Vulnerabilities, attack patterns, and defensive strategies for AI and OpenClaw systems.
OpenAI has started rolling out Lockdown Mode to eligible personal ChatGPT accounts and self-serve ChatGPT Business accounts. The feature is meant to limit outbound network requests and reduce the risk of data exfiltration after prompt injection attacks.
Source: Simon WillisonMicrosoft Threat Intelligence said Anthropic’s Claude Code GitHub Action could expose CI/CD secrets when it processes untrusted GitHub content. Anthropic fixed the issue in Claude Code 2.1.128 by blocking access to sensitive /proc files, according to Microsoft.
Source: Microsoft Security BlogBruce Schneier says researchers have prototyped an AI-powered internet worm. The prototype carries its own LLM, or large language model, and runs it on machines after they are compromised.
Source: Schneier on SecurityOpenAI has launched Active sessions, a new ChatGPT security feature that lets users and admins view and log out of browser and app sessions across ChatGPT, Codex, and API Platform. Security experts say the change improves visibility, but rapid model updates still make AI governance difficult for enterprises.
Source: CIO AIMicrosoft used Build 2026 to announce new security features across code, agents, and models. The company said the updates are meant to give developers real-time guidance and give security teams more visibility across the development lifecycle.
Source: Microsoft Security BlogWorkday announced new developer tools at DevCon 2026, including Developer Agent, Agent-Ready Tools and Agent Passport. The company says the features let developers build agents faster while adding third-party verification for security and compliance before production.
Source: SiliconANGLEMicrosoft has shipped new Entra features over the past 30 days, including phishing-resistant MFA on Linux, passkey registration campaigns, and changes to Conditional Access and self-service password reset. The company also added governance, app deactivation, and SOC response tools, with more enforcement dates set for 2026.
Source: Help Net SecurityAnthropic said it is expanding Project Glasswing, its effort to use Claude Mythos Preview to find software vulnerabilities, to about 150 additional organizations. The company said the first 50 partners found more than 10,000 high- or critical-severity flaws, and the new group includes infrastructure and open-source maintainers in more than 15 countries.
Source: Anthropic NewsAnthropic will give the EU cybersecurity agency ENISA access to Claude Mythos through Project Glasswing, ending weeks of stalled talks. The model has found more than 10,000 high- and critical-severity zero-day vulnerabilities, and ENISA becomes the first EU institution to join the controlled-access program.
Source: The Next WebJapan’s three megabanks will get access to OpenAI’s GPT-5.5-Cyber through the company’s Trusted Access for Cyber programme, according to Finance Minister Satsuki Katayama. The rollout comes amid a broader Japanese effort to treat frontier AI as both a cyber threat and a defensive tool.
Source: The Next WebHermes Agent v0.15.0 shipped on May 28, 2026 with major performance, architecture, and security changes. The release cuts run_agent.py by 76%, speeds up startup and session search, and adds new defenses against prompt-injection attacks, according to the project.
Source: Hermes Agent ReleasesAnthropic has added two security features to Claude: a self-hosted sandbox for Managed Agents and a security-guidance plugin that reviews code for common flaws during work. The company said the plugin runs automatically, while Red Hat described the sandbox as keeping execution on customer infrastructure.
Source: The Hacker NewsOpenClaw 2026.5.27 adds stronger security boundaries, blocks unsafe command and runtime settings, and improves delivery behavior across channels such as Slack, Telegram, iMessage, and Discord. The release also expands provider support, including OpenAI-compatible embeddings and Pixverse video generation, while hardening packaging, CI, and release verification.
Source: OpenClaw ReleasesGoogle Cloud introduced AI Threat Defense, an automated security platform that finds, prioritizes, and helps patch software flaws using its Gemini models, Wiz, CodeMender, and Mandiant. The company says the system is built for a threat environment where attackers use AI to find and exploit weaknesses in hours or days.
Source: Help Net SecurityAnthropic has added a security-guidance plugin to Claude Code that reviews code for common vulnerabilities while developers work. The company says it can catch issues before pull requests, and that internal use reduced security-related PR comments by 30% to 40%.
Source: Help Net SecurityOpenClaw’s 2026.5.26 update adds a faster Gateway path, broader transcript handling, and stronger content-boundary checks. The release also improves Telegram, iMessage, WhatsApp, Discord, Signal, voice features, installs, and diagnostics.
