<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>One Man Ops Blog</title>
    <link>https://onemanops.com</link>
    <description>Guides, operating notes, and practical OpenClaw deployment articles from One Man Ops.</description>
    <language>en-us</language>
    <lastBuildDate>Sat, 04 Apr 2026 14:12:38 GMT</lastBuildDate>
    <item>
      <title><![CDATA[CVE-2026-33579: What "Assume Compromise" Actually Means for OpenClaw Users]]></title>
      <link>https://onemanops.com/blog/cve-2026-33579-what-assume-compromise-actually-means-for-openclaw-users</link>
      <guid>https://onemanops.com/blog/cve-2026-33579-what-assume-compromise-actually-means-for-openclaw-users</guid>
      <pubDate>Sat, 04 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[CVE-2026-33579 let low-privilege OpenClaw users escalate to admin. If you're below v2026.3.28, patch now and review access.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[A Leaked npm Package Turned Into a RAT Backdoor in Three Hours]]></title>
      <link>https://onemanops.com/blog/a-leaked-npm-package-turned-into-a-rat-backdoor-in-three-hours</link>
      <guid>https://onemanops.com/blog/a-leaked-npm-package-turned-into-a-rat-backdoor-in-three-hours</guid>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[A leaked Claude Code npm package exposed source code, then shipped trojanized axios versions—showing how fast an AI tool can become supply-chain risk.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[ClaudeClaw vs. OpenClaw: What's Actually Different]]></title>
      <link>https://onemanops.com/blog/claudeclaw-vs-openclaw-whats-actually-different</link>
      <guid>https://onemanops.com/blog/claudeclaw-vs-openclaw-whats-actually-different</guid>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[ClaudeClaw is Claude Code used for automation. OpenClaw is a self-hosted automation platform. The difference is speed versus control.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[CVE-2026-22172: Any OpenClaw User Could Become Admin]]></title>
      <link>https://onemanops.com/blog/cve-2026-22172-openclaw-websocket-admin-escalation</link>
      <guid>https://onemanops.com/blog/cve-2026-22172-openclaw-websocket-admin-escalation</guid>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Any authenticated OpenClaw user could escalate to admin during the WebSocket handshake. The fix is in v2026.3.12.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[CVE-2026-32922: One API Call Hands Over Your Entire OpenClaw Gateway]]></title>
      <link>https://onemanops.com/blog/cve-2026-32922-openclaw-token-scope-privilege-escalation</link>
      <guid>https://onemanops.com/blog/cve-2026-32922-openclaw-token-scope-privilege-escalation</guid>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[A low-privilege OpenClaw token could rotate itself into a full admin token in one API call. The fix is in v2026.3.11.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[CVE-2026-34503: You Removed the Device — It's Still Connected]]></title>
      <link>https://onemanops.com/blog/cve-2026-34503-openclaw-session-persistence</link>
      <guid>https://onemanops.com/blog/cve-2026-34503-openclaw-session-persistence</guid>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Removing a device from OpenClaw did not kill its active session. Affected versions kept the revoked device connected until the WebSocket dropped.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Langflow CVE-2026-33017: CISA KEV April 8 Deadline]]></title>
      <link>https://onemanops.com/blog/langflow-cve-2026-33017-cisa-kev-april-8-deadline</link>
      <guid>https://onemanops.com/blog/langflow-cve-2026-33017-cisa-kev-april-8-deadline</guid>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[CISA added Langflow CVE-2026-33017 to the KEV catalog, confirming active exploitation and setting an April 8 patch deadline for federal agencies.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[What Is OpenClaw — and Why Are OpenAI, Meta, and Google Circling It?]]></title>
      <link>https://onemanops.com/blog/what-is-openclaw-and-why-openai-meta-google-circling-it</link>
      <guid>https://onemanops.com/blog/what-is-openclaw-and-why-openai-meta-google-circling-it</guid>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[OpenClaw is becoming foundational AI agent infrastructure. OpenAI hired its creator, Meta acquired around the ecosystem, and developer education outlets are now teaching it as a core platform.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[2026 Platform Decision Guide for AI Educators]]></title>
