#openclaw

[ follow ]
fromInfoWorld
5 hours ago

Compromised npm package silently installs OpenClaw on developer machines

Researchers have discovered that a compromised npm publish token pushed an update for the widely-used Cline command line interface (CLI) containing a malicious postinstall script. That script installs the wildly popular, but increasingly condemned, agentic application OpenClaw on the unsuspecting user's machine. This can be extremely dangerous, as OpenClaw has broad system access and deep integrations with messaging platforms including WhatsApp, Telegram, Slack, Discord, iMessage, Teams, and others.
Information security
fromTheregister
11 hours ago

Using a Raspberry Pi to run OpenClaw makes no sense

The viral AI personal assistant, formerly known as Clawdbot and Moltbot, has dominated the feeds of AI boosters over the past few weeks for its ability to perform everyday tasks like sending emails, managing calendars, booking appointments, and complaining about their meatbag masters on the purportedly all-agent forum known as MoltBook. More level-headed voices have already flagged a wave of security vulnerabilities.
Gadgets
#supply-chain-attack
Information security
fromThe Hacker News
20 hours ago

Cline CLI 2.3.0 Supply Chain Attack Installed OpenClaw on Developer Systems

Unauthorized npm update to Cline CLI (cline@2.3.0) installed OpenClaw via a postinstall script, affecting about 4,000 downloads during an eight-hour window on Feb 17, 2026.
Information security
fromArs Technica
1 day ago

OpenClaw security fears lead Meta, other AI firms to restrict its use

OpenClaw poses significant security risks; organizations must restrict access, mitigate exposures immediately, and test in controlled environments to identify vulnerabilities.
Information security
fromSecurityWeek
2 days ago

OpenClaw Security Issues Continue as SecureClaw Open Source Tool Debuts

OpenClaw is a widely used autonomous personal assistant with chronic security vulnerabilities despite rapid patches while transitioning into the OpenClaw Foundation with OpenAI support.
Apple
fromBusiness Insider
2 days ago

It's the Mac Mini's moment, thanks to the OpenClaw craze

Surging interest in locally run AI agent OpenClaw is driving high demand and weekslong wait times for higher-memory Mac Mini models.
#ai-agents
fromFortune
2 days ago
Artificial intelligence

Who is OpenClaw creator Peter Steinberger? The millennial developer caught the attention of Sam Altman and Mark Zuckerberg | Fortune

fromFortune
1 week ago
Artificial intelligence

Security experts are uneasy about OpenClaw, the bad boy of AI agents | Fortune

Artificial intelligence
fromFortune
2 weeks ago

Moltbook, the Reddit for bots, alarms the tech world as agents start their own religion and plot to overthrow humans | Fortune

Moltbook is a social network where AI agents interact publicly, raising excitement, skepticism, and security and safety concerns.
fromFortune
2 days ago
Artificial intelligence

Who is OpenClaw creator Peter Steinberger? The millennial developer caught the attention of Sam Altman and Mark Zuckerberg | Fortune

fromFortune
1 week ago
Artificial intelligence

Security experts are uneasy about OpenClaw, the bad boy of AI agents | Fortune

fromFortune
2 weeks ago
Artificial intelligence

Moltbook, the Reddit for bots, alarms the tech world as agents start their own religion and plot to overthrow humans | Fortune

#autonomous-ai-agents
fromFast Company
2 days ago
Artificial intelligence

These 6 quotes from OpenClaw creator Peter Steinberger hint at the future of personal computing

fromFast Company
2 days ago
Artificial intelligence

These 6 quotes from OpenClaw creator Peter Steinberger hint at the future of personal computing

#agentic-ai
fromWIRED
3 days ago
Artificial intelligence

Meta and Other Tech Companies Ban OpenClaw Over Cybersecurity Concerns

fromNature
2 weeks ago
Artificial intelligence

OpenClaw AI chatbots are running amok - these scientists are listening in

Information security
fromFast Company
2 weeks ago

Moltbook, the viral social network for AI agents, has a major security problem

OpenClaw's user-friendly agentic AI spurred widespread agent adoption and Moltbook's unsecured deployment exposed user data and private API keys.
Artificial intelligence
fromwww.bbc.com
2 weeks ago

What is the 'social media network for AI' Moltbook?

Moltbook: a Reddit-style network for AI agents to post, comment and form communities via agentic OpenClaw bots; human posting disabled, membership disputed.
fromWIRED
3 days ago
Artificial intelligence

Meta and Other Tech Companies Ban OpenClaw Over Cybersecurity Concerns

fromNature
2 weeks ago
Artificial intelligence

OpenClaw AI chatbots are running amok - these scientists are listening in

#openai
fromFortune
3 days ago
Artificial intelligence

What OpenAI's OpenClaw hire says about the future of AI agents | Fortune

fromFortune
5 days ago
Artificial intelligence

OpenAI hires OpenClaw AI agent developer Peter Steinberg | Fortune

fromFortune
3 days ago
Artificial intelligence

What OpenAI's OpenClaw hire says about the future of AI agents | Fortune

fromFortune
5 days ago
Artificial intelligence

OpenAI hires OpenClaw AI agent developer Peter Steinberg | Fortune

#infostealer
Artificial intelligence
fromComputerworld
4 days ago

OpenAI hires OpenClaw founder as AI agent race intensifies

OpenAI hired Peter Steinberger to lead personal-agent development; OpenClaw will continue as an open-source project under an independent foundation supported by OpenAI.
Artificial intelligence
fromWIRED
1 week ago

'Uncanny Valley': ICE's Secret Expansion Plans, Palantir Workers' Ethical Concerns, and AI Assistants

ICE plans to expand operations into nearly every U.S. state, Palantir leadership offered little substantive engagement on employee ethical concerns, and AI agents show limited real-world capabilities.
Information security
fromCult of Mac
1 week ago

How OpenClaw turns your Mac into an action-based AI agent

OpenClaw is a self-hosted AI agent for Mac or PC that performs local system actions but requires careful permission and security management.
Gadgets
fromThe Verge
1 week ago

Could the Trump Phone be a good phone?

