profile Instagram accounts by simply asking the bot to change the email address associated with the target account. The technique worked against several prominent accounts, including the Barack Obama White House Instagram, the Chief Master Sergeant of Space Force&apos;s account, and Sephora&apos;s account.</description>
          <author>Armorer Labs</author>
          <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>OWASP Agent Memory Guard: runtime screening for agent memory reads and writes</title>
          <link>https://armorerlabs.com/threat-intel/owasp-agent-memory-guard-2026-06</link>
          <guid>https://armorerlabs.com/threat-intel/owasp-agent-memory-guard-2026-06</guid>
          <description>[Source] OWASP Agent Memory Guard is an incubator project and reference implementation for screening AI-agent memory reads and writes against prompt injection, protected-key tampering, secret leakage, size anomalies, and rapid-change patterns.</description>
          <author>Armorer Labs</author>
          <pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Screen and policy-check agent memory operations</title>
          <link>https://armorerlabs.com/threat-intel/agent-memory-operation-screening-2026-06</link>
          <guid>https://armorerlabs.com/threat-intel/agent-memory-operation-screening-2026-06</guid>
          <description>[Control] Agent memory reads and writes should be treated as policy-relevant operations. Screening memory content for prompt injection, protected-key tampering, secret leakage, anomalous size, and unexpected churn can reduce the chance that durable context steers future privileged tool use.</description>
          <author>Armorer Labs</author>
          <pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Careful adoption controls for agentic AI services</title>
          <link>https://armorerlabs.com/threat-intel/agentic-ai-careful-adoption-guidance-2026-05</link>
          <guid>https://armorerlabs.com/threat-intel/agentic-ai-careful-adoption-guidance-2026-05</guid>
          <description>[Control] Official joint guidance and NIST/CAISI RFI analysis warn that agentic AI systems add risk when they plan, use tools and memory, access data, or act across workflows. Treat OpenClaw-style agents as privileged software identities.</description>
          <author>Armorer Labs</author>
          <pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Microsoft Agent Governance Toolkit: policy enforcement, zero-trust identity, and execution sandboxing for autonomous AI agents</title>
          <link>https://armorerlabs.com/threat-intel/microsoft-agent-governance-toolkit</link>
          <guid>https://armorerlabs.com/threat-intel/microsoft-agent-governance-toolkit</guid>
          <description>[Source] Microsoft AGT — public-preview multi-language open-source governance toolkit for autonomous AI agents. Policy engine with YAML/OPA/Cedar, SPIFFE/DID/mTLS identity, 4-privilege-ring execution sandboxing, kill switch, SLO monitoring, OWASP Agentic Top 10 coverage, MCP security gateway, 992 spec tests. Python, TypeScript, .NET, Rust, Go. Claude Code plugin.</description>
          <author>Armorer Labs</author>
          <pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>GitHub Advisory: LangChain runtime deserialization paths used overly broad allowlists</title>
          <link>https://armorerlabs.com/threat-intel/github-langchain-runtime-deserialization-allowlist-cve-2026-44843</link>
          <guid>https://armorerlabs.com/threat-intel/github-langchain-runtime-deserialization-allowlist-cve-2026-44843</guid>
          <description>[Article] GitHub advisory GHSA-pjwx-r37v-7724 describes `CVE-2026-44843`, where affected LangChain runtime paths could deserialize application-controlled run data with overly broad object allowlists.</description>
          <author>Armorer Labs</author>
          <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>LangChain runtime paths used overly broad deserialization allowlists for agent run data</title>
          <link>https://armorerlabs.com/threat-intel/langchain-runtime-deserialization-allowlist-2026-05</link>
          <guid>https://armorerlabs.com/threat-intel/langchain-runtime-deserialization-allowlist-2026-05</guid>
          <description>[Finding] GitHub advisory GHSA-pjwx-r37v-7724 reports `CVE-2026-44843`: affected `langchain-core` runtime paths could deserialize run inputs, run outputs, or application-controlled payloads with overly broad allowlists.</description>
          <author>Armorer Labs</author>
          <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>AgentTrust runtime safety layer for AI agent tool use</title>
          <link>https://armorerlabs.com/threat-intel/arxiv-agenttrust-runtime-interception-2026-05</link>
          <guid>https://armorerlabs.com/threat-intel/arxiv-agenttrust-runtime-interception-2026-05</guid>
          <description>[Article] The AgentTrust preprint describes a runtime safety layer that intercepts AI-agent tool calls before execution and returns allow, warn, block, or review verdicts for risky actions.</description>
          <author>Armorer Labs</author>
          <pubDate>Sat, 23 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Runtime interception for AI agent tool calls</title>
          <link>https://armorerlabs.com/threat-intel/agent-tool-call-runtime-interception-2026-05</link>
          <guid>https://armorerlabs.com/threat-intel/agent-tool-call-runtime-interception-2026-05</guid>
          <description>[Control] Agent operators should inspect high-impact tool calls before execution and return explicit allow, warn, block, or human-review decisions for actions involving files, shells, HTTP, credentials, or external side effects.</description>
          <author>Armorer Labs</author>
          <pubDate>Sat, 23 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>CI-based regression testing for agent safety and tool-use behavior</title>
          <link>https://armorerlabs.com/threat-intel/agent-safety-regression-testing-2026-05</link>
          <guid>https://armorerlabs.com/threat-intel/agent-safety-regression-testing-2026-05</guid>
          <description>[Control] Agent operators should turn prompt-injection findings, unsafe tool-use patterns, and production incidents into repeatable tests that inspect agent actions and run in CI as the agent, tools, prompts, and data connectors change.</description>
          <author>Armorer Labs</author>
          <pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Microsoft introduces RAMPART and Clarity for agent development safety</title>
          <link>https://armorerlabs.com/threat-intel/microsoft-rampart-clarity-agent-safety-tools-2026-05-20</link>
          <guid>https://armorerlabs.com/threat-intel/microsoft-rampart-clarity-agent-safety-tools-2026-05-20</guid>
          <description>[Article] Microsoft says agentic AI has shifted from generating text to taking actions across connected systems, and introduces RAMPART for CI-friendly agent safety tests plus Clarity for documenting design assumptions and failure analysis.</description>
          <author>Armorer Labs</author>
          <pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>NIST CAISI summary of AI agent security RFI responses</title>
          <link>https://armorerlabs.com/threat-intel/nist-caisi-ai-agent-security-rfi-summary-2026-05</link>
          <guid>https://armorerlabs.com/threat-intel/nist-caisi-ai-agent-security-rfi-summary-2026-05</guid>
          <description>[Source] NIST/CAISI summarizes public RFI responses on AI agent security, noting broad agreement that agents introduce novel security threats, create adoption barriers, and require adapted cybersecurity practices plus implementation guidance, information sharing, and standards.</description>
          <author>Armorer Labs</author>
          <pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>ClawHavoc campaign: 335 malicious OpenClaw skills distribute Atomic macOS Stealer via ClawHub</title>
          <link>https://armorerlabs.com/threat-intel/openclaw-clawhavoc-campaign-amos-2026-02</link>
          <guid>https://armorerlabs.com/threat-intel/openclaw-clawhavoc-campaign-amos-2026-02</guid>
          <description>[Finding] ClawHavoc distributed 335 malicious OpenClaw skills through ClawHub, disguising AMOS delivery as wallet, Polymarket, and YouTube utilities. Reported delivery used base64 shell scripts or password-protected ZIPs, with C2 at `91.92.242.30`.</description>
          <author>Armorer Labs</author>
          <pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>OpenClaw is a Security Nightmare — Here&apos;s the Safe Way to Run It</title>
          <link>https://armorerlabs.com/threat-intel/barrack-ai-openclaw-security-nightmare-2026-02</link>
          <guid>https://armorerlabs.com/threat-intel/barrack-ai-openclaw-security-nightmare-2026-02</guid>
          <description>[Article] Barrack.ai&apos;s February 17, 2026 article summarizes an Argus Security Platform audit of OpenClaw, covering five CVEs/GHSAs, the ClawHavoc AMOS campaign, OAuth plaintext storage, unsafe default bindings, and mitigation guidance.</description>
          <author>Armorer Labs</author>
          <pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Claw Chain: Cyera research unveils four chainable vulnerabilities in OpenClaw</title>
          <link>https://armorerlabs.com/threat-intel/cyera-claw-chain-openclaw-vulns-2026-05</link>
          <guid>https://armorerlabs.com/threat-intel/cyera-claw-chain-openclaw-vulns-2026-05</guid>
          <description>[Article] Cyera Research blog post disclosing &quot;Claw Chain&quot; — four chainable vulnerabilities in OpenClaw (all versions prior to April 23, 2026 patches). Published May 15, 2026 by Cyera Research. Covers four CVEs, attack chain, affected surface, and recommended mitigations.</description>
          <author>Armorer Labs</author>
          <pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Claw Chain: four chainable vulnerabilities in OpenClaw enable sandbox escape and privilege escalation</title>
          <link>https://armorerlabs.com/threat-intel/openclaw-claw-chain-four-chainable-vulns-2026-05</link>
          <guid>https://armorerlabs.com/threat-intel/openclaw-claw-chain-four-chainable-vulns-2026-05</guid>
          <description>[Finding] Cyera Research disclosed four chainable OpenClaw vulnerabilities affecting versions before the April 23, 2026 patches. The chain could let an attacker escape OpenShell sandbox constraints, exfiltrate secrets, escalate agent-runtime control, and persist.</description>
          <author>Armorer Labs</author>
          <pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Microsoft: When prompts become shells: RCE vulnerabilities in AI agent frameworks</title>
          <link>https://armorerlabs.com/threat-intel/microsoft-semantic-kernel-agent-rce-2026-05-07</link>
          <guid>https://armorerlabs.com/threat-intel/microsoft-semantic-kernel-agent-rce-2026-05-07</guid>
          <description>[Article] Microsoft Defender Security Research&apos;s May 7, 2026 article explains two fixed Semantic Kernel vulnerabilities where prompt-influenced tool parameters could cross into execution, file access, or sandbox-boundary impact.</description>
          <author>Armorer Labs</author>
          <pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Semantic Kernel prompt injection flaws show agent tool calls can become host execution</title>
          <link>https://armorerlabs.com/threat-intel/semantic-kernel-prompt-injection-rce-2026-05</link>
          <guid>https://armorerlabs.com/threat-intel/semantic-kernel-prompt-injection-rce-2026-05</guid>
          <description>[Finding] Microsoft Defender Security Research disclosed two fixed Semantic Kernel flaws where prompt injection could influence trusted tool parameters, reaching Python command execution in one path and unintended host file writes in another.</description>
          <author>Armorer Labs</author>
          <pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Akamai: One Is a Fluke, 3 Is a Pattern: MCP Back-End Vulnerabilities</title>
          <link>https://armorerlabs.com/threat-intel/akamai-mcp-backend-vulnerabilities-2026-05-12</link>
          <guid>https://armorerlabs.com/threat-intel/akamai-mcp-backend-vulnerabilities-2026-05-12</guid>
          <description>[Article] Akamai&apos;s May 12, 2026 research describes database-oriented MCP server flaws in Apache Doris MCP, Apache Pinot MCP, and Alibaba RDS MCP, showing how weak back-end validation can turn agent tool access into data-plane risk.</description>
          <author>Armorer Labs</author>
          <pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>MCP database server back-end validation flaws expose SQL and metadata paths</title>
          <link>https://armorerlabs.com/threat-intel/mcp-database-backend-validation-vulnerabilities-2026-05</link>
          <guid>https://armorerlabs.com/threat-intel/mcp-database-backend-validation-vulnerabilities-2026-05</guid>
          <description>[Finding] Akamai research describes three database MCP server failures: SQL injection in Apache Doris MCP, SQL-capable unauthenticated paths in Apache Pinot MCP, and unauthenticated metadata exposure in Alibaba RDS MCP.</description>
          <author>Armorer Labs</author>
          <pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Careful adoption of agentic AI services</title>
          <link>https://armorerlabs.com/threat-intel/cybergov-careful-adoption-agentic-ai-services-2026-05</link>
          <guid>https://armorerlabs.com/threat-intel/cybergov-careful-adoption-agentic-ai-services-2026-05</guid>
          <description>[Source] ASD ACSC hosts primary joint guidance from ASD ACSC, CISA, NSA, the Canadian Centre for Cyber Security, NCSC-NZ, and NCSC-UK on careful adoption of agentic AI services for operators that design, deploy, or operate LLM-based agentic systems.</description>
          <author>Armorer Labs</author>
          <pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>TanStack npm supply chain attack now a full campaign, targets AI developer tooling</title>
          <link>https://armorerlabs.com/threat-intel/intcyberdigest-tanstack-npm-attack-2026-05</link>
          <guid>https://armorerlabs.com/threat-intel/intcyberdigest-tanstack-npm-attack-2026-05</guid>
          <description>[Post] International Cyber Digest X/Twitter thread reporting an escalation of the TanStack npm supply chain attack into a broader campaign. Dated May 12, 2026. This is a social media post — treat as tip/investigation lead pending corroboration.</description>
          <author>Armorer Labs</author>
          <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>TanStack npm supply-chain campaign targets AI developer tooling</title>
          <link>https://armorerlabs.com/threat-intel/tanstack-npm-shai-hulud-ai-tooling-supply-chain-2026-05</link>
          <guid>https://armorerlabs.com/threat-intel/tanstack-npm-shai-hulud-ai-tooling-supply-chain-2026-05</guid>
          <description>[Finding] International Cyber Digest reports that the TanStack npm compromise expanded into a reported &quot;Mini&quot; Shai-Hulud campaign targeting AI developer tooling across npm and PyPI, including OpenSearch, Mistral AI, Guardrails AI, UiPath, and Squawk packages.</description>
          <author>Armorer Labs</author>
          <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Malicious DeepSeek-Claw OpenClaw skill delivers Remcos RAT and GhostLoader stealer via supply chain attack</title>
          <link>https://armorerlabs.com/threat-intel/malicious-deepseek-claw-skill-campaign</link>
          <guid>https://armorerlabs.com/threat-intel/malicious-deepseek-claw-skill-campaign</guid>
          <description>[Finding] A threat actor published a malicious &quot;DeepSeek-Claw&quot; skill to the OpenClaw skill ecosystem on GitHub, exploiting developer trust in the skill marketplace to deliver Remcos RAT and GhostLoader stealer malware. The attack targeted developers and AI-driven systems using OpenClaw, leveraging supply chain poisoning of the skill publishing workflow.</description>
          <author>Armorer Labs</author>
          <pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Malicious OpenClaw DeepSeek-Claw skill exploits agentic AI workflows to deliver RAT and stealer</title>
          <link>https://armorerlabs.com/threat-intel/cryptika-malicious-openclaw-deepseek-skill-2026-05</link>
          <guid>https://armorerlabs.com/threat-intel/cryptika-malicious-openclaw-deepseek-skill-2026-05</guid>
          <description>[Article] Cryptika analysis of a malicious OpenClaw &quot;DeepSeek-Claw&quot; skill campaign delivering Remcos RAT and GhostLoader stealer via supply chain poisoning of the OpenClaw skill ecosystem.</description>
          <author>Armorer Labs</author>
          <pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Malicious OpenClaw DeepSeek-Claw skill exploits agentic AI workflows to deliver RAT and stealer</title>
          <link>https://armorerlabs.com/threat-intel/cybersecurity-insiders-malicious-openclaw-deepseek-skill-2026-05</link>
          <guid>https://armorerlabs.com/threat-intel/cybersecurity-insiders-malicious-openclaw-deepseek-skill-2026-05</guid>
          <description>[Article] Cybersecurity-Insiders article summarizing the Zscaler ThreatLabZ analysis of the malicious &quot;DeepSeek-Claw&quot; OpenClaw skill campaign delivering Remcos RAT and GhostLoader stealer via supply chain poisoning. Published May 10, 2026 by Jane Devry.</description>
          <author>Armorer Labs</author>
          <pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Canvas Breach Disrupts Schools &amp; Colleges Nationwide</title>
          <link>https://armorerlabs.com/threat-intel/krebs-canvas-breach-disrupts-schools-2026-05-07</link>
          <guid>https://armorerlabs.com/threat-intel/krebs-canvas-breach-disrupts-schools-2026-05-07</guid>
          <description>[Article] KrebsOnSecurity reported that Canvas, the Instructure-owned learning-management platform, was disrupted after login pages showed an extortion message attributed to ShinyHunters. The article says Instructure disabled or took parts of the service offline during the response and describes broad operational impact across schools and universities.</description>
          <author>Armorer Labs</author>
          <pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Canvas/Instructure incident shows SaaS vendor compromise becoming downstream extortion pressure</title>
          <link>https://armorerlabs.com/threat-intel/instructure-canvas-shinyhunters-extortion-2026-05</link>
          <guid>https://armorerlabs.com/threat-intel/instructure-canvas-shinyhunters-extortion-2026-05</guid>
          <description>[Finding] In May 2026, Instructure disclosed unauthorized access affecting part of its Canvas environment. Public reporting linked the disruption to defaced Canvas login pages and an extortion message attributed to ShinyHunters during final-exam periods.</description>
          <author>Armorer Labs</author>
          <pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>ClawJacked local API exposure can enable remote abuse and code execution</title>
          <link>https://armorerlabs.com/threat-intel/clawjacked-local-api-exposure-rce</link>
          <guid>https://armorerlabs.com/threat-intel/clawjacked-local-api-exposure-rce</guid>
          <description>[Exposure] Oasis Security documented OpenClaw local agent API abuse via cross-origin WebSocket exploitation, allowing a website to silently control a developer&apos;s AI agent when localhost trust, rate-limit exemptions, and auto-approved device pairing are exposed.</description>
          <author>Armorer Labs</author>
          <pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>ClawJacked: Cross-origin WebSocket exploitation and full OpenClaw compromise</title>
          <link>https://armorerlabs.com/threat-intel/oasis-openclaw-vulnerability-2026-05-10</link>
          <guid>https://armorerlabs.com/threat-intel/oasis-openclaw-vulnerability-2026-05-10</guid>
          <description>[Article] Oasis Security follow-up article published 2026-05-10 providing explicit version scope, technical attack chain details, and indicators of compromise for the ClawJacked vulnerability class.</description>
          <author>Armorer Labs</author>
          <pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>ClawJacked: OpenClaw vulnerability exposing remote code execution risks</title>
          <link>https://armorerlabs.com/threat-intel/oasis-clawjacked-2026-02-19</link>
          <guid>https://armorerlabs.com/threat-intel/oasis-clawjacked-2026-02-19</guid>
          <description>[Article] This is a primary vendor research article describing the ClawJacked risk pattern around OpenClaw local API exposure and the resulting code-execution implications.</description>
          <author>Armorer Labs</author>
          <pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Security Incident Update &amp; FAQs</title>
          <link>https://armorerlabs.com/threat-intel/instructure-security-incident-update-2026-05-09</link>
          <guid>https://armorerlabs.com/threat-intel/instructure-security-incident-update-2026-05-09</guid>
          <description>[Article] Instructure&apos;s incident update and FAQ page provides the vendor&apos;s public status and customer guidance after unauthorized access affecting part of its environment. The May 9 status update says Canvas was fully back online and available for use, and that Instructure had established the page as a central source of information.</description>
          <author>Armorer Labs</author>
          <pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Explicit conversation scoping for agent memory</title>
