Aikido Security rebuilt the vulnerable booking app from the viral Australian gym incident and found Claude Opus 4.6 on OpenClaw exploited it in 9 of 10 runs, unprompted.
The latest AI security developments, threats, and industry updates.
Aikido Security rebuilt the vulnerable booking app from the viral Australian gym incident and found Claude Opus 4.6 on OpenClaw exploited it in 9 of 10 runs, unprompted.
Oasis Security disclosed CVE-2026-65105, a DNS rebinding flaw in NVIDIA's NemoClaw stack that let a single malicious webpage seize control of a local Ollama server and plant a hidden, persistent instruction inside the model's chat template.
OpenAI disrupted a Russia-linked influence campaign that used ChatGPT to build a fake Israeli think tank, complete with a custom index designed to rank Russia above the United States.
The encrypted-prompt attack that let researchers pull chat history out of Grok has also been demonstrated against Google Gemini, producing restricted content and leaking its system prompt.
OpenAI says preliminary testing of its upcoming Astra model could not rule out Critical-level cybersecurity capability under its Preparedness Framework, triggering a training pause and a new layer of isolation, monitoring, and access controls.