Fetching from the wire…
Security2026-08-09 · source-backed
Oasis Security disclosed a chain in Paperclip, an AI management platform for running autonomous agents at scale, affecting network-accessible instances in default authenticated mode (SecurityWeek). No invitation, no verified mailbox: register, sign in, create and self-approve a CLI authorization challenge to mint a board API token, then hit the company-import route (which enforced only board-level access, while direct company creation required instance admin) with a crafted .paperclip.yaml defining an agent using a host-level execution adapter. Oasis also found a DNS-rebinding weakness where local-dev mode trusts everything reaching 127.0.0.1, letting an attacker-controlled webpage run commands on a developer's machine.
Each link below shares sources, entities, or timing with this story.
Cyera signed an LOI to acquire Oasis Security for roughly $1 billion, about $700M in cash (SecurityWeek). Act Security came out of stealth with $60M total, a $20M seed from Team8 and Bessemer plus a $40M Series A led by Notable Capital (SecurityWeek). Hush Security closed a $3...
Oasis found that Claude Desktop's registration of the claude:// URL scheme caused the app to open, import a prompt from the URL, and immediately submit it with no display of the full prompt and no approval step. Visible text looked benign while hidden instructions in the same...
Adversa AI's March 2026 roundup documented 8 confirmed security incidents across OpenClaw and ServiceNow deployments, with aggregate scanning finding 43% of MCP servers vulnerable to command execution. A new vulnerability class is emerging around persistent memory and SOUL.md...
Published March 21: authenticated callers with operator.write scope can invoke owner-only gateway and cron controls in OpenClaw prior to 2026.3.1. CI/CD jobs with broad operator.write tokens are most exposed. Upgrade immediately. Source
CVE-2026-19889 and CVE-2026-75871, published August 27, let an authenticated user with Duo access redirect outbound model requests externally, affecting AI Gateway 18.9.0/18.10 through 19.0.12, 19.1 to 19.1.7 and 19.2 to 19.2.2 (NVD). Redirecting the model endpoint sends every...
Security researcher Yarden Porat of Cyata disclosed four critical vulnerabilities in CrewAI, one of the most widely used agent frameworks. These aren't theoretical. They chain together, and the entry point is prompt injection. The chain works like this: CVE-2026-2275 exploits...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.