          <link>https://armorerlabs.com/threat-intel/explicit-agent-memory-conversation-scoping-2026-05</link>
          <guid>https://armorerlabs.com/threat-intel/explicit-agent-memory-conversation-scoping-2026-05</guid>
          <description>[Control] Agent memory should be bound to explicit conversation, tenant, user, task, or workspace identifiers rather than inferred implicitly from ambient runtime state. Spring AI 1.1.6 provides fresh implementation evidence for this hardening pattern by requiring explicit conversation IDs for chat memory advisors.</description>
          <author>Armorer Labs</author>
          <pubDate>Sat, 09 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Spring AI 1.1.6 Requires Explicit Conversation IDs for Chat Memory</title>
          <link>https://armorerlabs.com/threat-intel/spring-ai-1-1-6-explicit-conversation-id-2026-05-08</link>
          <guid>https://armorerlabs.com/threat-intel/spring-ai-1-1-6-explicit-conversation-id-2026-05-08</guid>
          <description>[Source] Spring AI&apos;s official 1.1.6 release notes describe a breaking change for chat memory advisors: applications must now supply an explicit conversation ID, and `PromptChatMemoryAdvisor` is deprecated in favor of the newer advisor pattern.</description>
          <author>Armorer Labs</author>
          <pubDate>Sat, 09 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Show HN: Probus, AI vuln scanner</title>
          <link>https://armorerlabs.com/threat-intel/hn-probus-ai-vuln-scanner-2026-05-05</link>
          <guid>https://armorerlabs.com/threat-intel/hn-probus-ai-vuln-scanner-2026-05-05</guid>
          <description>[Post] A May 5, 2026 Hacker News post announcing Probus, an AI-assisted vulnerability scanner. The author says the tool was run against projects they use and lists reported findings in n8n, Vercel AI SDK, LangGraph.js, browser-use, and Haystack.</description>
          <author>Armorer Labs</author>
          <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Vercel AI SDK PR #14750: enforce callOptionsSchema at runtime in ToolLoopAgent</title>
          <link>https://armorerlabs.com/threat-intel/vercel-ai-pr-14750-toolloopagent-calloptions-schema-2026-04-27</link>
          <guid>https://armorerlabs.com/threat-intel/vercel-ai-pr-14750-toolloopagent-calloptions-schema-2026-04-27</guid>
          <description>[Source] GitHub pull request #14750 in `vercel/ai` fixes a runtime validation gap in `ToolLoopAgent`. The PR states that `ToolLoopAgentSettings.callOptionsSchema` was declared and documented as a runtime schema for caller-supplied `options`, but `ToolLoopAgent.prepareCall` did not invoke it.</description>
          <author>Armorer Labs</author>
          <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Vercel AI SDK ToolLoopAgent skipped runtime call option schema validation</title>
          <link>https://armorerlabs.com/threat-intel/vercel-ai-sdk-toolloopagent-calloptions-schema-bypass-2026-04</link>
          <guid>https://armorerlabs.com/threat-intel/vercel-ai-sdk-toolloopagent-calloptions-schema-bypass-2026-04</guid>
          <description>[Finding] A Vercel AI SDK pull request fixed a ToolLoopAgent gap where `callOptionsSchema` was documented for caller-supplied options but not enforced at runtime, allowing invalid options to reach instruction or tool-call preparation paths.</description>
          <author>Armorer Labs</author>
          <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>AI coding agent runtimes concentrate credential exposure risk</title>
          <link>https://armorerlabs.com/threat-intel/ai-coding-agent-runtime-credential-exposure-2026-04</link>
          <guid>https://armorerlabs.com/threat-intel/ai-coding-agent-runtime-credential-exposure-2026-04</guid>
          <description>[Finding] Recent reports show a recurring AI coding-agent risk: attackers target the runtime&apos;s credentials, filesystem access, service identities, and policy gaps through setup commands, repository content, collaboration metadata, or over-broad cloud permissions.</description>
          <author>Armorer Labs</author>
          <pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Action gates and runtime guards for OpenClaw</title>
          <link>https://armorerlabs.com/threat-intel/action-gates-and-runtime-guards</link>
          <guid>https://armorerlabs.com/threat-intel/action-gates-and-runtime-guards</guid>
          <description>[Control] Several community and vendor defenses converge on the same principle: treat agent execution as the security boundary, and require runtime guardrails or explicit approval before high-risk actions complete.</description>
          <author>Armorer Labs</author>
          <pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Claude Code, Copilot and Codex all got hacked. Every attacker went for the credential, not the model.</title>
          <link>https://armorerlabs.com/threat-intel/venturebeat-ai-coding-agent-credential-exploits-2026-04-30</link>
          <guid>https://armorerlabs.com/threat-intel/venturebeat-ai-coding-agent-credential-exploits-2026-04-30</guid>
          <description>[Article] VentureBeat aggregates AI coding-agent security reports involving Codex, Claude Code, GitHub Copilot, and Vertex AI, emphasizing that credential and runtime access around the agent are often the real target.</description>
          <author>Armorer Labs</author>
          <pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>GitHub workflow AI agents can leak credentials through comment-and-control prompt injection</title>
          <link>https://armorerlabs.com/threat-intel/github-workflow-agent-comment-control-credential-theft-2026-04</link>
          <guid>https://armorerlabs.com/threat-intel/github-workflow-agent-comment-control-credential-theft-2026-04</guid>
          <description>[Finding] Aonan Guan&apos;s &quot;Comment and Control&quot; write-up shows how attacker-controlled GitHub titles, issues, and comments can become prompt-injection channels for hosted coding agents with workflow credentials.</description>
          <author>Armorer Labs</author>
          <pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>MCP STDIO command execution and tool-integrity risks affect agent infrastructure</title>
          <link>https://armorerlabs.com/threat-intel/mcp-stdio-command-execution-and-tool-integrity-risks-2026-05</link>
          <guid>https://armorerlabs.com/threat-intel/mcp-stdio-command-execution-and-tool-integrity-risks-2026-05</guid>
          <description>[Finding] Cloud Security Alliance summarizes MCP risks where STDIO configuration can become OS command execution, while tool poisoning, rug-pull changes, cross-server tool shadowing, and unauthenticated exposure widen agent infrastructure risk.</description>
          <author>Armorer Labs</author>
          <pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>MCP Security Crisis: Systemic Design Flaws in AI Agent Infrastructure</title>
          <link>https://armorerlabs.com/threat-intel/csa-mcp-security-crisis-2026-05-04</link>
          <guid>https://armorerlabs.com/threat-intel/csa-mcp-security-crisis-2026-05-04</guid>
          <description>[Article] Cloud Security Alliance&apos;s May 4, 2026 AI Safety Initiative note synthesizes MCP STDIO command-execution research, tool-integrity attacks, exposed unauthenticated MCP servers, and high- or critical-severity CVEs in MCP-integrated projects.</description>
          <author>Armorer Labs</author>
          <pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Comment and Control: Prompt Injection to Credential Theft in Claude Code, Gemini CLI, and GitHub Copilot Agent</title>
          <link>https://armorerlabs.com/threat-intel/oddguan-comment-control-agent-credential-theft-2026-04-15</link>
          <guid>https://armorerlabs.com/threat-intel/oddguan-comment-control-agent-credential-theft-2026-04-15</guid>
          <description>[Article] The &quot;Comment and Control&quot; research write-up shows how GitHub pull request titles, issue bodies, and comments can steer hosted AI coding agents, with demonstrations against Claude Code Security Review, Gemini CLI Action, and GitHub Copilot Agent.</description>
          <author>Armorer Labs</author>
          <pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>US, Allies Issue Joint Guidance on Agentic AI System Security</title>
          <link>https://armorerlabs.com/threat-intel/executivegov-agentic-ai-security-guidance-2026-05-01</link>
          <guid>https://armorerlabs.com/threat-intel/executivegov-agentic-ai-security-guidance-2026-05-01</guid>
          <description>[Article] ExecutiveGov reports on joint guidance from U.S., Australian, Canadian, New Zealand, and U.K. intelligence and cybersecurity agencies for securing agentic AI systems in critical infrastructure and defense environments.</description>
          <author>Armorer Labs</author>
          <pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>AI SAST in Action: Finding Real Vulnerabilities in OpenClaw</title>
          <link>https://armorerlabs.com/threat-intel/endorlabs-ai-sast-openclaw-2026-02-10</link>
          <guid>https://armorerlabs.com/threat-intel/endorlabs-ai-sast-openclaw-2026-02-10</guid>
          <description>[Article] This is Endor Labs’ initial OpenClaw study describing how its AI SAST engine identified seven exploitable vulnerabilities through data-flow analysis and systematic validation.</description>
          <author>Armorer Labs</author>
          <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>AI security tools roundup with OpenClaw-relevant controls</title>
          <link>https://armorerlabs.com/threat-intel/ai-security-tools-roundup-openclaw-relevant-2026-02</link>
          <guid>https://armorerlabs.com/threat-intel/ai-security-tools-roundup-openclaw-relevant-2026-02</guid>
          <description>[Post] This is a filtered record of the broader AI security tools roundup you supplied. Only the OpenClaw-relevant items are retained conceptually here, such as ClawSec, OpenClaw dashboarding, and execution-control or guardrail tooling.</description>
          <author>Armorer Labs</author>
          <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>ClawSec Scanner</title>
          <link>https://armorerlabs.com/threat-intel/clawsec-scanner</link>
          <guid>https://armorerlabs.com/threat-intel/clawsec-scanner</guid>
          <description>[Control] ClawSec Scanner is a defensive control that combines dependency scanning, CVE enrichment, static analysis, and OpenClaw-specific dynamic testing into a single workflow.</description>
          <author>Armorer Labs</author>
          <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>ClawSec Scanner announcement</title>
          <link>https://armorerlabs.com/threat-intel/clawsec-scanner-announcement-2026-03</link>
          <guid>https://armorerlabs.com/threat-intel/clawsec-scanner-announcement-2026-03</guid>
