{"id":6610,"date":"2026-08-25T18:55:44","date_gmt":"2026-08-25T18:55:44","guid":{"rendered":"https:\/\/areeblog.com\/?p=6610"},"modified":"2026-08-25T18:55:44","modified_gmt":"2026-08-25T18:55:44","slug":"oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent","status":"publish","type":"post","link":"https:\/\/areeblog.com\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\/","title":{"rendered":"Oasis Security Researchers Reveal Security Flaw in NemoClaw AI Agent"},"content":{"rendered":"<p><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"6611\" data-permalink=\"https:\/\/areeblog.com\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\/unnamed\/\" data-orig-file=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/unnamed.jpg\" data-orig-size=\"900,470\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;,&quot;alt&quot;:&quot;&quot;}\" data-image-title=\"unnamed\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/unnamed.jpg\" class=\"aligncenter size-full wp-image-6611\" src=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/unnamed.jpg\" alt=\"Oasis Security Researchers Reveal Security Flaw in NemoClaw AI Agent\" width=\"900\" height=\"470\" srcset=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/unnamed.jpg 900w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/unnamed-300x157.jpg 300w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/unnamed-768x401.jpg 768w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/unnamed-860x449.jpg 860w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/p>\n<p>Security researchers at Oasis Security have disclosed a vulnerability in NVIDIA\u2019s NemoClaw <a href=\"https:\/\/areeblog.com\/cloudflare-cut-astros-open-github-issues-by-85-using-a-team-of-ai-agents\/\">AI-agent<\/a> environment that can allow a malicious webpage to reach the local Ollama server used for model inference and alter how an AI model processes instructions.<\/p>\n<p>The vulnerability, tracked as <a href=\"https:\/\/siliconangle.com\/2026\/08\/25\/nvidia-nemoclaw-flaw-let-attackers-poison-the-model-behind-a-developers-ai-agent\/\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2026-65105<\/a>, was reported to NVIDIA\u2019s Product Security Incident Response Team before the public disclosure, according to reporting on the researchers\u2019 findings.<\/p>\n<p>The issue is significant because the researchers were able to go beyond sending a temporary prompt to an AI system. Their research showed that an attacker could modify an Ollama model\u2019s chat template and place instructions inside it, allowing those instructions to be included in later interactions with the model.<\/p>\n<p>NemoClaw is designed to provide security and privacy controls around OpenClaw AI agents. NVIDIA\u2019s documentation describes OpenShell, the environment used by NemoClaw, as providing controls over processes, filesystem access, network activity and other capabilities available to an agent. The company\u2019s <a href=\"https:\/\/docs.nvidia.com\/nemoclaw\/user-guide\/openclaw\/security\/security-controls\/process-controls\" target=\"_blank\" rel=\"noopener noreferrer\">security documentation<\/a> describes several of those controls.<\/p>\n<p>Oasis researchers found a separate weakness involving the local Ollama inference service. In the configuration examined by the researchers, NemoClaw starts Ollama with <code>OLLAMA_HOST=0.0.0.0:11434<\/code>, causing the service to listen on all network interfaces rather than only the local loopback interface.<\/p>\n<p>According to the researchers\u2019 findings, the Ollama API does not require conventional authentication. Ollama includes protections intended to restrict unauthorized requests from websites, but the researchers reported that when Ollama is bound to a non-loopback address, its Host-header validation is skipped. That leaves browser-origin protections as a remaining barrier to direct access.<\/p>\n<p>The researchers demonstrated that a malicious website can use DNS rebinding to reach the locally running Ollama service through a victim\u2019s browser. Once access to the API is obtained, an attacker can interact with the model server without needing the user to deliberately open the Ollama service.<\/p>\n<p>The researchers found that the exposed API could be used to enumerate installed models, retrieve model templates and system prompts, obtain information such as the machine hostname, delete models, download or push models, consume GPU resources and force Ollama to sign out. The most consequential finding involved changing a model\u2019s chat template.<\/p>\n<p>A chat template determines how conversations are formatted before they are sent to a model. Oasis researchers reported that they could retrieve a legitimate template, insert an attacker-controlled instruction and write the modified template back to the model.<\/p>\n<p>That approach differs from a conventional prompt injection carried out inside a single conversation. The researchers\u2019 technique changes the model-serving configuration itself, allowing the malicious instruction to be inserted into subsequent requests handled by the model.