Fetching from the wire…
Public story · 2026-03-15 · source-backed
Adversa AI's March 2026 roundup documented 8 confirmed security incidents across OpenClaw and ServiceNow deployments, with aggregate scanning finding 43% of MCP servers vulnerable to command execution. A new vulnerability class is emerging around persistent memory and SOUL.md identity file poisoning as the successor to prompt injection — attackers modify the agent's persistent context rather than injecting into a single prompt. Adversa AI
The roundup ships a CISO playbook including detection engineering rules, incident response checklists, and 40 A2A threat papers synthesized into actionable guidance. Concurrently, CVE-2026-30856 disclosed that Tencent's WeKnora MCP server is vulnerable to tool execution hijacking via ambiguous naming combined with indirect prompt injection. The MCPTox benchmark tested 20 LLM agents against 45 real-world MCP servers (353 tools) and found o1-mini has a 72.8% attack success rate — with more capable models often more susceptible due to better instruction-following of injected payloads. GitLab Security Advisories
Run npx @invariantlabs/mcp-scan today. It auto-discovers MCP configs from Claude Desktop, Cursor, Claude Code, Gemini CLI, and Windsurf, then scans every installed server for prompt injection payloads, tool poisoning, and cross-origin privilege escalation. Invariant Labs This is a sub-minute audit that maps findings to the OWASP MCP Top 10.
Each link below shares sources, entities, or timing with this story.
OpenClaw uses Claude Code / Shared entities / Same source / Shared topic
Linked by a graph relationship (OpenClaw uses Claude Code); both cover Claude Code, Claude Desktop, Cursor, Gemini CLI; cite the same source (Invariant Labs).
OpenClaw uses Claude Code / Shared entities / Same source domain / Shared topic / What happened next
Linked by a graph relationship (OpenClaw uses Claude Code); both cover Adversa AI, Claude Code, Cursor, Gemini CLI; reported by the same outlet (adversa.ai).
OpenClaw uses Claude Code / Shared entities / Shared topic / What happened next
Linked by a graph relationship (OpenClaw uses Claude Code); both cover Claude Code, Claude Desktop, Cursor, Gemini CLI; overlapping topics (agent, claude, injection, server, tool).
OpenClaw uses Claude Code / Shared entities / What happened next / Tension
Linked by a graph relationship (OpenClaw uses Claude Code); both cover Claude Code, Claude Desktop, Cursor, Gemini CLI; picks up the Claude Code thread on 2026-03-16.
OpenClaw uses Claude Code / Shared entities / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (OpenClaw uses Claude Code); both cover Claude Code, Claude Desktop, Cursor, MCP; overlapping topics (claude, server, tool).
OpenClaw uses SQLite / Shared entities / Shared topic / What happened next / Tension
Linked by a graph relationship (OpenClaw uses SQLite); both cover Claude Code, Cursor, LLM, MCP; overlapping topics (agent, claude).
OpenClaw uses Claude Code / Shared entities / Shared topic / What happened next
Linked by a graph relationship (OpenClaw uses Claude Code); both cover Claude Code, Cursor, Gemini CLI, LLM; overlapping topics (agent, command, tool).
Linked by a graph relationship (OpenClaw uses Claude Code); both cover Claude Code, Cursor, Gemini CLI, MCP; overlapping topics (agent, claude).