Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
IT Security NachrichtenICYMI: August 2026 @AWS Security(24.09.2026 um 01:31 Uhr)
IT Security NachrichtenMaintenance Company in Dubai: What to Check Before You Sign(24.09.2026 um 01:33 Uhr)
IT Security DownloadsGitHub Release: ollama/ollama v0.34.4-rc1 (24.09.2026)(24.09.2026 um 01:36 Uhr)
IT Security DownloadsGitHub Release: google-gemini/gemini-cli v0.61.0 (24.09.2026)(24.09.2026 um 01:59 Uhr)
IT Security NachrichtenICYMI: August 2026 @AWS Security(24.09.2026 um 01:31 Uhr)
IT Security NachrichtenMaintenance Company in Dubai: What to Check Before You Sign(24.09.2026 um 01:33 Uhr)
IT Security DownloadsGitHub Release: ollama/ollama v0.34.4-rc1 (24.09.2026)(24.09.2026 um 01:36 Uhr)
IT Security DownloadsGitHub Release: google-gemini/gemini-cli v0.61.0 (24.09.2026)(24.09.2026 um 01:59 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

OpenClaw: How a Popular AI Agent Platform Became a Security Catastrophe

TL;DR: OpenClaw, an open-source AI assistant platform, is massively compromised. 42,000+ instances are exposed on the public internet. 93% have critical authentication flaws. One documented vulnerability (CVE-2026-25253) gives attackers…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

TL;DR: OpenClaw, an open-source AI assistant platform, is massively compromised. 42,000+ instances are exposed on the public internet. 93% have critical authentication flaws. One documented vulnerability (CVE-2026-25253) gives attackers one-click remote code execution. This is the largest security incident in sovereign AI history—and it proves why privacy tools like the TIAMAT privacy proxy exist.









What You Need To Know





  • 42,000+ OpenClaw instances currently exposed on the public internet with zero authentication (Shodan scan, Feb 2026)


  • 93% of scanned instances have at least one critical authentication bypass or credential exposure flaw


  • 1.5M API tokens leaked in single backend misconfiguration (Moltbook incident) + 35K user emails exposed


  • CVE-2026-25253 (CVSS 8.8): One-click RCE via WebSocket token hijacking—malicious websites can steal active bot tokens and execute shell commands


  • 341 malicious skills found in ClawHub (the public skill marketplace)—37% of community skills contain security flaws, including credential theft and malware delivery









What is OpenClaw and Why Did It Get So Broken?



OpenClaw is a self-hosted AI agent platform. You install it on your laptop, VPS, or Raspberry Pi. You connect it to Claude or GPT via API. Then you give it access to: your files, your shell, your email, your calendar, your browser, third-party services via plugins called "skills."



The appeal was obvious: unlike ChatGPT (which exists on Anthropic/OpenAI servers), OpenClaw runs locally. You control it. Your data never leaves your machine.



The execution was catastrophic.



OpenClaw's developers prioritized ease of use over security. This meant:




  • API keys stored in plaintext config files

  • OAuth tokens stored unencrypted in SQLite

  • No built-in network isolation

  • Community-written skills could be installed with zero code review

  • WebSocket connections not properly authenticated

  • Default ports exposed to the internet









The Data Breach Shadow






CVE-2026-25253: Token Theft → RCE



A WebSocket handler didn't properly validate authentication tokens. A malicious website could:




  1. Detect your OpenClaw instance

  2. Send a WebSocket request

  3. Spoof the token format (it was predictable)

  4. Hijack the session

  5. Execute arbitrary shell commands



CVSS 8.8 (High). One click. Thirty seconds. Game over.






Moltbook: 1.5M Tokens + 35K Emails



Moltbook was a cloud deployment service. Their backend stored:




  • User registration data

  • Deployed OpenClaw API keys

  • Users' ChatGPT/Claude API tokens

  • Full chat histories



All unencrypted. All downloaded by a researcher. Exploited in February 2026.






ClawHub: 341 Malicious Skills



Snyk Labs audited OpenClaw's public skill marketplace:




  • 341 skills with documented security flaws

  • 189 designed to steal credentials

  • 87 that download/execute external code

  • 65 that harvest browser cookies and passwords









Key Takeaways





  • OpenClaw was destroyed by the surveillance forces it was trying to escape. Self-hosting doesn't work without professional security infrastructure.


  • 42,000+ instances are vulnerable. If you're running OpenClaw, take it offline. Rotate your API keys.


  • TIAMAT Privacy Proxy solves this. Scrub PII. Route through TIAMAT. Use any LLM. Your data stays private.






For privacy-first AI APIs, visit https://tiamat.live.

IoC Intelligence (2 Indikatoren)
CVE-2026-25253tiamat[.]live
CTI Threat Relationship Graph5 Knoten / 4 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
IR-PLAYBOOK-RCE
HIGH
SOC Incident Playbook: Remote Code Execution (RCE) Defense
1-Click Detection Engineering: Sigma & YARA Rules
SOC Ready
title: Detect Exploitation - OpenClaw: How a Popular AI Agent Platform Became a Security Catastrophe
id: e26ecb42-0012-418c-aeec-fe0f1b03995a
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-24
logsource:
  category: network_connection
  product: any
detection:
  selection:
      DestinationHostname:
        - 'tiamat.live'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
  - attack.t1190
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-24"
        description = "YARA Signature for "
    strings:
        $str = "OpenClaw: How a Popular AI Age" ascii wide
    condition:
        any of them
}
Infrastructure Blast Radius & Exposure
HIGH CASCADING
Perimeter & External Ingress
GEFÄHRDET (85%)
Lateral Movement & Pivot
Geringes Risiko
Data Stores & Crown Jewels
GEFÄHRDET (95%)
Supply Chain & Cascading Reach
Geringes Risiko
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten OpenClaw: How a Popular AI Agent Platform Became a Security Catastrophe

Thematisch verwandte Begriffe: OpenClaw, Popular, Agent, Platform · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-96676 | A vulnerability was identified in Fast FAC1900R 20190827_2.0.2. The impa…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel TTP ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick