Close Menu
  • Home
  • Psychology
  • Dating
    • Relationship
  • Spirituality
    • Manifestation
  • Health
    • Fitness
  • Lifestyle
  • Family
  • Food
  • Travel
  • More
    • Business
    • Education
    • Technology
What's Hot

Review: Catgill Farm Glamping, Bolton Abbey, UK

March 29, 2026

AI Learning Assistant | Teacher Picks

March 29, 2026

Google Pixel 10a Review: This is Fine

March 29, 2026
Facebook X (Twitter) Pinterest YouTube
Facebook X (Twitter) Pinterest YouTube
Mind Fortunes
Subscribe
  • Home
  • Psychology
  • Dating
    • Relationship
  • Spirituality
    • Manifestation
  • Health
    • Fitness
  • Lifestyle
  • Family
  • Food
  • Travel
  • More
    • Business
    • Education
    • Technology
Mind Fortunes
Home»Technology»Infostealers added Clawdbot to their target lists before most security teams knew it was running
Technology

Infostealers added Clawdbot to their target lists before most security teams knew it was running

January 30, 2026No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
Infostealers added Clawdbot to their target lists before most security teams knew it was running
Share
Facebook Twitter LinkedIn Pinterest Email

Clawdbot’s implementation of MCP lacks mandatory authentication, allowing for prompt injection and granting shell access intentionally. An article published by VentureBeat on Monday highlighted these architectural vulnerabilities. By Wednesday, security researchers had confirmed these three attack surfaces and uncovered additional ones as well.

The project underwent a rebranding from Clawdbot to Moltbot on January 27 following a trademark request from Anthropic due to the similarity to “Claude.”

Various commodity infostealers have already begun exploiting these vulnerabilities. RedLine, Lumma, and Vidar have included the AI agent in their target lists even before most security teams were aware of its presence in their environments. Shruti Gandhi, a general partner at Array VC, reported a staggering 7,922 attack attempts on her firm’s Clawdbot instance.

The security concerns surrounding Clawdbot prompted a comprehensive evaluation of its security posture. Here are the key findings that emerged:

SlowMist issued a warning on January 26 revealing that hundreds of Clawdbot gateways were exposed to the internet, providing unauthorized access to API keys, OAuth tokens, and private chat histories without the need for credentials. Matvey Kukuy, the CEO of Archestra AI, successfully extracted an SSH private key via email using prompt injection within just five minutes.

Referred to as Cognitive Context Theft by Hudson Rock, the malware associated with Clawdbot not only steals passwords but also gathers psychological profiles, work-related information, trust networks, and personal anxieties – offering attackers a wealth of data for effective social engineering.

Clawdbot, an open-source AI agent designed to automate tasks across various platforms, gained immense popularity as a personal assistant, garnering 60,000 GitHub stars in a short span of time. However, many developers deployed instances without fully understanding the security implications. Default settings left port 18789 exposed to the public internet, making it vulnerable to exploitation.

See also  MAFS UK 2025: When Do the Final Vows and Reunion Episodes Air?

A red-teaming firm led by Jamieson O’Reilly conducted a scan on Shodan, revealing hundreds of exposed Clawdbot instances, with some lacking any authentication measures, allowing for full command execution. O’Reilly also demonstrated a supply chain attack on ClawdHub’s skills library, reaching multiple developers across different countries in a short timeframe.

Despite the prompt patching of the gateway authentication bypass by Peter Steinberger, the creator of Clawdbot, fundamental architectural issues persist, such as plaintext memory file storage, unverified supply chain components, and pathways for prompt injection – all ingrained in the system’s design.

AI agents like Clawdbot pose a significant risk due to their extensive permissions across various platforms. A minor prompt injection can quickly escalate into substantial actions without detection, highlighting the expanding attack surface that security teams struggle to monitor effectively.

Security experts emphasize the need for a shift in mindset regarding the treatment of AI agents, urging organizations to view them as critical production infrastructure rather than mere productivity tools. The lack of visibility into where agents are deployed, their actions, and data access permissions poses a significant challenge for security teams.

As the threat landscape evolves, security leaders must take proactive steps to address the vulnerabilities associated with AI agents like Clawdbot. Implementing inventory management, enforcing least privilege, and enhancing runtime visibility are crucial measures to mitigate potential risks.

In conclusion, the rapid rise and subsequent security concerns surrounding Clawdbot underscore the urgency for organizations to adopt a proactive stance towards securing AI agents. As the threat of exploitation looms, security teams must stay ahead of potential attacks by implementing robust security measures and maintaining vigilance to safeguard critical data and infrastructure.

See also  MCP shipped without authentication. Clawdbot shows why that's a problem.
added Clawdbot Infostealers Knew lists Running security target Teams
Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
Previous ArticleEtihad Guest Takes Off Across India with Massive Partner Expansion | News
Next Article 3 Important Questions To Ask a Chiropractor

Related Posts

Google Pixel 10a Review: This is Fine

March 29, 2026

RCS 4.0 Brings Native Video Calls and Messaging Enhancements

March 28, 2026

What will power the grid in 2035? The race is wide open

March 28, 2026

Google Pixel Phone: How to Free up to 7GB of Storage

March 28, 2026

Comments are closed.

Our Picks

NBCU Academy’s The Edit | Teacher Picks

March 7, 2026

AI Learning Assistant | Teacher Picks

March 29, 2026

What SEL Skills Do High School Graduates Need Most? Report Lists Top Picks

March 8, 2026
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Don't Miss
Travel

Review: Catgill Farm Glamping, Bolton Abbey, UK

March 29, 20260

The story of Catgill is one of profound diversification and family legacy. Since 2014, husband-and-wife…

AI Learning Assistant | Teacher Picks

March 29, 2026

Google Pixel 10a Review: This is Fine

March 29, 2026

7 Rare Lucky Signs on Palm Said to Bring Luck and Success

March 28, 2026
About Us
About Us

Explore blogs on mind, spirituality, health, and travel. Find balance, wellness tips, inner peace, and inspiring journeys to nurture your body, mind, and soul.

We're accepting new partnerships right now.

Our Picks

Review: Catgill Farm Glamping, Bolton Abbey, UK

March 29, 2026

AI Learning Assistant | Teacher Picks

March 29, 2026

Google Pixel 10a Review: This is Fine

March 29, 2026

Subscribe to Updates

Awaken Your Mind, Nourish Your Soul — Join Our Journey Today!

Facebook X (Twitter) Pinterest YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 mindfortunes.org - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.