The 2026 Threat Landscape — Use Cases, Damage Categories & Protection Protocols
March 15, 2026 · Research Brief · 40 Sources
Open-source AI agent framework — 180K+ GitHub stars in 3 weeks, Feb 2026
When "vibe coding" goes dark — AI-orchestrated cyberattacks by non-coders
45% of AI-generated code has vulnerabilities (Veracode) · 80% of 2025 ransomware used AI (MIT Sloan)
17 real-world use cases categorized by legality and ethics
Direct criminal activity causing immediate harm
Laws broken, but motivations may be defensible (activism, whistleblowing, anti-censorship)
Violates platform ToS, community norms, or professional ethics — not laws
Pushes guidelines but serves legitimate purposes — security research, journalism, defense
Legitimate use — the risk comes from negligence, misconfiguration, and lack of awareness
How the attacks actually work — from prompt injection to memory poisoning
OpenClaw has documented incidents in ALL 10 categories
| # | Risk Category | OpenClaw Example | Tier | Severity |
|---|---|---|---|---|
| 1 | Goal Misalignment | Agent executes unintended actions autonomously | WHITE | HIGH |
| 2 | Tool Misuse | Terminal commands, file system access exploited | BLACK | CRITICAL |
| 3 | Delegated Trust | Skills from ClawHub trusted without verification | BLACK | CRITICAL |
| 4 | Inter-Agent Communication | Cross-platform agent impersonation via Slack | BLACK | CRITICAL |
| 5 | Persistent Memory Exploit | SOUL.md poisoning via crafted emails/docs | BLACK | CRITICAL |
| 6 | Emergent Behavior | Agent acts beyond intended scope unsupervised | D.GREY | HIGH |
| 7 | Prompt Injection | CVE-2026-25253, log poisoning, email injection | BLACK | CRITICAL |
| 8 | Insufficient Monitoring | No audit trail on 30K+ exposed instances | WHITE | HIGH |
| 9 | Excessive Permissions | Full system access by default, no least-privilege | WHITE | CRITICAL |
| 10 | Supply Chain Compromise | 1,184 malicious skills, Cline CLI backdoor | BLACK | CRITICAL |
40 sources · 17 use cases · 5 threat tiers · Full research brief available
March 15, 2026 · White-hat cybersurveillance education