New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets

Two security teams have shown, in separate research published this week, that OpenClaw, the popular self-hosted AI agent, can be driven to run attacker-controlled code or hand over sensitive data through ordinary-looking inputs.

Imperva buried instructions inside shared contacts, vCards, and location pins that the agent executed without the victim ever seeing them. Varonis built a test agent on

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks

Next Post

ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities

Related Posts
Total
0
Share