Fetching from the wire…
Top 5 · 2026-02-24 · source-backed
Microsoft Security Blog published official guidance: OpenClaw should run ONLY in fully isolated VMs or separate physical systems with dedicated, non-privileged credentials. Two supply chains (untrusted skills/extensions + untrusted external text) converge into a single execution loop, and persistent agent "memory" can be modified to follow attacker instructions permanently. This is the most authoritative security guidance from a major vendor on autonomous coding agents. Action: If you run OpenClaw, isolate it TODAY. This is Microsoft saying "not on your workstation."
Each link below shares sources, entities, or timing with this story.
The agent skills supply chain is under coordinated attack. Snyk's ToxicSkills audit found 36% of ClawHub's 3,984 skills contain prompt injection payloads, 13.4% have critical malware, and submission rates exploded 10x to 500+/day. This week alone: CVE-2026-2256 (CVSS 9.1) is a...
Microsoft published the first vendor-specific OWASP-style top-10 for enterprise AI agent platforms, complete with Microsoft Defender detection queries. This is both a marketing play and a genuinely useful resource. The top risks include: prompt injection through tool responses...
The July 23 post says Dynamics exposes over 650,000 MCP actions spanning sales, finance, supply chain, HR, field service, customer service, and project operations, so agents operate inside the transaction layer using the same data models, rules, permissions, and audit trails a...
Microsoft and GitHub disabled the repos, many of them Azure and AI developer tools, after attackers injected malware that harvests credentials the moment a repo is opened in Claude Code, Gemini CLI, or VS Code. Miasma is built on the open-sourced Mini Shai-Hulud codebase from...
19. Microsoft Security Blog — OpenClaw 20. ClawSec GitHub 21. SecureClaw GitHub 22. CVE-2026-27001 Advisory 23. UC Berkeley CLTC Report 24. SoundHound MWC Launch 25. SentinelOne ClawSec Blog
Announced July 27, live today: Red agents probe like attackers, Blue investigate like responders, Green remediate and harden, humans keep review and final decisions. It runs on MAI-Cyber-1-Flash, Microsoft's first purpose-built security model, carrying ~90% of the workload ins...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.