Product
medium
threat
Exploitation of OpenClaw and Moltbot AI Coding Agents
1 rule 3 TTPs 3 IOCsAI coding assistants including OpenClaw, Moltbot, and Clawdbot are being weaponized via malicious 'ClawHub' registry skills to execute unauthorized system commands and exfiltrate cryptocurrency and credential data.
exploited
OpenClaw +2
ai-security
supply-chain
command-and-control
living-off-the-land
1r
3t
3i
medium
advisory
GenAI Tool Configuration Poisoning via MCP Server Injection
1 rule 2 TTPsAdversaries are targeting configuration files of popular GenAI tools to inject malicious Model Context Protocol (MCP) servers, enabling persistence, arbitrary command execution, and data exfiltration.
Cursor +9
defense-evasion
persistence
genai-security
supply-chain
1r
2t
critical
advisory
Elastic Defend Alert from GenAI Utility or Descendant
2 rules 1 TTPThis rule detects Elastic Defend alerts originating from or directly related to GenAI coding utilities, indicating potential prompt injection, malicious skills, or supply-chain compromise.
Cursor +11
genai
supply-chain
elastic-defend
2r
1t