Notícias
Notícias
5 min de leitura
5 de outubro de 2026

Seus agents transmitem dados em MITM sem saber. Vulnerabilidade real.

Xray-core certificate verification bypass exposes agents to MITM attacks. Your agent data = intercepted. Supply chain security = now critical.

Equipe OpenClaw

Equipe OpenClaw · Time de Engenharia & Produto

A Equipe OpenClaw é formada por engenheiros, designers e especialistas em IA dedicados a construir a melhor plataforma de agentes conversacionais para negócios brasileiros. Combinamos expertise…


Seus agents transmitem dados em MITM sem saber. Vulnerabilidade real.

Ontem vulnerabilidade importante descoberta: Xray-core certificate verification bypass.

"Xray-core library (used by agents/infrastructure) has hidden vulnerability: Skips certificate verification (man-in-the-middle attack possible). Translation: Your agent conversations = can be intercepted. Customer data = exposed. You don't know it's happening."

What this means: Your agents might be transmitting data over compromised connections.

Why it matters: Agent conversations contain sensitive customer data (personal info, payment data, business secrets). MITM attacks = data theft.

Problem it reveals: Founders think "agent = uses standard security." Wrong. Open-source dependencies = hidden vulnerabilities.

Você é founder.

Current reality (2026 - Agents with unverified certificate chains):

YOUR CURRENT AGENT SECURITY (Vulnerable to MITM attacks):