<\/p>\n<p>According to the <a href=\"https:\/\/expertinsights.com\/news\/nvidia-nemoclaw-lets-web-page-hijack-model-server\" target=\"_blank\" rel=\"noopener noreferrer\">technical reporting on the research<\/a>, this means a simple new conversation or a system prompt supplied by the AI agent does not necessarily remove the altered template. The researchers described the modified template as sitting beneath the normal instruction layer used by the agent.<\/p>\n<p>The potential consequences depend on what the affected AI agent is authorized to do. The research describes possible scenarios in which a compromised model could influence an agent to introduce vulnerable code, conceal security problems, recommend attacker-controlled packages or send information to an external endpoint.<\/p>\n<p>Those outcomes are not automatic consequences of CVE-2026-65105. They depend on the permissions, integrations and resources available to the affected agent. The vulnerability primarily provides a route to modify the model used by the agent; what can happen after that depends on the agent\u2019s existing capabilities.<\/p>\n<p>The research also raises a separate exposure issue because Ollama is configured to listen on <code>0.0.0.0:11434<\/code>. <a href=\"https:\/\/expertinsights.com\/news\/nvidia-nemoclaw-lets-web-page-hijack-model-server\" target=\"_blank\" rel=\"noopener noreferrer\">Expert Insights<\/a> reported that systems able to reach that port over a network could potentially communicate with the Ollama API directly, without relying on the browser-based DNS rebinding technique.<\/p>\n<p>That creates two relevant attack paths. An attacker could use a malicious webpage to reach the local service through DNS rebinding, or a device that has network access to the exposed Ollama port could attempt to communicate with the API directly.<\/p>\n<p>The findings do not indicate that an attacker automatically escapes the NemoClaw sandbox. Instead, the research shows that the model service supporting the agent can potentially be manipulated while the agent\u2019s surrounding controls remain in place.<\/p>\n<p>That distinction is important. NemoClaw\u2019s security architecture is intended to restrict what an agent can do on the host system. The Oasis research highlights a different problem: an attacker may attempt to manipulate the model that the agent already relies on, rather than directly defeating the agent\u2019s process, filesystem or network restrictions.<\/p>\n<p>Oasis disclosed the vulnerability to NVIDIA before making the findings public. NVIDIA has continued to publish NemoClaw release updates containing security and runtime changes. Its <a href=\"https:\/\/docs.nvidia.com\/nemoclaw\/latest\/user-guide\/openclaw\/release-notes\/2026\/7\/20\" target=\"_blank\" rel=\"noopener noreferrer\">July 20 release notes<\/a>, for example, document security-related dependency remediation and changes involving inference-provider configuration, while later releases include additional hardening.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security researchers at Oasis Security have disclosed a vulnerability in NVIDIA\u2019s NemoClaw AI-agent environment that can allow a malicious webpage to reach the local Ollama server used for model inference and alter how an AI model processes instructions. The vulnerability, tracked as CVE-2026-65105, was reported to NVIDIA\u2019s Product Security Incident Response Team before the public [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":6611,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","_monsterinsights_skip_tracking":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[164],"tags":[1075],"class_list":["post-6610","post","type-post","status-publish","format-standard","has-post-thumbnail","category-tech-updates","tag-ai-agents"],"share_on_mastodon":{"url":"https:\/\/mastodon.social\/@Areeblog\/117157688596559061","error":""},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.4 (Yoast SEO v28.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Oasis Security Researchers Reveal Security Flaw in NemoClaw AI Agent - Aree Blog<\/title>\n<meta name=\"description\" content=\"Oasis Security found a NemoClaw flaw that can let malicious webpages alter local Ollama models and AI agent behavior.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/areeblog.com\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Oasis Security Researchers Reveal Security Flaw in NemoClaw AI Agent\" \/>\n<meta property=\"og:description\" content=\"Oasis Security found a NemoClaw flaw that can let malicious webpages alter local Ollama models and AI agent behavior.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/areeblog.com\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\/\" \/>\n<meta property=\"og:site_name\" content=\"Aree Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-25T18:55:44+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/unnamed.