Safety: Security incidents
Articles on security incidents.
Can an AI Agent Plugin Hide Instructions You Can't See?
In 2026 a campaign called ClawHavoc hid malicious instructions inside AI-agent plugins using invisible text. How it worked, and 3 questions to ask first.
When Is It Safe to Give an AI Agent Access to Your Computer?
A three-question framework for judging AI agent safety, using OpenClaw's 2026 security incidents as the real-world example of what happens when it fails.
Did an AI Agent Really Run a Ransomware Attack by Itself?
JadePuffer: researchers documented an AI agent running a full ransomware intrusion. Here's what it actually did, what still needed a human, and what it means.
Why OpenClaw's AI Agents Keep Getting Hacked (It's Not the Bugs — It's the Door)
OpenClaw shipped 40+ fixes in 2026, yet thousands of instances stay exposed — the cause is an unauthenticated network port left open by design, not a patchable bug.