├─ What the Xray-core vulnerability reveals: │ ├─ Library: Xray-core (network proxy/tunneling library) │ ├─ Vulnerability: Certificate verification bypass (skips SSL/TLS checks) │ ├─ Impact: Man-in-the-middle attacks possible (attacker intercepts traffic) │ ├─ Severity: Critical (affects all agents using Xray-core) │ ├─ Discovery: Recently disclosed (hidden vulnerability) │ ├─ Status: Unfixed (patch pending) │ └─ Your exposure: If agents depend on Xray-core, you're vulnerable │ ├─ How MITM attack works (against your agents): │ ├─ Normal agent connection (secure): │ │ ├─ Customer message → Agent → API → Response │ │ ├─ Encryption: TLS certificate verified │ │ ├─ Protection: Encrypted end-to-end │ │ └─ Safety: Data cannot be intercepted │ │ │ ├─ MITM attack (with Xray-core vulnerability): │ │ ├─ Customer message → Attacker intercepts │ │ ├─ Attacker pretends to be API (fake certificate) │ │ ├─ Xray-core: Skips certificate verification (vulnerability) │ │ ├─ Agent: Sends data to attacker (thinks it's API) │ │ ├─ Attacker: Reads all agent data (unencrypted in transit) │ │ ├─ Attacker: Can modify responses (inject malicious content) │ │ ├─ Customer: Receives compromised agent response │ │ └─ Result: Complete data compromise (customer doesn't know) │ │ │ ├─ Vulnerability details: │ │ ├─ Root cause: Certificate verification disabled (or skipped) │ │ ├─ Why it happened: Development shortcut (testing convenience) │ │ ├─ Impact: ANY attacker on network = can intercept │ │ ├─ Scale: Network attacker (ISP, WiFi, cloud provider) │ │ ├─ Detection: Victim has NO WAY to know (silent interception) │ │ └─ Danger: Extremely high (invisible breach) │ │ │ └─ Your agents' vulnerability: │ ├─ If using Xray-core: Direct vulnerability (high risk) │ ├─ If using dependency of Xray: Transitive vulnerability (medium risk) │ ├─ If using similar pattern: Same vulnerability (moderate risk) │ ├─ Question: Do you know what libraries your agents depend on? │ └─ Answer: Most founders don't (supply chain blind spot) │ ├─ SUPPLY CHAIN RISK (The broader problem): │ ├─ Your agent dependency chain: │ │ ├─ Your agent code │ │ ├─ Direct dependencies (you chose these) │ │ ├─ Transitive dependencies (dependencies' dependencies) │ │ ├─ Deep transitive (dependencies of dependencies of dependencies) │ │ └─ Total: Hundreds or thousands of libraries (you don't control) │ │ │ ├─ Risk at each level: │ │ ├─ Direct dependencies: You chose them (some responsibility) │ │ ├─ Transitive: Inherited vulnerabilities (you don't know about) │ │ ├─ Deep transitive: Hidden vulnerabilities (complete blindness) │ │ ├─ Abandoned libraries: No longer maintained (unfixed vulnerabilities) │ │ └─ Malicious injection: Someone adds backdoor to library │ │ │ ├─ Xray-core example: │ │ ├─ Library: Xray-core (network tunneling) │ │ ├─ Popularity: Used by many projects (widespread risk) │ │ ├─ Vulnerability: Certificate bypass (critical) │ │ ├─ Discovery: Recent (was hidden for years) │ │ ├─ Impact: All projects using Xray = potentially compromised │ │ ├─ Your question: "Are my agents using Xray-core?" │ │ ├─ Your honest answer: "I don't know" │ │ └─ Danger: Complete supply chain blindness │ │ │ ├─ Scale of the problem: │ │ ├─ npm ecosystem: 1.5 million packages (JavaScript) │ │ ├─ Python PyPI: 500K packages │ │ ├─ RubyGems: 200K packages │ │ ├─ Total: Millions of libraries │ │ ├─ Vulnerabilities found annually: Thousands (growing) │ │ ├─ Vulnerability disclosure rate: Maybe 30% (most stay hidden) │ │ ├─ Average agent codebase: 200+ dependencies │ │ ├─ Your risk: Statistically, at least 1-2 vulnerabilities in your stack │ │ └─ Your visibility: Near zero (you're not auditing) │ │ │ └─ Why this matters for agents: │ ├─ Agent = trusted with customer data │ ├─ Agent vulnerability = customer breach │ ├─ Customer breach = your liability (LGPD, GDPR, compliance) │ ├─ Xray vulnerability = silent data theft (months undetected) │ ├─ Silent theft = worst case scenario (regulatory + customer trust) │ └─ Your exposure: Existential risk (if compromised = company damage) │ ├─ DATA AT RISK (What attackers can steal from your agents): │ ├─ Customer conversations: │ │ ├─ Personal information (name, email, phone, address) │ │ ├─ Business secrets (project details, strategy, pricing) │ │ ├─ Payment data (if agent processes transactions) │ │ ├─ Authentication tokens (if agent handles logins) │ │ ├─ API keys (if agent stores credentials) │ │ └─ Sensitive documents (if agent processes files) │ │ │ ├─ Internal agent data: │ │ ├─ System prompts (reveals agent behavior + limitations) │ │ ├─ Training data (intellectual property) │ │ ├─ Internal APIs (attacker maps system architecture) │ │ ├─ Database connections (attacker gains database access) │ │ └─ Cloud credentials (attacker compromises infrastructure) │ │ │ ├─ Attacker capabilities (with intercepted data): │ │ ├─ Impersonation: Pretend to be customer (replay messages) │ │ ├─ Fraud: Submit fake requests using customer data │ │ ├─ Blackmail: Threaten customer with exposed data │ │ ├─ Sabotage: Modify agent responses (inject malicious content) │ │ ├─ Sell data: Auction customer data on dark web │ │ └─ Ransomware: Encrypt data + demand payment │ │ │ ├─ Your liability: │ │ ├─ LGPD (Brazil): Data breach notification required (30 days) │ │ ├─ GDPR (EU): Data breach notification required (72 hours) │ │ ├─ SEC (US): Material breach disclosure required │ │ ├─ Fine: 2-4% of revenue (LGPD) or 4-20M EUR (GDPR) │ │ ├─ Customer lawsuits: Potential damages (class action risk) │ │ ├─ Insurance: Claims might not cover ("knew about vulnerability") │ │ └─ Reputation: "Company knew about risk, didn't fix it" │ │ │ └─ Xray-core specific threat: │ ├─ Vulnerability: Certificate bypass (easy to exploit) │ ├─ Detection: Hard to discover (silent interception) │ ├─ Exploitation: Low technical barrier (any network attacker can do it) │ ├─ Duration: Could be months before discovery │ ├─ Scale: If agents exposed, ALL customer data at risk │ ├─ Spread: Attacker can pivot to other systems (lateral movement) │ └─ Nightmare: Worst-case security scenario (silent + widespread) │ ├─ HOW TO FIND XRAY-CORE VULNERABILITY IN YOUR AGENTS: │ ├─ Step 1: Identify dependencies │ │ ├─ Command (JavaScript): npm list (show all dependencies) │ │ ├─ Command (Python): pip list (show all packages) │ │ ├─ Command (Ruby): bundle list (show all gems) │ │ ├─ Output: Full dependency tree (direct + transitive) │ │ ├─ Look for: xray-core, xray, x-ray (different naming variations) │ │ ├─ Goal: Confirm if Xray-core is in your stack │ │ └─ If found: You're vulnerable (immediate action needed) │ │ │ ├─ Step 2: Check for transitive dependencies │ │ ├─ Direct check: Does your code explicitly import xray-core? (No = maybe safe) │ │ ├─ Transitive check: Do your dependencies use xray-core? (Yes = still vulnerable) │ │ ├─ Tool: npm audit (JavaScript vulnerability scanner) │ │ ├─ Tool: pip-audit (Python vulnerability scanner) │ │ ├─ Tool: bundle audit (Ruby vulnerability scanner) │ │ ├─ Tool: snyk.io (universal vulnerability scanner) │ │ ├─ Action: Run scanner on your agent codebase │ │ └─ Output: List of known vulnerabilities (Xray-core included if present) │ │ │ ├─ Step 3: Check vulnerability databases │ │ ├─ CVE (Common Vulnerabilities + Exposures): cve.mitre.org │ │ ├─ NVD (National Vulnerability Database): nvd.nist.gov │ │ ├─ GitHub Security Advisory: github.com/advisories │ │ ├─ Snyk Vulnerability DB: snyk.io/vulnerability-scanner │ │ ├─ Search: "Xray-core certificate bypass" OR "Xray-core CVE" │ │ ├─ Find: Vulnerability details + severity + fix │ │ └─ Action: If listed as "critical" = emergency patch │ │ │ ├─ Step 4: