LIVE · cybersecurity feed
Live wire
security

OpenClaw 2.0 pours glitter on slow-burning security dumpster fire

Making installation easier and putting a new wrapper on the interface while leaving most of the security to users is a recipe for more trouble with the popular agent harness

zeroday.news ·

The OpenClaw Foundation has released version 2.0 of its AI agent harness, an update described by community manager Hannes Rudolph as the most extensive in the platform's history. The new version, announced Sunday, focuses heavily on usability enhancements, including a simplified installation process and a redesigned browser interface, alongside some security features that have drawn criticism for not being enabled by default.

OpenClaw is an open-source, self-hosted AI agent harness that enables users to create and connect AI agents to various applications and services. Since its launch in November 2025, OpenClaw gained rapid popularity for its capabilities but also raised significant security concerns due to the potential for unrestrained automation.

The installation process in OpenClaw 2.0 has been streamlined, reducing initial configuration steps to allow users to begin interacting with their agent more quickly. The browser application has been rebuilt to offer a "first-class experience," according to Rudolph, with a chat-like interface similar to popular AI services such as ChatGPT, Claude, Gemini, and Perplexity. This new interface features conversations in a sidebar and the active conversation in the center, moving away from the previous "Overview page" design.

A significant new feature for collaborative use is "shared cloud sessions." Previously, OpenClaw lacked a mechanism for multiple team members to interact with a single agent instance while maintaining context. Shared cloud sessions address this by allowing multiple users to engage with one "Claw" agent, preserving conversational history across interactions. The Foundation notes that this brings OpenClaw closer to the collaborative capabilities offered by enterprise-focused agent harnesses from companies like Anthropic and OpenAI.

Despite these usability improvements, security remains a point of contention. OpenClaw has previously been associated with incidents such as an agent sharing private information when prompted and another manipulating a gym's waiting list. The new shared cloud sessions, while enabling collaboration, are explicitly stated in the patch notes as "not tenant isolation or a security boundary," indicating that users must manage isolation independently.

OpenClaw 2.0 introduces a "protected credentials" feature designed to allow users to share credentials with agents in shared environments without exposing them directly in chat. These credentials are secured in a local secret store, which separates "Protected values" from "Agent-readable environment values." However, the patch notes clarify that "Secret Store values are not encrypted at rest and depend on the filesystem permissions of OpenClaw's state directory," implying that their security relies on the underlying system's file permissions.

Another security addition is a new sandbox for contributor-controlled code, intended to provide an environment for isolating untrusted code. Critically, this sandboxing feature is turned off by default. Critics suggest that while OpenClaw 2.0 makes the platform more accessible and easier to use, it does not prioritize security by default, leaving users responsible for enabling crucial protections.

ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

malware

ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool

ValleyRAT hides behind legitimate adware, using DLL sideloading to evade detection, steal data and give Silver Fox control of infected systems. ValleyRAT doesn’t always need to disguise itself as a cracked game or a fake browser update. It can also hide behind something much more ordinary: an application that looks like adware and appears to […]

security

Fraudsters steal $6 million from Tectonic crypto platform after inflating token price

At least $6 million was stolen from crypto platform Tectonic after an attacker manipulated the price of the Tonic coin over the weekend.

malware

Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode

Research by: hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign activity dates back to March 2024 [1]; Check Point Research has been tracking the malware since early […] The post Breaking

ransomware

Berlin confirms data theft after Rhysida ransomware attack claims

Berlin's city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. [...]