Source: OpenClaw ReleasesMicrosoft is adding security and governance features for AI agents as enterprises deploy more AI tools and connectors. PwC says the goal is to help companies move quickly without accumulating new security risks, or “AI security debt.”
Source: CIO AI7AI has launched PLAID ELITE, a fully managed AI-native security operations service that uses autonomous agents with oversight from 7AI engineers. The company says it can handle alert triage, investigation and response continuously, while reducing false positives and speeding investigations from hours to minutes.
Source: SiliconANGLEAnthropic says its Project Glasswing program has helped uncover more than 10,000 high- or critical-severity vulnerabilities since launching last month. The company said a subset of partners using Claude Mythos Preview also helped patch findings and issue advisories, while urging faster patching and stronger defenses.
Source: The Hacker NewsMicrosoft Security highlighted customer stories from St. Luke’s University Health Network and ManpowerGroup, saying both organizations are building security foundations for AI. The examples focus on unified visibility, governance, and automation across cloud, identity, data, and operations.
Source: Microsoft Security BlogMicrosoft announced updates to Purview, Entra ID, and Windows 365 for Agents aimed at improving visibility and control across AI tools, data, and identities. The changes include a Claude connector for Purview, a new DSPM experience, OCR and custom examinations in investigations, and a secure execution environment for agents.
Source: Microsoft Security BlogAnthropic said Claude now connects with 28 security and compliance tools through its Compliance API. The integrations give IT and security teams access to conversation content and activity events so they can apply existing monitoring, DLP, and governance policies to Claude.
Source: Claude BlogMicrosoft has open-sourced two tools for AI agent development: RAMPART, a testing framework for continuous safety checks, and Clarity, a structured app for reviewing design assumptions before coding starts. The company says both tools are meant to make AI safety part of the normal engineering workflow.
Source: Microsoft Security Blog1Password has released an MCP server for OpenAI’s Codex coding agent that lets secrets be accessed at runtime without exposing them in prompts, code or model context. The company said the integration uses just-in-time credentials and is part of its broader push to secure agentic development.
Source: SiliconANGLEElementalSoul has released claude-bughunter, a self-contained skill bundle for Claude Code aimed at bug hunting and external red-team work. The package includes 51 skills, 15 slash commands, and more than 574 disclosed-report patterns across 24 vulnerability classes.
Source: HN Show HNAnthropic has revised its disclosure policy for Mythos, its unreleased cybersecurity-focused AI model in Project Glasswing. Partners can now share vulnerability findings with other security teams, regulators, open-source maintainers, the media and the public, subject to responsible-disclosure rules.
Source: The Next WebDify v1.14.2 is a patch release that tightens tenant isolation, restricts tool credential changes, and fixes several workflow, tracing, and knowledge-base issues. The update also changes Docker environment file layout and requires a database migration for configurable Explore app categories.
Source: Dify ReleasesMicrosoft Threat Intelligence says the group Storm-2949 used social engineering and abused password reset flows to take over Microsoft Entra ID accounts, then exfiltrated data from Microsoft 365 and Azure resources. The attack spread across App Service, Key Vault, Storage, SQL, and virtual machines, according to Microsoft.
Source: Microsoft Security BlogForcepoint says the TeamPCP threat group used a supply chain attack to turn two LiteLLM PyPI releases into credential-stealing malware. The malicious code targeted cloud and AI credentials, including keys for OpenAI, Anthropic, Microsoft Azure, AWS and Google Cloud.
Source: SiliconANGLECyera says four chainable OpenClaw vulnerabilities, dubbed Claw Chain, could let attackers steal data, escalate privileges, and plant backdoors. OpenClaw says the issues affect its OpenShell sandbox backend and MCP loopback runtime and were fixed in version 2026.4.22.
Source: The Next WebKnowBe4 said it is extending its agent risk management tools to cover both human workers and AI agents. Vice president of AI and data Matt Duren said the company is adding visibility, explainability and tailored training as enterprises deploy more non-human digital workers.
Source: SiliconANGLEAnthropic is changing Claude subscription pricing so programmatic use will be billed with dedicated monthly credits at API rates, while interactive use through its own tools remains subsidized. The change follows a months-long rollout of blocks on third-party tools such as OpenCode and OpenClaw.
Source: Kilo BlogCyera says four OpenClaw vulnerabilities, nicknamed Claw Chain, can be chained to steal data, escalate privileges, and maintain persistence. OpenClaw says the issues were fixed in version 2026.4.22 and credits researcher Vladimir Tokarev for reporting them.