Assess your risk │ │ ├─ Question 1: Does agent transmit sensitive data? (Yes = high risk) │ │ ├─ Question 2: Is agent exposed to untrusted networks? (Yes = high risk) │ │ ├─ Question 3: Are agents customer-facing? (Yes = high risk) │ │ ├─ Question 4: How long until detected if compromised? (Weeks = high risk) │ │ ├─ Score: If 3+ yes = critical risk (patch immediately) │ │ ├─ Score: If 2+ yes = high risk (patch this week) │ │ ├─ Score: If 1+ yes = moderate risk (patch this month) │ │ └─ Score: If 0 = low risk (patch on schedule) │ │ │ └─ Step 5: Take action │ ├─ Option 1: Patch library (update to fixed version) │ │ ├─ Command: npm update xray-core (if fix available) │ │ ├─ Verify: npm audit (confirm vulnerability gone) │ │ ├─ Test: Run test suite (ensure no regressions) │ │ ├─ Deploy: Push to production (roll out fix) │ │ └─ Timeline: Same day (critical patches don't wait) │ │ │ ├─ Option 2: Replace library (remove xray-core dependency) │ │ ├─ Find: Alternative library (with same functionality) │ │ ├─ Migrate: Rewrite code to use alternative │ │ ├─ Test: Full regression testing (major change) │ │ ├─ Deploy: Staged rollout (reduce risk) │ │ └─ Timeline: 1-2 weeks (more involved) │ │ │ ├─ Option 3: Isolate (disable vulnerable feature) │ │ ├─ Scope: Disable Xray-core in agent (temporary) │ │ ├─ Impact: Some functionality might break (acceptable?) │ │ ├─ Deploy: Immediate (emergency fix) │ │ ├─ Plan: Permanent fix in Option 1 or 2 │ │ └─ Timeline: Today (emergency measure) │ │ │ └─ Recommended: Option 1 (patch) + immediate deployment │ ├─ Reason: Fastest fix (if patch available) │ ├─ Testing: Minimal (patch should be safe) │ ├─ Timing: Deploy same day │ ├─ Verification: Run audit to confirm fix │ └─ Next: Monitor for additional vulnerabilities │ ├─ ZERO-TRUST SECURITY FOR AGENTS (Prevention for future): │ ├─ What zero-trust means: │ │ ├─ Assumption: Don't trust anything by default │ │ ├─ Verification: Verify every request/connection │ │ ├─ Encryption: Assume network is compromised │ │ ├─ Least privilege: Give minimum necessary access │ │ ├─ Audit: Log everything (detect compromise) │ │ └─ Response: Detect + isolate threats (minimize damage) │ │ │ ├─ Zero-trust for agent infrastructure: │ │ ├─ Certificate pinning: Agent verifies exact certificate (not just valid) │ │ │ ├─ How: Hardcode expected certificate hash in agent │ │ │ ├─ Protection: Attacker's fake cert always rejected │ │ │ ├─ Benefit: Prevents man-in-the-middle attacks │ │ │ ├─ Implementation: 5 lines of code (most languages) │ │ │ └─ Cost: Minimal (easy to implement) │ │ │ │ │ ├─ Mutual TLS: Agent verifies server, server verifies agent │ │ │ ├─ How: Both sides present certificates │ │ │ ├─ Protection: Only authorized agents can connect │ │ │ ├─ Benefit: Prevents unauthorized agents (stolen credentials) │ │ │ ├─ Implementation: Medium complexity (PKI setup) │ │ │ └─ Cost: Moderate (certificate infrastructure) │ │ │ │ │ ├─ Encrypted secrets: Never store credentials in code │ │ │ ├─ How: Vault/KMS stores secrets (accessed at runtime) │ │ │ ├─ Protection: Credentials not in source code │ │ │ ├─ Benefit: Stolen source code ≠ stolen credentials │ │ │ ├─ Implementation: Easy (most clouds support) │ │ │ └─ Cost: Low (built-in to cloud providers) │ │ │ │ │ ├─ Network segmentation: Agents isolated from untrusted networks │ │ │ ├─ How: VPC/firewall restricts agent communication │ │ │ ├─ Protection: Attacker can't intercept (no network access) │ │ │ ├─ Benefit: MITM attacks impossible (if network trusted) │ │ │ ├─ Implementation: Medium complexity (network setup) │ │ │ └─ Cost: Low-moderate (depends on architecture) │ │ │ │ │ ├─ Monitoring + alerting: Detect suspicious activity │ │ │ ├─ What to monitor: Certificate errors, failed TLS handshakes │ │ │ ├─ Alert on: Any certificate verification failure │ │ │ ├─ Protection: Catch MITM attacks quickly (reduces damage) │ │ │ ├─ Implementation: Easy (log parsing + alerting) │ │ │ └─ Cost: Low (standard security tools) │ │ │ │ │ └─ Incident response: Plan for compromise │ │ ├─ Assume: Agent traffic was compromised │ │ ├─ Action: Revoke all agent credentials (prevent replay) │ │ ├─ Action: Notify customers (data breach notification) │ │ ├─ Action: Audit all agent activity (find what was stolen) │ │ ├─ Action: Restore from backup (if data corrupted) │ │ └─ Cost: High (but lower than unplanned breach) │ │ │ ├─ Implementation priority: │ │ ├─ Week 1: Fix Xray-core vulnerability (emergency) │ │ ├─ Week 2-3: Implement certificate pinning (quick win) │ │ ├─ Week 4-6: Set up monitoring + alerts (detect attacks) │ │ ├─ Week 7-8: Implement mutual TLS (medium effort) │ │ ├─ Week 9-12: Network segmentation (longer project) │ │ ├─ Ongoing: Security audits + dependency scanning │ │ └─ Goal: Zero-trust agent infrastructure (by Q1 2027) │ │ │ └─ Cost-benefit: │ ├─ Implementation cost: R$ 50K-100K (engineering effort) │ ├─ Operational cost: R$ 5K-10K/month (tools + monitoring) │ ├─ Benefit: Prevent R$ 500K-5M breach (customer trust + legal) │ ├─ ROI: 50-100x (if prevents one breach) │ ├─ Timeline: 12 weeks (phased approach) │ └─ Priority: Critical (essential for agent security) │ ├─ SUPPLY CHAIN SECURITY PROCESS (Ongoing vulnerability management): │ ├─ Immediate (This week): │ │ ├─ [ ] Scan dependencies for vulnerabilities (npm audit / snyk) │ │ ├─ [ ] Check for Xray-core specifically (manual verification) │ │ ├─ [ ] Assess risk (customer data exposure?) │ │ ├─ [ ] Patch or replace vulnerable libraries │ │ ├─ [ ] Deploy patches to production │ │ └─ [ ] Verify fixes (audit confirms clean) │ │ │ ├─ Short-term (This month): │ │ ├─ [ ] Document all dependencies (create SBOM) │ │ ├─ [ ] Identify outdated libraries (>1 year old) │ │ ├─ [ ] Update dependencies (systematic approach) │ │ ├─ [ ] Set up automated scanning (CI/CD integration) │ │ ├─ [ ] Configure alerts (vulnerability notifications) │ │ ├─ [ ] Train team on vulnerability response │ │ └─ [ ] Document incident response plan │ │ │ ├─ Medium-term (This quarter): │ │ ├─ [ ] Implement certificate pinning (all agents) │ │ ├─ [ ] Enable mutual TLS (if applicable) │ │ ├─ [ ] Set up monitoring + alerting (TLS errors) │ │ ├─ [ ] Regular penetration testing (find vulnerabilities) │ │ ├─ [ ] Security training for developers (awareness) │ │ └─ [ ] Audit third-party dependencies (vet suppliers) │ │ │ ├─ Long-term (This year): │ │ ├─ [ ] Network segmentation (agents isolated) │ │ ├─ [ ] Encrypted secrets management (vault/KMS) │ │ ├─ [ ] Zero-trust architecture (verify everything) │ │ ├─ [ ] Regular security audits (third-party validation) │ │ ├─ [ ] Compliance certification (SOC2, ISO27001) │ │ ├─ [ ] Incident response drills (test readiness) │ │ └─ [ ] Continuous monitoring (24/7 threat detection) │ │ │ └─ Tools to use: │ ├─ Vulnerability scanning: npm audit, snyk, trivy │ ├─ Dependency management: Dependabot, Renovate │ ├─ Supply chain security: OWASP Dependency-Check │ ├─ Secrets management: HashiCorp Vault, AWS Secrets Manager │ ├─ Monitoring: ELK stack, Datadog, New Relic │ └─ Testing: OWASP ZAP, Burp Suite (penetration testing) │ └─ THE BOTTOM LINE: ├─ Xray-core vulnerability: Critical (certificate verification bypass) ├─ Your exposure: Unknown (most founders don't know dependencies) ├─ Risk: Silent data theft (MITM attacks undetectable) ├─ Liability: Regulatory fines + customer lawsuits ├─ Timeline: Check for vulnerability THIS WEEK ├─ Action: Patch or replace immediately (if present) ├─ Prevention: Implement zero-trust security (ongoing) ├─ Cost: R$ 50K-100K (vs. R$ 500K-5M breach) ├─ Timeline: 12 weeks to full zero-trust (phased) └─ Advantage: Early movers with zero-trust = secure agents


