SourcesOpenClaw Security Crisis 341 Malicious Skills CVE-2026-25253The Hacker News·high signalXBlueskyLinkedInCopy linkCVE-2026-25253 CVSS 8.8 one-click RCE. 42665 exposed instances. 341 of 2857 ClawHub skills malicious (12%). 335 traced to coordinated ClawHavoc operation.SourceSource pageThe Hacker News↳ Follow the threadStack layer / Threat patternPlugin4Shell: One SHA-Pinning Bug Gives Zero-Click RCE in Claude Code, Codex, Copilot and Gemini CLIHelp Net Security (corroborated by The Register)Stack layer / Threat patternAn AI agent found the libheif RCE behind Next.js image optimization, and Vercel published the full disclosure timelineVercel BlogPolicy dependency / Stack layerLangChain ships a first-party integration that deliberately does not wrap the vendor's SDKGitHubStack layer / Threat patternThree LMDeploy advisories land at once, topped by a 9.8 unauthenticated pickle RCE in the DistServe control planeGitHub Advisory DatabasePolicy dependency / Threat patternRust's crates security team warns of an active campaign social-engineering maintainers over fake video callsSimon Willison's Blog (Rust Blog)Stack layer / Threat patternA Fake Security-Product Story in an Unexecuted Binary Section Flipped 30 of 35 Malware VerdictsarXiv 2609.19722Policy dependency / Stack layerAgents hallucinate tools that do not exist, a 675B model does it as often as a 7B one, and merging MCP servers adds new failure surfacesarXiv 2609.19425Policy dependency / Stack layerClaude Code 2.1.277 reads AGENTS.md when there is no CLAUDE.md, and subagent output now carries an anti-spoofing headerClaude Code changelog