๐ต๏ธ RESEARCH & DEEP DIVES
-
OWASP Releases Top 10 Security Risks for AI Agent Skills
OWASP has released a security framework for risks affecting AI agent skills.- The framework covers OpenClaw, Claude Code, Cursor, Codex, and VS Code ecosystems.
- It identifies malicious skills, supply-chain compromise, excessive privileges, insecure metadata, weak isolation, and cross-platform reuse as key risks.
- Skills are reusable instruction-and-resource bundles that agents can discover, load, and execute with host-agent permissions.
- A January 2026 ClawHavoc campaign distributed 1,184 malicious skills through 12 publisher accounts linked to one command-and-control address.
๐ Source: owasp.org ยท ๐ Coverage: resilientcyber.io ยท ๐ via Dark Reading
-
google-calendar-url-signing-phishing โ r/cybersecurity
๐ CVEs & KEV
-
CVE-2026-77234 โ CVSS 9.3 โ Improper input validation in FreeRTOS-Kernel timer command handlingImproper i...
-
CVE-2026-62674 โ CVSS 9.0 โ Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCEOmni...
-
CVE-2026-62675 โ CVSS 8.8 โ Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Ca...
-
CVE-2026-62677 โ CVSS 8.8 โ Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesy...
-
CVE-2026-41451 โ CVSS 8.5 โ UAC before 3.3.0 Command Injection via User Substitution in parse_artifact.shUAC (...
-
CVE-2026-41450 โ CVSS 8.5 โ UAC before 3.3.0 Command Injection via command_collector.shUAC (Unix-like Artifact...
-
CVE-2026-41449 โ CVSS 8.5 โ UAC before 3.3.0 Command Injection via run_command.shUAC (Unix-like Artifacts Coll...
-
CVE-2026-77236 โ CVSS 8.3 โ Missing size validation in SecureContext_AllocateContext in FreeRTOS-KernelMi...
-
CVE-2026-77235 โ CVSS 8.3 โ Missing privilege check in SecureContext_FreeContext in FreeRTOS-KernelMissin...
-
CVE-2026-77237 โ CVSS 8.2 โ Missing type validation in xQueueAddToSet in FreeRTOS-KernelMissing queue-set...
-
CVE-2026-71862 โ CVSS 7.5 โ Checkmate: Sensitive Bearer Token Exposure via Public Status Pages When showU...
-
CVE-2026-55241 โ CVSS 7.5 โ Checkmate: Pre-auth Denial of Service via File Upload on RegistrationCheckmat...
-
CVE-2026-62676 โ CVSS 7.1 โ Omnigent Guardrail policy bypass: shell-command parser fails open in policies...
-
CVE-2026-17252 โ CVSS 7.1 โ Unauthenticated Denial of Service via Composed HTTP Parsing and Stack-Based O...