SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free
SCTPhantom is a Linux kernel use-after-free in SCTP's dynamic address reconfiguration code.
SCTPhantom is a Linux kernel use-after-free in SCTP's dynamic address reconfiguration code.
This article breaks down the end-to-end attack chain of Memory Heist and demonstrates how to automate its detection using the Agent Security Scanning module (agent-scan) in AI-Infra-Guard (A.I.G).
Read Full Article arrow_forwardAI Agents gain access to tools, code execution, and business systems, risks such as prompt injection, jailbreaks, and tool abuse can lead to data leaks, system compromise, or business tampering. Tencent Zhuque Lab open-sources the A.I.G Agent Security dirll Skill to help developers and business teams run lightweight, local, and systematic security tests before launch.
Read Full Article arrow_forwardThe Chinese University of Hong Kong, Shenzhen, in collaboration with Tencent Zhuque Lab, has released SkillTrustBench, the first safety evaluation benchmark for Agent skills.
Read Full Article arrow_forwardThe explosive popularity of OpenClaw in early 2026 transformed AI from a system that answers questions into an agent that executes operations on your behalf. "Skills" are the primary mechanism through which Agents acquire these capabilities, making them the latest entry point for attackers to poison the well. We used A.I.G (https://github.com/tencent/AI-Infra-Guard) to conduct a comprehensive scan of over 50,000 Skills on ClawHub. We uncovered not only known malicious samples but also the next generation of highly stealthy attack vectors.
Read Full Article arrow_forwardZhuque Lab’s Red Teaming Bot—an automated vulnerability discovery and adversary simulation platform powered by multi-agent orchestration—successfully conducted rapid security audits on targets including OpenClaw and the Linux kernel.
Read Full Article arrow_forward