ClawHub vulnerability made trust the attack surface
Silverfort says an exposed public Convex mutation let anyone fake ClawHub downloads, push a malicious skill to the top, and turn OpenClaw trust into a supply-chain risk.
AI News Silo organizes the latest AI news articles about everything in artificial intelligence today.
Category archive
Follow Open Source AI coverage across open-weight models, OSS tooling, agent frameworks, developer runtimes, and the maintainership questions shaping the broader AI stack.
Why this category exists
Open Source AI coverage from AI News Silo, covering open-weight models, OSS AI tooling, agent frameworks, developer runtimes, and the governance of shared AI stacks.
High-signal themes
Core search targets: open source AI, open source AI news, open source AI models.
Silverfort says an exposed public Convex mutation let anyone fake ClawHub downloads, push a malicious skill to the top, and turn OpenClaw trust into a supply-chain risk.
Ai2's MolmoWeb ships open weights, open web-task data, and runnable tooling, giving developers a real shot at self-hosted browser agents instead of rented black boxes.
Cisco's DefenseClaw arrives just after NVIDIA's NemoClaw and a run of real OpenClaw attacks, turning agent security from a side note into the market forming around the platform.
OpenClaw 2026.3.22 does not prove ClawHub is a booming marketplace. It does something more consequential: it makes ClawHub part of the default install and migration path.
OpenShell matters less as another framework than as a control plane that moves policy, sandboxing, and model routing outside the agent’s reach.
vLLM's Triton and ROCm attention work points to a new inference contest: portable backends that can make AMD and other non-NVIDIA stacks credible in production.
The Linux Foundation’s $12.5 million coalition shows AI labs now need open source maintainers to handle a rising flood of AI-generated security findings.
I only get excited about open-weight inference when utilization, latency, privacy, and ops discipline line up. Sticker price alone is the decoy menu.