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"900\" \/>\n\t<meta property=\"og:image:height\" content=\"470\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Daniel Chinonso John\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Daniel Chinonso John\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\\\/\"},\"author\":{\"name\":\"Daniel Chinonso John\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/#\\\/schema\\\/person\\\/d972222c55618fb0f4b4c0c11ff52f63\"},\"headline\":\"Oasis Security Researchers Reveal Security Flaw in NemoClaw AI Agent\",\"datePublished\":\"2026-08-25T18:55:44+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\\\/\"},\"wordCount\":803,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/unnamed.jpg\",\"keywords\":[\"AI Agents\"],\"articleSection\":[\"Tech Updates\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/areeblog.com\\\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\\\/\",\"url\":\"https:\\\/\\\/areeblog.com\\\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\\\/\",\"name\":\"Oasis Security Researchers Reveal Security Flaw in NemoClaw AI Agent - Aree Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/unnamed.jpg\",\"datePublished\":\"2026-08-25T18:55:44+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/#\\\/schema\\\/person\\\/d972222c55618fb0f4b4c0c11ff52f63\"},\"description\":\"Oasis Security found a NemoClaw flaw that can let malicious webpages alter local Ollama models and AI agent behavior.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/areeblog.com\\\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\\\/#primaryimage\",\"url\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/unnamed.jpg\",\"contentUrl\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/unnamed.jpg\",\"width\":900,\"height\":470,\"caption\":\"Oasis Security Researchers Reveal Security Flaw in NemoClaw AI Agent\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/areeblog.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Oasis Security Researchers Reveal Security Flaw in NemoClaw AI Agent\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/#website\",\"url\":\"https:\\\/\\\/areeblog.com\\\/\",\"name\":\"Aree Blog\",\"description\":\"Unfiltered Perspectives, Unstoppable Insights\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/areeblog.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/#\\\/schema\\\/person\\\/d972222c55618fb0f4b4c0c11ff52f63\",\"name\":\"Daniel Chinonso John\",\"description\":\"Daniel Chinonso John is a web designer, penetration tester, and founder of Aree Tech. He writes clear, actionable posts at the intersection of productivity, AI, cybersecurity, and blogging to help readers get things done.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/daniel-john-45183a169\\\/\"],\"url\":\"https:\\\/\\\/areeblog.com\\\/author\\\/danojohn55gmail-com\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Oasis Security Researchers Reveal Security Flaw in NemoClaw AI Agent - Aree Blog","description":"Oasis Security found a NemoClaw flaw that can let malicious webpages alter local Ollama models and AI agent behavior.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/areeblog.com\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\/","og_locale":"en_US","og_type":"article","og_title":"Oasis Security Researchers Reveal Security Flaw in NemoClaw AI Agent","og_description":"Oasis Security found a NemoClaw flaw that can let malicious webpages alter local Ollama models and AI agent behavior.","og_url":"https:\/\/areeblog.com\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\/","og_site_name":"Aree Blog","article_published_time":"2026-08-25T18:55:44+00:00","og_image":[{"width":900,"height":470,"url":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/unnamed.jpg","type":"image\/jpeg"}],"author":"Daniel Chinonso John","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Daniel Chinonso John","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/areeblog.com\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\/#article","isPartOf":{"@id":"https:\/\/areeblog.com\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\/"},"author":{"name":"Daniel Chinonso John","@id":"https:\/\/areeblog.com\/#\/schema\/person\/d972222c55618fb0f4b4c0c11ff52f63"},"headline":"Oasis Security Researchers Reveal Security Flaw in NemoClaw AI Agent","datePublished":"2026-08-25T18:55:44+00:00","mainEntityOfPage":{"@id":"https:\/\/areeblog.com\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\/"},"wordCount":803,"commentCount":0,"image":{"@id":"https:\/\/areeblog.com\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\/#primaryimage"},"thumbnailUrl":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/unnamed.jpg","keywords":["AI Agents"],"articleSection":["Tech Updates"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/areeblog.com\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/areeblog.com\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\/","url":"https:\/\/areeblog.com\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\/","name":"Oasis Security Researchers Reveal Security Flaw in NemoClaw AI Agent - Aree Blog","isPartOf":{"@id":"https:\/\/areeblog.