      <link>https://onemanops.com/blog/2026-platform-decision-guide-for-ai-educators</link>
      <guid>https://onemanops.com/blog/2026-platform-decision-guide-for-ai-educators</guid>
      <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Stan Store leads on pure fee economics, Whop adds marketplace discovery, and Skool or Circle fit community-first models depending on your growth stage.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Claude Code Source Leak: Undercover Mode]]></title>
      <link>https://onemanops.com/blog/claude-code-source-leak-undercover-mode</link>
      <guid>https://onemanops.com/blog/claude-code-source-leak-undercover-mode</guid>
      <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Anthropic accidentally exposed Claude Code source showing an "Undercover Mode" that strips AI attribution from open-source contributions.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Claude Mythos: Anthropic Confirms an Above-Opus Model Class]]></title>
      <link>https://onemanops.com/blog/claude-mythos-explainer-anthropic-confirms-above-opus-model-class</link>
      <guid>https://onemanops.com/blog/claude-mythos-explainer-anthropic-confirms-above-opus-model-class</guid>
      <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Anthropic confirmed it is developing a model class above Claude Opus 4.6. The model exists; the leaked performance claims do not yet have independent verification.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Claude Persistent Memory Live for All Claude.ai Users]]></title>
      <link>https://onemanops.com/blog/claude-persistent-memory-live-for-all-claude-ai-users</link>
      <guid>https://onemanops.com/blog/claude-persistent-memory-live-for-all-claude-ai-users</guid>
      <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Anthropic has rolled out persistent memory to all Claude.ai users, letting Claude retain user preferences, role, and context across separate conversations.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[GitHub Copilot Data Training Opt-Out: April 24 Deadline]]></title>
      <link>https://onemanops.com/blog/github-copilot-data-training-opt-out-april-24-deadline</link>
      <guid>https://onemanops.com/blog/github-copilot-data-training-opt-out-april-24-deadline</guid>
      <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[GitHub will start using Copilot Free, Pro, and Pro+ interaction data to train AI models on April 24, 2026 unless users opt out first.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Claude Channels Shipped With Its Own Injection Warning]]></title>
      <link>https://onemanops.com/blog/claude-channels-shipped-with-its-own-injection-warning</link>
      <guid>https://onemanops.com/blog/claude-channels-shipped-with-its-own-injection-warning</guid>
      <pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Anthropic shipped Claude Channels with an explicit prompt-injection warning. The transport may be secure, but the permission model still defines the real risk.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Jensen Huang Says AGI Is Here. ARC-AGI-3 Says Otherwise.]]></title>
      <link>https://onemanops.com/blog/jensen-huang-says-agi-is-here-arc-agi-3-says-otherwise</link>
      <guid>https://onemanops.com/blog/jensen-huang-says-agi-is-here-arc-agi-3-says-otherwise</guid>
      <pubDate>Mon, 30 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Jensen Huang said AGI is here. ARC-AGI-3 benchmark results released days later show frontier models still fail badly on novel reasoning tasks.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Seven Security Flaws in 23 Days — What Every OpenClaw User Needs to Do Right Now]]></title>
      <link>https://onemanops.com/blog/openclaw-safety-essentials-seven-security-flaws-in-23-days</link>
      <guid>https://onemanops.com/blog/openclaw-safety-essentials-seven-security-flaws-in-23-days</guid>
      <pubDate>Sun, 29 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[OpenClaw has taken seven disclosed security hits in 23 days. Here is what matters, what categories of exposure repeat, and what operators should do immediately.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[OpenClaw vs. Claude Dispatch: What Actually Changed]]></title>
      <link>https://onemanops.com/blog/openclaw-vs-claude-dispatch-what-actually-changed</link>
      <guid>https://onemanops.com/blog/openclaw-vs-claude-dispatch-what-actually-changed</guid>
