LIVE · cybersecurity feed
Live wire
aimedium

OpenClaw: risks for the users and how to mitigate them

OpenClaw, an AI agent ecosystem formerly known as Clawdbot and Moltbot, offers flexibility and task automation but introduces security risks to users and organizations. The system's 'skills' feature, which allows for natural language instructions and easy creation of extensions, can be exploited by attackers. The article aims to explore these security aspects, known vulnerabilities, and mitigation strategies.

zeroday.news · 31d ago

OpenClaw, an AI agent ecosystem formerly known as Clawdbot and Moltbot, presents significant security risks to users and organizations due to vulnerabilities and the widespread distribution of malicious extensions. The platform's popularity stems from its flexibility and ability to automate complex tasks using natural language instructions without requiring programming knowledge. This ease of use, however, has attracted attackers who exploit its architecture and the availability of third-party "skills" – sets of commands that extend the agent's capabilities.

These skills, often shared through a hub called ClawHub, can be created easily and do not necessarily require coding, typically existing as plaintext files. While intended for tasks ranging from email management to software development, their design allows them to access the operating system's file system and interact with system tokens and keys. This access is often granted by users who provide necessary data through environment variables or plaintext files alongside the agent.

Since February 2026, approximately 530 vulnerabilities have been documented in OpenClaw and its underlying technologies, with a notable number classified as high-severity. These issues primarily concern the insecure storage of sensitive data and the granting of excessive privileges, which can be exploited to hijack the agent or force it to execute unauthorized commands.

A significant threat vector involves malicious skills, which researchers liken to supply-chain attacks. The ease of skill creation means attackers can distribute harmful code disguised as legitimate tools. Until early February 2026, there was no formal security vetting for skills uploaded to the hub. Investigations in April revealed that at least 24 accounts were distributing over 600 malicious skills, with open-source intelligence indicating the creation of over 1100 malicious accounts since January.

Following these discoveries, measures were implemented to scan uploaded skills using VirusTotal and NVIDIA's SkillSpector. However, the nature of OpenClaw as an instruction-executing agent means that detecting malicious activity requires not only analyzing files for dangerous commands but also examining potential harmful behaviors triggered by seemingly innocuous instructions.

Kaspersky products have detected malicious OpenClaw skill activity, identifying certain malicious skills as HEUR:Trojan.ANSI.MalClaw.gen. Statistics from their systems show that attacks continue even after the implementation of countermeasures against malicious skill publications.

To mitigate these risks, a layered security approach is recommended. This includes isolating the OpenClaw agent from critical data and infrastructure systems. Organizations should also vet all skills before they are introduced into their environment, with solutions like Kaspersky Scan Engine being suitable for this purpose.

Monitoring the network access patterns of the agent is also crucial. OpenClaw offers a sandboxing subsystem and wrappers for service interactions that can aid in this. Finally, establishing a comprehensive AI policy and ensuring employees do not use unapproved third-party tools are essential steps in protecting against these threats.

aisecurity risksvulnerabilitiesmitigationautomation
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.

vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.