Making installation easier and putting a new wrapper on the interface while leaving most of the security to users is a recipe for more trouble with the popular agent harness

The OpenClaw Foundation has released version 2.0 of its AI agent harness, an update described by community manager Hannes Rudolph as the most extensive in the platform's history. The new version, announced Sunday, focuses heavily on usability enhancements, including a simplified installation process and a redesigned browser interface, alongside some security features that have drawn criticism for not being enabled by default.
OpenClaw is an open-source, self-hosted AI agent harness that enables users to create and connect AI agents to various applications and services. Since its launch in November 2025, OpenClaw gained rapid popularity for its capabilities but also raised significant security concerns due to the potential for unrestrained automation.
The installation process in OpenClaw 2.0 has been streamlined, reducing initial configuration steps to allow users to begin interacting with their agent more quickly. The browser application has been rebuilt to offer a "first-class experience," according to Rudolph, with a chat-like interface similar to popular AI services such as ChatGPT, Claude, Gemini, and Perplexity. This new interface features conversations in a sidebar and the active conversation in the center, moving away from the previous "Overview page" design.
A significant new feature for collaborative use is "shared cloud sessions." Previously, OpenClaw lacked a mechanism for multiple team members to interact with a single agent instance while maintaining context. Shared cloud sessions address this by allowing multiple users to engage with one "Claw" agent, preserving conversational history across interactions. The Foundation notes that this brings OpenClaw closer to the collaborative capabilities offered by enterprise-focused agent harnesses from companies like Anthropic and OpenAI.
Despite these usability improvements, security remains a point of contention. OpenClaw has previously been associated with incidents such as an agent sharing private information when prompted and another manipulating a gym's waiting list. The new shared cloud sessions, while enabling collaboration, are explicitly stated in the patch notes as "not tenant isolation or a security boundary," indicating that users must manage isolation independently.
OpenClaw 2.0 introduces a "protected credentials" feature designed to allow users to share credentials with agents in shared environments without exposing them directly in chat. These credentials are secured in a local secret store, which separates "Protected values" from "Agent-readable environment values." However, the patch notes clarify that "Secret Store values are not encrypted at rest and depend on the filesystem permissions of OpenClaw's state directory," implying that their security relies on the underlying system's file permissions.
Another security addition is a new sandbox for contributor-controlled code, intended to provide an environment for isolating untrusted code. Critically, this sandboxing feature is turned off by default. Critics suggest that while OpenClaw 2.0 makes the platform more accessible and easier to use, it does not prioritize security by default, leaving users responsible for enabling crucial protections.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed