China’s CERT Issues Security Warning on OpenClaw AI Tool

China's cybersecurity agency has raised alarms about the OpenClaw AI tool, citing serious security vulnerabilities and potential risks to users.
Ciberseguridad, vulnerabilidades y privacidad

China's cybersecurity agency has raised alarms about the OpenClaw AI tool, citing serious security vulnerabilities and potential risks to users.

A malicious npm package posing as an OpenClaw installer has been identified, capable of deploying a remote access trojan (RAT) and stealing sensitive data from macOS systems.

The cybercrime group ShinyHunters has announced a significant data breach affecting around 100 companies, including Salesforce, by exploiting misconfigured guest user profiles.

Microsoft's threat intelligence team highlights the growing use of AI agents by cybercriminals, particularly North Korean actors, to streamline cyberattack infrastructure management.

A new multi-stage malware campaign, dubbed VOID#GEIST, has been identified, utilizing batch scripts to deliver various remote access trojans, including XWorm, AsyncRAT, and Xeno RAT.

Anthropic has identified 22 security vulnerabilities in Firefox, including 14 high-severity issues, through its AI model, Claude Opus 4.6. Most vulnerabilities have been addressed in the latest update.

OpenAI's new Codex Security tool has scanned 1.2 million code commits, uncovering significant vulnerabilities across various open-source projects.

Security researchers have identified a spyware campaign that disguises itself as an emergency alert application, targeting Israeli citizens through SMS messages.

Cisco has confirmed that two vulnerabilities in its SD-WAN management software are currently being exploited, posing risks of file overwrites and privilege escalation.

Mozilla has collaborated with Anthropic to improve Firefox's security through AI-based vulnerability detection, while also addressing hardware-related browser crashes.