<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Simon Roses Femerling &#8211; Blog</title>
	<atom:link href="https://simonroses.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://simonroses.com</link>
	<description>CyberSpace Insecurity 3.X</description>
	<lastBuildDate>Fri, 05 Jun 2026 07:52:00 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>
<site xmlns="com-wordpress:feed-additions:1">13601991</site>	<item>
		<title>Information Warfare Strategies (SRF-IWS): Offensive Operations Against a Papal Visit — Pope Leo XIV in Madrid 2026</title>
		<link>https://simonroses.com/2026/06/information-warfare-strategies-srf-iws-offensive-operations-against-a-papal-visit-pope-leo-xiv-in-madrid-2026/</link>
					<comments>https://simonroses.com/2026/06/information-warfare-strategies-srf-iws-offensive-operations-against-a-papal-visit-pope-leo-xiv-in-madrid-2026/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Fri, 05 Jun 2026 07:52:00 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[BlueTeam]]></category>
		<category><![CDATA[Information Warfare]]></category>
		<category><![CDATA[RedTeam]]></category>
		<category><![CDATA[SRF-IWS]]></category>
		<category><![CDATA[SRFIWS]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2394</guid>

					<description><![CDATA[> **Disclaimer:** Everything described here is pure imagination and any resemblance to reality is coincidental. This document is intended for security professionals to develop defensive countermeasures. The author is not responsible for the consequences of any action taken based on &#8230; <a href="https://simonroses.com/2026/06/information-warfare-strategies-srf-iws-offensive-operations-against-a-papal-visit-pope-leo-xiv-in-madrid-2026/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/06/information-warfare-strategies-srf-iws-offensive-operations-against-a-papal-visit-pope-leo-xiv-in-madrid-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2394</post-id>	</item>
		<item>
		<title>Scanning Vibe-Coded Apps: Why Traditional SAST/DAST Falls Short (part 6)</title>
		<link>https://simonroses.com/2026/05/scanning-vibe-coded-apps-why-traditional-sast-dast-falls-short-part-6/</link>
					<comments>https://simonroses.com/2026/05/scanning-vibe-coded-apps-why-traditional-sast-dast-falls-short-part-6/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Thu, 28 May 2026 07:20:50 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Pentest]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[VibeCoding]]></category>
		<category><![CDATA[VibeCodingSecurity]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2379</guid>

					<description><![CDATA[> **Vibe Coding Security Series** > 1. [What Is Vibe Coding Security? A Field Guide for 2026](https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/) > 2. [The OWASP Top 10 for Vibe-Coded Applications](https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/) > 3. [Anatomy of a Vibe Coding Breach: Lessons from 2026&#8217;s Worst Incidents](https://simonroses.com/2026/04/anatomy-of-a-vibe-coding-breach-part-3/) > &#8230; <a href="https://simonroses.com/2026/05/scanning-vibe-coded-apps-why-traditional-sast-dast-falls-short-part-6/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/05/scanning-vibe-coded-apps-why-traditional-sast-dast-falls-short-part-6/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2379</post-id>	</item>
		<item>
		<title>When Agents Fix Agents: How Hermes Patched OpenClaw After a Bad Update</title>
		<link>https://simonroses.com/2026/05/when-agents-fix-agents-how-hermes-patched-openclaw-after-a-bad-update/</link>
					<comments>https://simonroses.com/2026/05/when-agents-fix-agents-how-hermes-patched-openclaw-after-a-bad-update/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Sat, 23 May 2026 08:31:51 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[AgenticAI]]></category>
		<category><![CDATA[Agents]]></category>
		<category><![CDATA[Hermes]]></category>
		<category><![CDATA[openclaw]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2341</guid>

					<description><![CDATA[**Read Time:** 7 minutes ## TL;DR I told OpenClaw to update itself. It did. Then the gateway refused to start because a config field had quietly changed shape between releases (`channels.discord.streaming` went from string to object). `openclaw doctor &#8211;fix` saw &#8230; <a href="https://simonroses.com/2026/05/when-agents-fix-agents-how-hermes-patched-openclaw-after-a-bad-update/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/05/when-agents-fix-agents-how-hermes-patched-openclaw-after-a-bad-update/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2341</post-id>	</item>
		<item>
		<title>Authentication &#038; Secrets: What AI Gets Wrong Every Time (Part 5)</title>
		<link>https://simonroses.com/2026/05/authentication-secrets-what-ai-gets-wrong-every-time-part-5/</link>
					<comments>https://simonroses.com/2026/05/authentication-secrets-what-ai-gets-wrong-every-time-part-5/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Thu, 21 May 2026 07:27:38 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[VibeCoding]]></category>
		<category><![CDATA[VibeCodingSecurity]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2328</guid>

					<description><![CDATA[> **Vibe Coding Security Series** > 1. [What Is Vibe Coding Security? A Field Guide for 2026](https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/) > 2. [The OWASP Top 10 for Vibe-Coded Applications](https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/) > 3. [Anatomy of a Vibe Coding Breach: Lessons from 2026&#8217;s Worst Incidents](https://simonroses.com/2026/04/anatomy-of-a-vibe-coding-breach-part-3/) > &#8230; <a href="https://simonroses.com/2026/05/authentication-secrets-what-ai-gets-wrong-every-time-part-5/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/05/authentication-secrets-what-ai-gets-wrong-every-time-part-5/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2328</post-id>	</item>
		<item>
		<title>The Dependency Trap: Supply Chain Risks in AI-Generated Code (Part 4)</title>
		<link>https://simonroses.com/2026/05/the-dependency-trap-supply-chain-risks-in-ai-generated-code-part-4/</link>
					<comments>https://simonroses.com/2026/05/the-dependency-trap-supply-chain-risks-in-ai-generated-code-part-4/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Fri, 08 May 2026 09:59:43 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[VibeCoding]]></category>
		<category><![CDATA[VibeCodingSecurity]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2307</guid>

					<description><![CDATA[> **Vibe Coding Security Series** > 1. [What Is Vibe Coding Security? A Field Guide for 2026](https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/) > 2. [The OWASP Top 10 for Vibe-Coded Applications](https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/) > 3. [Anatomy of a Vibe Coding Breach: Lessons from 2026&#8217;s Worst Incidents](https://simonroses.com/2026/04/anatomy-of-a-vibe-coding-breach-lessons-from-2026s-worst-incidents-part-3/) > &#8230; <a href="https://simonroses.com/2026/05/the-dependency-trap-supply-chain-risks-in-ai-generated-code-part-4/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/05/the-dependency-trap-supply-chain-risks-in-ai-generated-code-part-4/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2307</post-id>	</item>
		<item>
		<title>Anatomy of a Vibe Coding Breach: Lessons from 2026&#8217;s Worst Incidents (Part 3)</title>
		<link>https://simonroses.com/2026/04/anatomy-of-a-vibe-coding-breach-lessons-from-2026s-worst-incidents-part-3/</link>
					<comments>https://simonroses.com/2026/04/anatomy-of-a-vibe-coding-breach-lessons-from-2026s-worst-incidents-part-3/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Thu, 30 Apr 2026 14:05:29 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[VibeCoding]]></category>
		<category><![CDATA[VibeCodingSecurity]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2286</guid>