The Trump Mobile T1 Phone 8002's existence and U.S.-made claims remain doubtful despite a virtual reveal; OpenClaw and Moltbook show divergent AI promise and risk.
Information security
fromTheregister
1 week ago

OpenClaw instances open to the internet present ripe targets

Over 135,000 internet-exposed OpenClaw AI agent instances, combined with known vulnerabilities and malicious skills, create a systemic security crisis.
fromTechzine Global
1 week ago

Over 40,000 OpenClaw agents vulnerable

Security experts have discovered tens of thousands of unsecured OpenClaw instances. The AI agents run vulnerable software versions and offer attackers access to systems. More than 12,000 instances are vulnerable to remote code execution. Researchers at SecurityScorecard have exposed a major security problem for the rapidly growing OpenClaw. Through internet scans, the team identified 28,663 unique IP addresses with exposed OpenClaw control panels spread across 76 countries.
Information security
Artificial intelligence
fromBusiness Insider
1 week ago

OpenClaw creator makes a case for 'specialized intelligence' over superintelligence

Specialized, task-focused AI produces practical advances and aligns with human societal specialization, offering more value than pursuing hypothetical AGI or superintelligence.
Information security
fromThe Hacker News
1 week ago

OpenClaw Integrates VirusTotal Scanning to Detect Malicious ClawHub Skills

OpenClaw now scans all ClawHub skills with VirusTotal Code Insight, auto-approving benign skills, flagging suspicious ones, blocking malicious skills, and rescanning daily.
#moltbook
Information security
fromSecurityWeek
2 weeks ago

Security Analysis of Moltbook Agent Network: Bot-to-Bot Prompt Injection and Data Leaks

An exposed Moltbook API key and malicious AI agents caused large data leaks and bot-driven influence operations before a rapid patch.
Artificial intelligence
fromFortune
2 weeks ago

Ending the world for the LOLs | Fortune

Moltbook posts largely reflect human prompting, OpenClaw tooling, and training-data mimicry rather than autonomous agent coordination or nefarious self-organization.
Information security
fromTheregister
2 weeks ago

It's easy to backdoor OpenClaw, and its skills leak API keys

OpenClaw agents and the ClawHub marketplace expose credentials and enable indirect prompt injection, allowing backdoors, data theft, and unintentional leakage of financial information.
Artificial intelligence
fromBusiness Insider
2 weeks ago

China's tech giants are opening their doors to OpenClaw. The Chinese internet is lapping it up.

Chinese tech giants integrate OpenClaw into cloud platforms, enabling widespread automation use in China despite raised privacy and security concerns.
Information security
fromThe Verge
2 weeks ago

OpenClaw's AI 'skill' extensions are a security nightmare

OpenClaw's skill marketplace contains hundreds of malicious add-ons that can deliver malware and exfiltrate crypto and device credentials.
Artificial intelligence
fromFast Company
2 weeks ago

OpenClaw is a major leap forward for AI-and a cybersecurity nightmare

Roughly 1,000 unsecured OpenClaw gateways exposed user files and accounts, enabling full read/write access and exploitable third-party skills that could cause serious harm.
fromSecurityWeek
2 weeks ago

Vulnerability Allows Hackers to Hijack OpenClaw AI Assistant

The security hole, tracked as CVE-2026-25253, was patched in recent days with the release of version 2026.1.29. "This is a token exfiltration vulnerability that leads to full gateway compromise," the AI tool's developers explained in an advisory. "It impacts any Moltbot deployment where a user has authenticated to the Control UI. The attacker gains operator-level access to the gateway API, enabling arbitrary config changes and code execution on the gateway host."
Information security
Information security
fromTheregister
2 weeks ago

DIY AI bot farm OpenClaw is a security 'dumpster fire'

OpenClaw, an AI messaging assistant, contains multiple high-impact security vulnerabilities, hosts hundreds of malicious extensions, exposed sensitive data, and has been rapidly exploited.
Information security
fromThe Hacker News
2 weeks ago

OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link

A token-exfiltration vulnerability in OpenClaw allowed one-click remote code execution by trusting an unvalidated gatewayUrl and auto-sending stored gateway tokens.
Artificial intelligence
fromZDNET
2 weeks ago

From Clawdbot to OpenClaw: This viral AI agent is evolving fast - and it's nightmare fuel for security pros

OpenClaw is a newly rebranded autonomous personal AI platform that integrates multiple models but raises security concerns after new exploits emerged despite security claims.
fromTheregister
2 weeks ago

OpenClaw ecosystem still suffering severe security issues

If an OpenClaw user running a vulnerable version and configuration clicked on that link, an attacker could then trigger a cross-site WebSocket hijacking attack because the polyonymous AI project's server doesn't validate the WebSocket origin header. This means the OpenClaw server will accept requests from any website. A maliciously crafted webpage, in this case, can execute client-side JavaScript code on the victim's browser to retrieve an authentication token, establish a WebSocket connection to the server, and use that token to pass authentication.
Information security
Artificial intelligence
fromZDNET
2 weeks ago

OpenClaw is a security nightmare - 5 red flags you shouldn't ignore (before it's too late)

OpenClaw is an open-source AI assistant that automates digital tasks but introduces notable security and scam risks when widely adopted.
[ Load more ]