Xray-core vulnerability exposes agent data. MITM attacks possible.

What the vulnerability means

Xray-core (library used by agents) skips certificate verification.

Translation: Attacker intercepts agent connection (pretends to be API). Agent doesn't verify identity (vulnerability). Attacker reads all agent data (customer info, secrets, payments).

Your exposure: If agents use Xray-core, data is compromised.

Timeline: You don't know how long it's been happening (silent interception).


Supply chain risk = your biggest security blind spot

Dependency analysis

Your agent codebase depends on:

  • Direct libraries (you chose these): ~10-50
  • Transitive dependencies (~dependencies' dependencies): ~100-200
  • Deep transitive (unknown layers): ~50-100
  • Total: 200-400 libraries (you don't control)

Risk: At least 1-2 critical vulnerabilities hidden in your stack (statistically)

Visibility: Near zero (most founders can't name 10% of dependencies)

Xray-core example: One library, one vulnerability, affects all agents using it


Conclusion: Xray-core proves supply chain risk is real. Zero-trust security = now essential.

Latest developments show open-source dependencies are attack vector for agent compromise.

Translation: You must know your dependencies. You must scan for vulnerabilities. You must verify certificates.

Why zero-trust matters:

  • Xray vulnerability = silent MITM possible
  • Certificate pinning = stops this attack (5 lines of code)
  • Monitoring = detects compromise quickly
  • Incident response = limits damage
  • Compliance = proves you tried (legal defense)

What to do:

  1. Scan dependencies for vulnerabilities (npm audit / snyk)
  2. Check for Xray-core specifically (search dependencies)
  3. Assess risk (customer data exposed?)
  4. Patch or replace vulnerable library (immediate)
  5. Deploy patches to production (same day)
  6. Implement certificate pinning (prevent MITM)
  7. Set up monitoring (detect suspicious activity)
  8. Plan zero-trust security (phased over 12 weeks)
  9. Train team on vulnerability response
  10. Audit third-party dependencies regularly

Estimated cost (immediate patch): R$ 5K-10K (1-2 days engineering)

Estimated cost (zero-trust): R$ 50K-100K (12-week project)

Estimated cost (breach if not fixed): R$ 500K-5M (customer + legal + compliance)

Smart founders auditing dependencies this week. Average founders fixing after disclosure (reactive). Lazy founders ignoring vulnerability (exposed). Choose your path: Proactive security or reactive breach.


Stop ignoring supply chain risk. Start scanning dependencies.

If agent security matters (and it does), the question is: How do you actually know what vulnerabilities are hiding in your agent dependencies without becoming a security expert?

Supply chain security requires:

  • Dependency inventory (what libraries are you using?)
  • Vulnerability scanning (automated detection)
  • Risk assessment (which vulnerabilities matter most?)
  • Patch management (keep libraries updated)
  • Certificate verification (prevent MITM attacks)
  • Monitoring + alerting (detect intrusions)
  • Incident response (plan for compromise)
  • Third-party audits (validate security)
  • Compliance documentation (prove due diligence)
  • Team training (security awareness)
  • Continuous reassessment (vulnerabilities evolving)
  • Regulatory preparation (LGPD/GDPR breach notification)

OpenClaw helps you secure agents against supply chain attacks:

  • Dependency inventory setup (SBOM creation)
  • Vulnerability scanning integration (automated + continuous)
  • Risk prioritization (which vulnerabilities to fix first)
  • Patch management workflow (coordinated updates)
  • Certificate pinning implementation (prevent MITM)
  • TLS monitoring + alerting (detect attacks)
  • Incident response planning (minimize breach damage)
  • Compliance documentation (prove due diligence)
  • Third-party audit coordination (independent validation)
  • Team training program (security awareness)
  • Continuous scanning (keep ahead of vulnerabilities)
  • Regulatory readiness (LGPD/GDPR preparation)

Start scanning dependencies → OpenClaw AI Agent Supply Chain Security Framework

Because Xray-core proves it. Hidden vulnerabilities exist in your dependencies. MITM attacks possible against unsecured agents. Early movers implement zero-trust (prevent attacks). Late movers discover breach post-facto (damage control). You have 1 week to audit dependencies. Start scanning today. Fix critical vulnerabilities this week. Implement zero-trust over next 12 weeks. Secure agents = protected customer data = avoided breach = competitive advantage. Vulnerable agents = customer data stolen = regulatory fines = brand damage = customer loss. Audit now. Secure now. Lead market.


Publicado em 5 de outubro de 2026

Leia também