					<description><![CDATA[> **Vibe Coding Security Series** > 1. [What Is Vibe Coding Security? A Field Guide for 2026](https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/) > 2. [The OWASP Top 10 for Vibe-Coded Applications](https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/) > 3. **Anatomy of a Vibe Coding Breach: Lessons from 2026&#8217;s Worst Incidents** *(you &#8230; <a href="https://simonroses.com/2026/04/anatomy-of-a-vibe-coding-breach-lessons-from-2026s-worst-incidents-part-3/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/04/anatomy-of-a-vibe-coding-breach-lessons-from-2026s-worst-incidents-part-3/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2286</post-id>	</item>
		<item>
		<title>The OWASP Top 10 for Vibe-Coded Applications (Part 2)</title>
		<link>https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/</link>
					<comments>https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/#comments</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Thu, 23 Apr 2026 17:33:14 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[VibeCoding]]></category>
		<category><![CDATA[VibeCodingSecurity]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2278</guid>

					<description><![CDATA[> **Vibe Coding Security Series** > 1. [What Is Vibe Coding Security? A Field Guide for 2026](https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/) > 2. **The OWASP Top 10 for Vibe-Coded Applications** *(you are here)* > 3. [Anatomy of a Vibe Coding Breach: Lessons from 2026&#8217;s &#8230; <a href="https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2278</post-id>	</item>
		<item>
		<title>How to Weaponize AI Agent Skills</title>
		<link>https://simonroses.com/2026/04/how-to-weaponize-ai-agent-skills/</link>
					<comments>https://simonroses.com/2026/04/how-to-weaponize-ai-agent-skills/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Fri, 17 Apr 2026 08:16:41 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Pentest]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[agent-security]]></category>
		<category><![CDATA[AgenticAI]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[openclaw]]></category>
		<category><![CDATA[Skills]]></category>
		<category><![CDATA[VibeCoding]]></category>
		<category><![CDATA[VibeCodingSecurity]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2272</guid>

					<description><![CDATA[**Read Time:** 10 minutes ## TL;DR AI agent skills — the modular plugins that let agents search the web, execute commands, send messages, and call APIs — are **the new browser extensions**: useful, powerful, and a massive attack surface nobody &#8230; <a href="https://simonroses.com/2026/04/how-to-weaponize-ai-agent-skills/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/04/how-to-weaponize-ai-agent-skills/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2272</post-id>	</item>
		<item>
		<title>What Is Vibe Coding Security? A Field Guide for 2026 (Part 1)</title>
		<link>https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/</link>
					<comments>https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Fri, 10 Apr 2026 07:42:37 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Threat Modeling]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[VibeCoding]]></category>
		<category><![CDATA[VibeCodingSecurity]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2267</guid>

					<description><![CDATA[> **Vibe Coding Security Series** > 1. **What Is Vibe Coding Security? A Field Guide for 2026** *(you are here)* > 2. [The OWASP Top 10 for Vibe-Coded Applications](https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/) > 3. [Anatomy of a Vibe Coding Breach: Lessons from 2026&#8217;s &#8230; <a href="https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2267</post-id>	</item>
		<item>
		<title>AI Must Make Superhumans, Not Unemployed: The Case Against Layoffs and Unaffordable Agents</title>
		<link>https://simonroses.com/2026/04/ai-must-make-superhumans-not-unemployed-the-case-against-layoffs-and-unaffordable-agents/</link>
					<comments>https://simonroses.com/2026/04/ai-must-make-superhumans-not-unemployed-the-case-against-layoffs-and-unaffordable-agents/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Sat, 04 Apr 2026 11:45:17 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Economics]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Tecnologia]]></category>
		<category><![CDATA[AgenticAI]]></category>
		<category><![CDATA[openclaw]]></category>
		<category><![CDATA[OpenSourceModel]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2260</guid>

