<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>munio — security research</title><description>Security research, vulnerability analysis, and guides from munio.</description><link>https://munio.dev/</link><item><title>We scanned 763 MCP servers. Here&apos;s what we found.</title><link>https://munio.dev/blog/mcp-server-security-scan-763/</link><guid isPermaLink="true">https://munio.dev/blog/mcp-server-security-scan-763/</guid><description>Most MCP servers ship with no input validation. A few have exploitable vulnerabilities. The real risk is in how tools combine.</description><pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Safety Control Tampering: A New Class of Attack on AI Agents</title><link>https://munio.dev/blog/safety-control-tampering-openclaw-rce/</link><guid isPermaLink="true">https://munio.dev/blog/safety-control-tampering-openclaw-rce/</guid><description>CVE-2026-25253 revealed a 1-click RCE in OpenClaw. We analyzed the attack chain and found a pattern that goes beyond this single vulnerability — attackers disabling safety controls before exploitation.</description><pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate></item></channel></rss>