Ongoing Security Crisis: Supply-Chain, Privacy, Authorization, and Autonomous-Agent Risks
The security picture now combines reported CVEs, ClawHub authorization flaws, MemTensor and fake-installer compromises, SSRF, unsafe Gateway exposure, and concrete Muse privacy failures involving excessive or unauthorized access. NVIDIA's Open Agent Safety Platform adds momentum toward runtime enforcement and independent monitoring, but its OpenClaw-related claims remain largely promotional and unvalidated; the reported Microsoft Autopilot deployment and 138 CVEs also remain unverified.
Sources (21)
Updated Sep 29, 2026