					<description><![CDATA[**Read Time:** 12 minutes ## TL;DR AI should elevate people, not eliminate them. Every employee with AI becomes a superhuman: faster, smarter, more capable. Yet some companies are choosing mass layoffs instead of empowerment, and AI providers are making the &#8230; <a href="https://simonroses.com/2026/04/ai-must-make-superhumans-not-unemployed-the-case-against-layoffs-and-unaffordable-agents/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/04/ai-must-make-superhumans-not-unemployed-the-case-against-layoffs-and-unaffordable-agents/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2260</post-id>	</item>
		<item>
		<title>Moltbook: When AI Agents Build Their Own Social Network, What Could Go Wrong?</title>
		<link>https://simonroses.com/2026/03/moltbook-when-ai-agents-build-their-own-social-network-what-could-go-wrong/</link>
					<comments>https://simonroses.com/2026/03/moltbook-when-ai-agents-build-their-own-social-network-what-could-go-wrong/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Fri, 27 Mar 2026 10:14:51 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Pentest]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[AgenticAI]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[openclaw]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Software Security]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2254</guid>

					<description><![CDATA[**Read Time:** 14 minutes ## TL;DR [Moltbook](https://www.moltbook.com/) bills itself as &#8220;A Social Network for AI Agents&#8221;—a platform where autonomous agents post content, share skills, upvote, comment, and interact with each other. Think Reddit, but every user is an AI agent. &#8230; <a href="https://simonroses.com/2026/03/moltbook-when-ai-agents-build-their-own-social-network-what-could-go-wrong/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/03/moltbook-when-ai-agents-build-their-own-social-network-what-could-go-wrong/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2254</post-id>	</item>
		<item>
		<title>Professional Vibe Coding vs. Vibe Coding: Why Developers Should Embrace It (On Their Own Terms)</title>
		<link>https://simonroses.com/2026/03/professional-vibe-coding-vs-vibe-coding-why-developers-should-embrace-it-on-their-own-terms/</link>
					<comments>https://simonroses.com/2026/03/professional-vibe-coding-vs-vibe-coding-why-developers-should-embrace-it-on-their-own-terms/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Thu, 05 Mar 2026 07:36:34 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Pentest]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Threat Modeling]]></category>
		<category><![CDATA[ai-security]]></category>
		<category><![CDATA[AppSec]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<category><![CDATA[ProfessionalVibeCoding]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[VibeCoding]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2248</guid>

					<description><![CDATA[**Read Time:** 10 minutes ## TL;DR Vibe coding (letting AI generate entire applications from natural language prompts) has exploded in popularity. For non-coders, it is a revolution: suddenly anyone can build software. But the conversation usually stops there, as if &#8230; <a href="https://simonroses.com/2026/03/professional-vibe-coding-vs-vibe-coding-why-developers-should-embrace-it-on-their-own-terms/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/03/professional-vibe-coding-vs-vibe-coding-why-developers-should-embrace-it-on-their-own-terms/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2248</post-id>	</item>
		<item>
		<title>AI Agent Skill Poisoning: The Supply Chain Attack You Haven&#8217;t Heard Of</title>
		<link>https://simonroses.com/2026/02/ai-agent-skill-poisoning-the-supply-chain-attack-you-havent-heard-of/</link>
					<comments>https://simonroses.com/2026/02/ai-agent-skill-poisoning-the-supply-chain-attack-you-havent-heard-of/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Thu, 26 Feb 2026 06:59:44 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Pentest]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[agent-security]]></category>
		<category><![CDATA[ai-security]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[openclaw]]></category>
		<category><![CDATA[pentesting]]></category>
		<category><![CDATA[Skill]]></category>
		<category><![CDATA[supply-chain]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2237</guid>

					<description><![CDATA[**Read Time:** 15 minutes ## TL;DR Security professionals are well acquainted with npm supply chain attacks, PyPI package poisoning, and the infamous [xz backdoor](https://en.wikipedia.org/wiki/XZ_Utils_backdoor). But a new attack vector is emerging that flies under the radar—one that is arguably more &#8230; <a href="https://simonroses.com/2026/02/ai-agent-skill-poisoning-the-supply-chain-attack-you-havent-heard-of/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/02/ai-agent-skill-poisoning-the-supply-chain-attack-you-havent-heard-of/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2237</post-id>	</item>
	</channel>
</rss>