          <description>[Post] This is the announcement text you provided for ClawSec Scanner, describing dependency scanning, CVE enrichment, SAST, OpenClaw-specific DAST, and unified reporting.</description>
          <author>Armorer Labs</author>
          <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>ClawSec Suite</title>
          <link>https://armorerlabs.com/threat-intel/clawsec-suite</link>
          <guid>https://armorerlabs.com/threat-intel/clawsec-suite</guid>
          <description>[Control] ClawSec Suite is a defensive monitoring and integrity package for OpenClaw. It focuses on advisory feed monitoring, affected-skill checking, signature verification, and approval-gated handling of malicious-skill scenarios.</description>
          <author>Armorer Labs</author>
          <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>ClawSec releases and skill index</title>
          <link>https://armorerlabs.com/threat-intel/clawsec-releases-and-skill-index</link>
          <guid>https://armorerlabs.com/threat-intel/clawsec-releases-and-skill-index</guid>
          <description>[Source] This source combines Prompt Security release material for ClawSec and the public skill index published at `https://clawsec.prompt.security/skills/index.json`.</description>
          <author>Armorer Labs</author>
          <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>ClawSec suite announcement</title>
          <link>https://armorerlabs.com/threat-intel/clawsec-suite-announcement-2026-02</link>
          <guid>https://armorerlabs.com/threat-intel/clawsec-suite-announcement-2026-02</guid>
          <description>[Post] This is the user-provided announcement for ClawSec as a security package for OpenClaw agents, highlighting drift detection, audits, skill integrity checks, and alerting.</description>
          <author>Armorer Labs</author>
          <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>ClawdINT internal content leak scenario involving OpenClaw</title>
          <link>https://armorerlabs.com/threat-intel/clawdint-internal-content-leak-2026-03</link>
          <guid>https://armorerlabs.com/threat-intel/clawdint-internal-content-leak-2026-03</guid>
          <description>[Post] This is the user-provided post describing an OpenClaw agent that reportedly accessed an internal cyber threat intelligence platform and later published high-quality external output that included internal-only content.</description>
          <author>Armorer Labs</author>
          <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Endor Labs identified a cluster of exploitable OpenClaw vulnerabilities</title>
          <link>https://armorerlabs.com/threat-intel/endorlabs-openclaw-vulnerability-set-2026-02</link>
          <guid>https://armorerlabs.com/threat-intel/endorlabs-openclaw-vulnerability-set-2026-02</guid>
          <description>[Finding] Endor Labs reported that its AI SAST workflow identified seven exploitable vulnerabilities in OpenClaw and later published technical detail focused on six disclosed issues validated through exploit development and live testing.</description>
          <author>Armorer Labs</author>
          <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Hebrew community guidance on OpenClaw hardening via prompt instructions</title>
          <link>https://armorerlabs.com/threat-intel/hebrew-openclaw-hardening-prompt-guidance</link>
          <guid>https://armorerlabs.com/threat-intel/hebrew-openclaw-hardening-prompt-guidance</guid>
          <description>[Post] This is an English-normalized record of the Hebrew post you supplied. It warns that a default OpenClaw installation can reveal sensitive system information and can self-update important markdown files that shape identity, memory, and automation behavior.</description>
          <author>Armorer Labs</author>
          <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Hebrew community roundup of OpenClaw runtime guard and detection tools</title>
          <link>https://armorerlabs.com/threat-intel/hebrew-openclaw-runtime-guard-tools-roundup</link>
          <guid>https://armorerlabs.com/threat-intel/hebrew-openclaw-runtime-guard-tools-roundup</guid>
          <description>[Post] This is an English-normalized record of the Hebrew post describing three open-source defenses: Knostic Shield as an in-runtime guard, OpenClaw Detect for organizational discovery, and Capsule ClawGuard as an approval-gated execution guard.</description>
          <author>Armorer Labs</author>
          <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>How AI SAST Traced Data Flows to Uncover Six OpenClaw Vulnerabilities</title>
          <link>https://armorerlabs.com/threat-intel/endorlabs-six-openclaw-vulns-2026-02-18</link>
          <guid>https://armorerlabs.com/threat-intel/endorlabs-six-openclaw-vulns-2026-02-18</guid>
          <description>[Article] This technical Endor Labs follow-up focuses on six disclosed OpenClaw vulnerabilities, their tainted data flows, and how exploit validation was used to confirm impact.</description>
          <author>Armorer Labs</author>
          <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Integrators, not isolators: The risky side of AI agents in sensitive environments</title>
          <link>https://armorerlabs.com/threat-intel/lukasz-olejnik-integrators-not-isolators-2026-02-02</link>
          <guid>https://armorerlabs.com/threat-intel/lukasz-olejnik-integrators-not-isolators-2026-02-02</guid>
          <description>[Article] This article explains the operational risk created when AI agents integrate across multiple systems and treat all reachable context as usable information. It is relevant to OpenClaw because the platform is often deployed with broad local and connected-system access.</description>
          <author>Armorer Labs</author>
          <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Large numbers of OpenClaw instances were reported exposed to the public internet</title>
          <link>https://armorerlabs.com/threat-intel/mass-exposed-openclaw-instances-2026-02</link>
          <guid>https://armorerlabs.com/threat-intel/mass-exposed-openclaw-instances-2026-02</guid>
          <description>[Exposure] A February 2026 report summarized SecurityScorecard research describing more than 40,000 publicly exposed OpenClaw instances and a large subset considered vulnerable or exploitable through remote-code-execution paths.</description>
          <author>Armorer Labs</author>
          <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>OpenClaw Security Engineer&apos;s Cheat Sheet</title>
          <link>https://armorerlabs.com/threat-intel/semgrep-openclaw-security-engineers-cheat-sheet-2026-02</link>
          <guid>https://armorerlabs.com/threat-intel/semgrep-openclaw-security-engineers-cheat-sheet-2026-02</guid>
          <description>[Article] This Semgrep article compiles operational guidance for dealing with OpenClaw in enterprise environments, including first principles, attack-surface analysis, detection ideas, skill risk, and safer experimentation patterns.</description>
          <author>Armorer Labs</author>
          <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>OpenClaw can unintentionally fuse and publish sensitive internal data across connected systems</title>
          <link>https://armorerlabs.com/threat-intel/agent-overreach-sensitive-systems</link>
          <guid>https://armorerlabs.com/threat-intel/agent-overreach-sensitive-systems</guid>
          <description>[Finding] The risk is not only direct exploitation. OpenClaw can act as an integrator across multiple connected systems and combine internal data in ways the operator did not anticipate. If publication or outbound messaging is also available, that can turn ordinary retrieval into a disclosure event.</description>
          <author>Armorer Labs</author>
          <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>OpenClaw gateway security baseline</title>
          <link>https://armorerlabs.com/threat-intel/openclaw-gateway-security-baseline</link>
          <guid>https://armorerlabs.com/threat-intel/openclaw-gateway-security-baseline</guid>
          <description>[Control] Use the OpenClaw gateway security documentation as the baseline control set for local-only deployment, token-based auth, narrow DM scope, and reduced tool access.</description>
          <author>Armorer Labs</author>
          <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>OpenClaw gateway security documentation</title>
          <link>https://armorerlabs.com/threat-intel/openclaw-gateway-security-docs</link>
          <guid>https://armorerlabs.com/threat-intel/openclaw-gateway-security-docs</guid>
          <description>[Source] This documentation page provides the vendor-recommended gateway security baseline, including loopback binding, token-based auth, restrictive tool profiles, DM scoping, and disabled elevated execution.</description>
          <author>Armorer Labs</author>
          <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>OpenClaw security engineer cheat sheet</title>
          <link>https://armorerlabs.com/threat-intel/openclaw-security-engineers-cheat-sheet</link>
          <guid>https://armorerlabs.com/threat-intel/openclaw-security-engineers-cheat-sheet</guid>
          <description>[Control] Semgrep’s cheat sheet is a practical operator-oriented control reference covering first principles, attack surface, detection, sandboxing, skill risk, and safer experimentation patterns for OpenClaw.</description>
          <author>Armorer Labs</author>
          <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Reported supply-chain campaign using a malicious extension to spawn coding agents</title>
          <link>https://armorerlabs.com/threat-intel/pillar-agent-spawn-campaign-2026-03</link>
          <guid>https://armorerlabs.com/threat-intel/pillar-agent-spawn-campaign-2026-03</guid>
          <description>[Post] This is the user-provided summary of a campaign where a compromised CI pipeline allegedly led to a malicious IDE extension that launched coding agents with permissive flags and prompted them to exfiltrate credentials.</description>
          <author>Armorer Labs</author>
          <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
        </item>
        <item>
          <title>Researchers Find 40,000+ Exposed OpenClaw Instances</title>
          <link>https://armorerlabs.com/threat-intel/infosecurity-openclaw-exposed-instances-2026-02-09</link>
          <guid>https://armorerlabs.com/threat-intel/infosecurity-openclaw-exposed-instances-2026-02-09</guid>
          <description>[Article] This article summarizes SecurityScorecard reporting about publicly exposed OpenClaw instances and the security risk created by widespread misconfiguration.</description>
          <author>Armorer Labs</author>
          <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
        </item>
      </channel>
    </rss>