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/areeblog.com\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\/#primaryimage"},"image":{"@id":"https:\/\/areeblog.com\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\/#primaryimage"},"thumbnailUrl":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/unnamed.jpg","datePublished":"2026-08-25T18:55:44+00:00","author":{"@id":"https:\/\/areeblog.com\/#\/schema\/person\/d972222c55618fb0f4b4c0c11ff52f63"},"description":"Oasis Security found a NemoClaw flaw that can let malicious webpages alter local Ollama models and AI agent behavior.","breadcrumb":{"@id":"https:\/\/areeblog.com\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/areeblog.com\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/areeblog.com\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\/#primaryimage","url":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/unnamed.jpg","contentUrl":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/unnamed.jpg","width":900,"height":470,"caption":"Oasis Security Researchers Reveal Security Flaw in NemoClaw AI Agent"},{"@type":"BreadcrumbList","@id":"https:\/\/areeblog.com\/oasis-security-researchers-reveal-security-flaw-in-nemoclaw-ai-agent\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/areeblog.com\/"},{"@type":"ListItem","position":2,"name":"Oasis Security Researchers Reveal Security Flaw in NemoClaw AI Agent"}]},{"@type":"WebSite","@id":"https:\/\/areeblog.com\/#website","url":"https:\/\/areeblog.com\/","name":"Aree Blog","description":"Unfiltered Perspectives, Unstoppable Insights","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/areeblog.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/areeblog.com\/#\/schema\/person\/d972222c55618fb0f4b4c0c11ff52f63","name":"Daniel Chinonso John","description":"Daniel Chinonso John is a web designer, penetration tester, and founder of Aree Tech. He writes clear, actionable posts at the intersection of productivity, AI, cybersecurity, and blogging to help readers get things done.","sameAs":["https:\/\/www.linkedin.com\/in\/daniel-john-45183a169\/"],"url":"https:\/\/areeblog.com\/author\/danojohn55gmail-com\/"}]}},"jetpack_sharing_enabled":true,"jetpack-related-posts":[{"id":6332,"url":"https:\/\/areeblog.com\/why-ai-vulnerabilities-require-coordinated-disclosure\/","url_meta":{"origin":6610,"position":0},"title":"Why AI Vulnerabilities Require Coordinated Disclosure","author":"Daniel Chinonso John","date":"July 15, 2026","format":false,"excerpt":"More than 95% of vulnerabilities tracked under Google Project Zero's 90-day disclosure policy have historically been fixed before the deadline. That shows responsible disclosure works when researchers and vendors cooperate. Artificial intelligence is now testing whether that same model can survive an entirely new class of security problems. Unlike a\u2026","rel":"","context":"In &quot;Cybersecurity&quot;","block_context":{"text":"Cybersecurity","link":"https:\/\/areeblog.com\/category\/cybersecurity\/"},"img":{"alt_text":"Why AI Vulnerabilities Require Coordinated Disclosure","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260715-WA0006.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260715-WA0006.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260715-WA0006.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260715-WA0006.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260715-WA0006.jpg?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":6883,"url":"https:\/\/areeblog.com\/llmvul-dataset-exposes-vulnerabilities-in-ai-generated-c-c-code\/","url_meta":{"origin":6610,"position":1},"title":"LLMVul Dataset Exposes Vulnerabilities in AI-Generated C\/C++ Code","author":"Samuel Ogori","date":"September 12, 2026","format":false,"excerpt":"A new cybersecurity research dataset has identified 1,540 potentially vulnerable C and C++ functions associated with AI-assisted software development, giving researchers a large real-world collection for examining security weaknesses in code produced with artificial intelligence tools. The dataset, called LLMVul, was developed by Mohammad Farhad and Shuvalaxmi Dass of the\u2026","rel":"","context":"In &quot;Cybersecurity&quot;","block_context":{"text":"Cybersecurity","link":"https:\/\/areeblog.com\/category\/cybersecurity\/"},"img":{"alt_text":"LLMVul Dataset Exposes Vulnerabilities in AI-Generated C\/C++ Code","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/AI-hands-generate-code-Summit_Art_Creations-shutterstock.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/AI-hands-generate-code-Summit_Art_Creations-shutterstock.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/AI-hands-generate-code-Summit_Art_Creations-shutterstock.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/AI-hands-generate-code-Summit_Art_Creations-shutterstock.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/AI-hands-generate-code-Summit_Art_Creations-shutterstock.jpg?