Source: The Hacker NewsOpenAI said two employee devices were affected by the Mini Shai-Hulud supply chain attack on TanStack, but no user data, production systems, or intellectual property were compromised. The company revoked certificates, rotated credentials, and told macOS users of several apps to update after signing keys tied to those products were exposed.
Source: The Hacker NewsTeamPCP says it is selling nearly 450 repositories tied to Mistral AI for $25,000, and claims it will leak the data if no buyer appears within a week. Mistral AI said the incident came after a supply-chain attack hit a developer device, but said its hosted services and core repositories were not compromised.
Source: BleepingComputerOpenAI said two employees’ devices were breached in the TanStack supply chain attack that hit hundreds of npm and PyPI packages. The company said customer data, production systems, and deployed software were not affected, but it rotated code-signing certificates and is requiring some macOS users to update before June 12, 2026.
Source: BleepingComputerMicrosoft says autonomous AI agents need defense in depth because they can take actions, change data, and trigger workflows across systems. The company argues that the application layer - permissions, workflows, identity, and escalation controls - matters most for keeping agents safe in production.
Source: Microsoft Security BlogJupiterOne has launched two new products, AI Attack Surface Management and Unified Vulnerability Management, to help security teams track AI sprawl and prioritize vulnerabilities. The company says the tools map assets, identities and AI agents together so teams can see what matters to business risk.
Source: SiliconANGLEVaultBix is a Chrome extension that warns or blocks users when they paste secrets, personal data, or proprietary code into AI tools. The company says detection runs locally in the browser, with no account required and no data sent to a server.
Source: HN Show HNMicrosoft said its new multi-model agentic security system, codename MDASH, helped identify 16 vulnerabilities in Windows networking and authentication components, including four critical remote code execution bugs. The company said the system also scored 88.45% on the public CyberGym benchmark and found all 21 planted bugs in a private test driver with zero false positives.
Source: Microsoft Security BlogAWS has launched a preview of full repository code review in AWS Security Agent. The feature scans an entire codebase, builds a security model of the application, and produces findings with evidence, severity, and remediation guidance.
Source: AWS Security BlogOpenAI has launched Daybreak, a cybersecurity platform built to find vulnerabilities, generate patches, and validate fixes in enterprise codebases. The system uses three GPT-5.5 variants and launches with partners including Cisco, CrowdStrike, and Palo Alto Networks.
Source: The Next Webcurl maintainer Daniel Stenberg said Anthropic’s Mythos scan found one confirmed vulnerability and about 20 bugs in curl, after the project reviewed the report. He said the issue will be released as a low-severity CVE with curl 8.21.0 in late June.
Source: r/ClaudeAIGeopolitical tension, supply chain disruption, and changing regulations are forcing CIOs to rethink global IT strategy. Forrester and several IT leaders say the pressure is also affecting AI spending, compliance, and infrastructure planning across regions.
Source: CIO AIGoogle Chrome has been quietly installing Gemini Nano, a 4GB on-device AI model, on some users’ computers without asking first, according to Swedish computer scientist and lawyer Alexander Hanff. Google says users can disable and remove the model in Chrome settings, and it will stop downloading or updating once turned off.
Source: r/ControlProblemIntruder, a London cybersecurity startup backed by GCHQ’s Cyber Accelerator, has launched AI pentesting agents that mimic human methodology and return results in minutes. The company says the tools can help midmarket firms test faster and at lower cost than manual penetration tests, which can run $10,000 to $50,000.
Source: The Next WebAnthropic says it reduced agentic misalignment in Claude models by changing safety training, including teaching the model to explain why actions are better and using more diverse data. The company says newer Claude models now score zero on its blackmail evaluation, though it says alignment remains an unsolved problem.
Source: r/ControlProblemGoogle Chrome is silently downloading a 4 GB on-device AI model, according to a report that traced the file on macOS and Windows. The model, used for Gemini Nano features, can re-download itself after deletion and appears without a consent prompt.
Source: r/LocalLLaMAA SANS guest diary describes a system that summarizes DShield web honeypot logs and uses Claude to generate a React dashboard tailored to each day’s attack patterns. The design keeps raw malicious strings away from the model and renders the generated UI inside a sandboxed iframe with fallback validation.
Source: SANS ISCThe White House is discussing an executive order that would require government review of new AI models before release, according to The New York Times. The shift follows concern over Anthropic’s Mythos model, which the company withheld from public release over cybersecurity risks.
Source: r/OpenAI