<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Exploit Intel — exploit-intel</title><link>https://exploit-intel.com/blog/tags/exploit-intel/</link><description>EIP research articles tagged exploit-intel.</description><language>en-us</language><atom:link href="https://exploit-intel.com/blog/tags/exploit-intel/index.xml" rel="self" type="application/rss+xml"/><lastBuildDate>Mon, 16 Mar 2026 12:00:00 -0400</lastBuildDate><item><title>Six AI Agents, One Security Company: The Paperclip AI Experiment</title><link>https://exploit-intel.com/blog/posts/six-ai-agents-one-security-company-the-paperclip-experiment/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/six-ai-agents-one-security-company-the-paperclip-experiment/</guid><description>We used Paperclip AI to stand up a six-agent AI company that now runs our exploit research pipeline almost entirely on autopilot - CVE candidate selection, forge dispatch, results collection, and SEO all managed autonomously. A CEO, a security researcher, a software engineer, a QA reviewer, a research intern, and a pipeline operator - all AI agents. They refactored four codebases into a clean monorepo, hardened the security, and built the MCP tools that now let the whole chain run without us touching a terminal. Four days, 135 issues, $180. The $1.38 QA agent found a bypass in the $115 engineer's security fix. This is the full story of the Paperclip AI experiment.</description><pubDate>Mon, 16 Mar 2026 12:00:00 -0400</pubDate></item><item><title>CVE-2026-28391: OpenClaw Command Injection - The Day I Hacked Myself</title><link>https://exploit-intel.com/blog/posts/cve-2026-28391-openclaw-command-injection-the-day-i-hacked-myself/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cve-2026-28391-openclaw-command-injection-the-day-i-hacked-myself/</guid><description>CVE-2026-28391 is a CVSS 9.8 command injection in OpenClaw &lt; 2026.2.2, caused by a POSIX vs cmd.exe shell-parsing mismatch. Our own suggestion algorithm ranked it as the most interesting CVEForge target. 8/8 bypass vectors confirmed, code execution verified. This is the story of the day our orchestration layer dispatched a full vulnerability assessment against itself.</description><pubDate>Mon, 09 Mar 2026 12:00:00 -0400</pubDate></item><item><title>Introducing FuzzForge: Autonomous Source-Code Fuzzing - Finding Bugs in nginx in 112 Minutes</title><link>https://exploit-intel.com/blog/posts/introducing-fuzzforge-autonomous-source-fuzzing-nginx/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/introducing-fuzzforge-autonomous-source-fuzzing-nginx/</guid><description>We forked Shannon a third time. Seven AI agents, source code as the starting point, sanitizer-instrumented builds, and a pipeline that read 259 C files, built its own fuzzing harnesses, ran 18,000 iterations, and found a previously unknown FastCGI protocol desynchronization bug in nginx. Two hours. Twenty-five dollars.</description><pubDate>Sun, 08 Mar 2026 12:00:00 -0400</pubDate></item></channel></rss>
