SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free
SCTPhantom is a Linux kernel use-after-free in SCTP's dynamic address reconfiguration code.
Read Full Article arrow_forwardSCTPhantom is a Linux kernel use-after-free in SCTP's dynamic address reconfiguration code.
Read Full Article arrow_forwardThis article breaks down the end-to-end attack chain of Memory Heist and demonstrates how to automate its detection using the Agent Security Scanning module (agent-scan) in AI-Infra-Guard (A.I.G).
Read Full Article arrow_forwardAI Agents gain access to tools, code execution, and business systems, risks such as prompt injection, jailbreaks, and tool abuse can lead to data leaks, system compromise, or business tampering. Tencent Zhuque Lab open-sources the A.I.G Agent Security dirll Skill to help developers and business teams run lightweight, local, and systematic security tests before launch.
Read Full Article arrow_forwardThe Chinese University of Hong Kong, Shenzhen, in collaboration with Tencent Zhuque Lab, has released SkillTrustBench, the first safety evaluation benchmark for Agent skills.
Read Full Article arrow_forwardThe explosive popularity of OpenClaw in early 2026 transformed AI from a system that answers questions into an agent that executes operations on your behalf. "Skills" are the primary mechanism through which Agents acquire these capabilities, making them the latest entry point for attackers to poison the well. We used A.I.G (https://github.com/tencent/AI-Infra-Guard) to conduct a comprehensive scan of over 50,000 Skills on ClawHub. We uncovered not only known malicious samples but also the next generation of highly stealthy attack vectors.
Read Full Article arrow_forwardZhuque Lab’s Red Teaming Bot—an automated vulnerability discovery and adversary simulation platform powered by multi-agent orchestration—successfully conducted rapid security audits on targets including OpenClaw and the Linux kernel.
Read Full Article arrow_forwardZhuque Lab has open-sourced A.I.G (AI Infra Guard), an AI infra security toolkit that now supports one-click detection for supply chain poisoning attacks targeting LiteLLM, the popular LLM gateway.
Read Full Article arrow_forwardTencent Zhuque Lab recently uncovered widespread security vulnerabilities in popular AI tools, including DeepSeek. If left unmitigated, these flaws could allow attackers to exfiltrate sensitive user data, hijack computational resources, or even gain full control over user devices.To address these threats, we will demonstrate how to use the open-source toolkit AI-Infra-Guard to perform one-click detection and effectively remediate these security risks.
Read Full Article arrow_forward