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":6735,"url":"https:\/\/areeblog.com\/researchers-find-ai-coding-agents-can-turn-llms-txt-into-a-software-supply-chain-attack-surface\/","url_meta":{"origin":6610,"position":2},"title":"Researchers Find AI Coding Agents Can Turn llms.txt Into a Software Supply-Chain Attack Surface","author":"Daniel Chinonso John","date":"September 3, 2026","format":false,"excerpt":"Security researchers have demonstrated that AI coding agents can execute unclaimed software packages referenced by trusted-looking website documentation, creating a potential software supply-chain attack path for companies using autonomous coding tools. The research focused on llms.txt and llms-full.txt, machine-readable files increasingly published by websites to summarize their content and structure\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"Researchers Find AI Coding Agents Can Turn llms.txt Into a Software Supply-Chain Attack Surface","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260903-WA0006.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260903-WA0006.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260903-WA0006.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260903-WA0006.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260903-WA0006.jpg?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":6851,"url":"https:\/\/areeblog.com\/bynario-raises-e2-1m-to-tackle-ai-fueled-vulnerability-surge\/","url_meta":{"origin":6610,"position":3},"title":"Bynario Raises \u20ac2.1M to Tackle AI-Fueled Vulnerability Surge","author":"Daniel Chinonso John","date":"September 10, 2026","format":false,"excerpt":"Italian cybersecurity startup Bynario has raised \u20ac2.1 million in pre-seed funding as the rapid growth of AI-assisted security research creates a new challenge for organisations: handling the growing number of potential software vulnerabilities being identified. The Milan-based company said the round was led by 360 Capital Partners, with participation from\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"Italian Cybersecurity Startup Bynario Raises \u20ac2.1M to Tackle AI-Fueled Vulnerability Surge","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/images-57.jpeg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/images-57.jpeg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/images-57.jpeg?resize=525%2C300&ssl=1 1.5x"},"classes":[]},{"id":6842,"url":"https:\/\/areeblog.com\/a-hidden-chatgpt-attack-channel-shows-why-ai-agent-isolation-is-failing\/","url_meta":{"origin":6610,"position":4},"title":"A Hidden ChatGPT Attack Channel Shows Why AI Agent Isolation Is Failing","author":"Daniel Chinonso John","date":"September 9, 2026","format":false,"excerpt":"A hidden communication channel inside ChatGPT's code-execution infrastructure allowed two separate accounts to exchange information, raising new concerns about how AI agents are isolated from one another and from connected services. The vulnerability was disclosed by Check Point Research on September 8, 2026. Researchers found that separate ChatGPT execution environments\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"A Hidden ChatGPT Attack Channel Shows Why AI Agent Isolation Is Failing","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260909-WA0013.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260909-WA0013.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260909-WA0013.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260909-WA0013.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260909-WA0013.jpg?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":6720,"url":"https:\/\/areeblog.com\/ai-coding-agents-found-running-malicious-git-commands-before-user-approval\/","url_meta":{"origin":6610,"position":5},"title":"AI Coding Agents Found Running Malicious Git Commands Before User Approval","author":"Daniel Chinonso John","date":"September 1, 2026","format":false,"excerpt":"Security researchers at Manifold Security have identified six high-severity security findings across five AI coding agents that can allow attacker-controlled code to run while the agents gather repository information. The research, published September 1, 2026, covers Claude Code, Qwen Code, Goose, Grok Build and Hermes Agent. Manifold said two of\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"AI Coding Agents Found Running Malicious Git Commands Before User Approval","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260901-WA0010.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260901-WA0010.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260901-WA0010.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260901-WA0010.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260901-WA0010.jpg?resize=1050%2C600&ssl=1 3x"},"classes":[]}],"jetpack_featured_media_url":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/unnamed.jpg","_links":{"self":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/posts\/6610","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/comments?post=6610"}],"version-history":[{"count":2,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/posts\/6610\/revisions"}],"predecessor-version":[{"id":6613,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/posts\/6610\/revisions\/6613"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/media\/6611"}],"wp:attachment":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/media?parent=6610"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/categories?post=6610"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/tags?post=6610"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}