Four OpenClaw flaws allow data theft, privilege escalation, and persistence

Ravi LakshmananMay 15, 2026Vulnerability/AI Security Cybersecurity researchers have revealed a series of four security flaws in OpenClaw that can be chained together to achieve data theft, privilege escalation, and persistence. The vulnerabilities, collectively referred to as “Claw Chain” by Cyera, could allow attackers to establish a foothold, expose sensitive data, and install backdoors. A brief […]

GoPro is also shifting its focus to defense.

Want to make money? Start building your data center. Alternatively, you can build batteries to power data centers. Or: Focus on defense. This is not financial advice, but it certainly seems to be appealing to public markets and retail investors these days. Ford’s nascent energy storage business, which is a fraction of Tesla’s size and […]

What you can learn about your real attack surface by observing your tools for 45 days

hacker newsMay 15, 2026Endpoint security/threat detection In “The Biggest Security Risk Isn’t Malware — It’s What You Already Trust,” I made the simple argument that the most dangerous activity within most organizations no longer looks like an attack. It’s administrative-like. PowerShell, WMIC, netsh, Certutil, MSBuild — the same trusted utilities that IT teams use every […]

TanStack supply chain attack attacks two OpenAI employee devices, forcing macOS updates

OpenAI disclosed that two of its employee devices in its corporate environment were affected by the Mini Shai-Hulud supply chain attack on TanStack, but said that no user data, production systems, or intellectual property was compromised or modified in an unauthorized manner. “Once we identified the malicious activity, we quickly took steps to investigate, contain, […]

On-premises Microsoft Exchange Server CVE-2026-42897 can be exploited via crafted email

Rabi LakshmananMay 15, 2026Microsoft / Vulnerability Microsoft has disclosed a new security vulnerability affecting the on-premises version of Exchange Server and announced that it is being exploited in the wild. The vulnerability is tracked as CVE-2026-42897 (CVSS score: 8.1) and is described as a spoofing bug due to a cross-site scripting flaw. An anonymous researcher […]

CISA adds Cisco SD-WAN CVE-2026-20182 to KEV after administrator access exploit

Rabi LakshmananMay 15, 2026Vulnerability/Credential Theft The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly disclosed vulnerability affecting Cisco Catalyst SD-WAN controllers to its Known Exploited Vulnerabilities (KEV) catalog and asked federal civilian executive branch (FCEB) agencies to fix the issue by May 17, 2026. This vulnerability is a critical authentication bypass […]

Lovable just helped a company bring vibecoding to their hardware

Lovable, an AI-powered app building platform, has helped Atech, a Danish hardware startup that wants to bring “vibe coding” to the hardware creation process. Lovable was participating in an $800,000 pre-seed round that also included participation from a16z’s Scout Fund, Sequoia Scout Fund, and Nordic Makers. In a chat with TechCrunch, Gustav Hugod, head of […]

Transforming health brands for modern consumers

In this episode of ADWEEK’s Adspeak, Chief Brand and Community Officer Jenny Rooney speaks with Caldera Arts Director Jason White. Lina Polimeni, SVP and CMO of Eli Lilly and Company. Lifestyle content creator Nita Daniel talks about how health brands can gain trust in a skeptical, consumer-driven world. In this conversation, we explore why pharma […]

What happens when AI starts building itself?

Richard Socher has long been a leading figure in AI, best known for founding early chatbot startup You.com and for his earlier work at ImageNet. He now joins the current generation of research-focused AI startups with Recursive Superintelligence, a San Francisco-based startup that emerged from stealth with $650 million in funding on Wednesday. Socher joins […]