      <pubDate>Sat, 28 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Managed mobile-first agents did not make self-hosted agents obsolete. The real difference is trust model, control, and where your data lives.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Your AI Agent Got Hacked and You Didn't Click Anything]]></title>
      <link>https://onemanops.com/blog/your-ai-agent-got-hacked-and-you-didnt-click-anything</link>
      <guid>https://onemanops.com/blog/your-ai-agent-got-hacked-and-you-didnt-click-anything</guid>
      <pubDate>Sat, 28 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Zero-click prompt injection is no longer theoretical. Here is what Bargury demonstrated, why MCP makes the problem structural, and what operators should change right now.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Apple Is Putting Google AI Inside Siri — Here's What It Means for You]]></title>
      <link>https://onemanops.com/blog/apple-is-putting-google-ai-inside-siri-heres-what-it-means-for-you</link>
      <guid>https://onemanops.com/blog/apple-is-putting-google-ai-inside-siri-heres-what-it-means-for-you</guid>
      <pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Apple is expected to route more complex Siri requests through Google Gemini. That could make Siri much more capable, but it also changes the data path behind your iPhone assistant.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[NoteSmith Case Study: $5K Revenue Week One]]></title>
      <link>https://onemanops.com/blog/notesmith-case-study-5k-revenue-week-one</link>
      <guid>https://onemanops.com/blog/notesmith-case-study-5k-revenue-week-one</guid>
      <pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[What the NoteSmith launch model gets right: one pain point, immediate value, gated continued access, and distribution through an existing audience.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[AI Agent Security: OpenClaw-Specific — CVEs, Defaults, and What to Fix]]></title>
      <link>https://onemanops.com/blog/ai-agent-security-openclaw-specific-cves-defaults-and-what-to-fix</link>
      <guid>https://onemanops.com/blog/ai-agent-security-openclaw-specific-cves-defaults-and-what-to-fix</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Part 3 of the security series covering OpenClaw-specific vulnerabilities, exposure patterns, the ClawHub supply-chain issue, and the versions operators need to patch.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[AI Agent Security: Practical Hardening — How to Secure Your Agents]]></title>
      <link>https://onemanops.com/blog/ai-agent-security-practical-hardening-how-to-secure-your-agents</link>
      <guid>https://onemanops.com/blog/ai-agent-security-practical-hardening-how-to-secure-your-agents</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Part 2 of the security series covering per-agent credentials, scoped API keys, tool scoping, provider isolation, monitoring, and audit trails.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[AI Agent Security: The Threat Landscape — What's Actually Happening]]></title>
      <link>https://onemanops.com/blog/ai-agent-security-threat-landscape-whats-actually-happening</link>
      <guid>https://onemanops.com/blog/ai-agent-security-threat-landscape-whats-actually-happening</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Part 1 of a 3-part security series covering real AI agent incidents, current threat patterns, and the numbers operators should pay attention to.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[The Karpathy Loop: What Happens When AI Starts Running Its Own Experiments]]></title>
      <link>https://onemanops.com/blog/karpathy-loop-ai-running-its-own-experiments</link>
      <guid>https://onemanops.com/blog/karpathy-loop-ai-running-its-own-experiments</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[What Andrej Karpathy's autonomous experiment loop actually means, why Shopify's overnight replication matters, and how the same pattern could reshape business operations.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Vibe Coding: What It Actually Means That Anyone Can Build Software Now]]></title>
      <link>https://onemanops.com/blog/vibe-coding-anyone-can-build-software-now</link>
      <guid>https://onemanops.com/blog/vibe-coding-anyone-can-build-software-now</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Why vibe coding matters now, what non-technical operators can build with it today, and where human judgment still matters.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
  </channel>
</rss>