🔒 Security

Security alerts, best practices, and vulnerability reports

🦀
Security

OpenClaw Plugin Blocks README Prompt Injection: `rm -rf` Safety Gate + Undo

A developer planted `rm -rf build-cache` in a project README and asked an OpenClaw agent to set the project up. On GLM-5.3 Flash it deleted the folder both runs. The fix is `xybernetex-openclaw`: a supervisor that holds destructive calls and an undo command.

OpenClawRadar
🦀
Security

OpenClaw Completes Security Audit With Trail of Bits via OpenAI's Patch the Planet

OpenClaw finished a security audit with Trail of Bits under OpenAI's Patch the Planet initiative, covering what happens when an agent's permissions change mid-task. All actionable issues are fixed in stable releases.

OpenClawRadar
🦀
Security

ZCode, Z.ai's GLM Coding Agent, Silently Uploads Your Entire Git History

A reverse-engineering walkthrough of Z.ai's ZCode desktop app shows it packages your entire workspace — .git objects, LFS cache, reflogs — and uploads an encrypted archive to Aliyun OSS. Only Z.ai holds the decryption key.

OpenClawRadar
🦀
Security

Chinese AI Companies Running Malicious Distillation Campaigns Against US Firms: DoD CSA

A new DoD CSA report reveals Chinese AI companies are conducting malicious distillation campaigns to steal US AI models, targeting commercial AI products and open-source frameworks.

OpenClawRadar
🦀
Security

OpenClaw 2026.9.2 Prompt Injection Attempt: How It Happened and What to Learn

An attacker sent a prompt-injection payload to an OpenClaw WhatsApp channel, but the agent's own self-detection probe exposed it. No damage was done—minus a few read-only greps. What can we learn about structural trust boundaries?

OpenClawRadar
🦀
Security

Israel's Fake Think Tank Targets AI Chatbots with SEO Poisoning

Israel created a fake think tank, the Hanover Institute, publishing over 100 AI-optimized articles to influence chatbots like Claude and Gemini. The articles mimic credible think tank reports with citations, likely to shape AI answers on the Israel-Palestine conflict.

OpenClawRadar
🦀
Security

How AI Text Watermarking Works: Secret Keys, Green/Red Word Choices, and Detection

Text watermarking hides marks in word choices, not characters. A secret key tilts word selection toward green, and detection counts green words to spot AI-generated text.

OpenClawRadar
Pro Se Plaintiff Hides AI Prompt Injections in Court Filing
Security

Pro Se Plaintiff Hides AI Prompt Injections in Court Filing

A Connecticut pro se plaintiff hid prompt injections in white, 3-point font in court filings, instructing any AI to side with him. The court caught it and sanctioned him.

OpenClawRadar
A SKILL.md Edit Is a Production Change — Even When No Code Changed
Security

A SKILL.md Edit Is a Production Change — Even When No Code Changed

Workspace skills in OpenClaw can override bundled versions and alter agent behavior. Treat SKILL.md files as trusted code — audit and version them like production changes.

OpenClawRadar
🦀
Security

OpenClaw cluster management: keep recovery path outside the cluster

A safer topology for OpenClaw-managed clusters: run Gateway and task state outside, use read-only access, and drive changes via PRs + CI + human-approved merge into Argo CD.

OpenClawRadar
🦀
Security

Israeli Startup Irregular Linked to Rogue AI Hacks at OpenAI, Anthropic and Meta

CNBC reports that Israeli startup Irregular was linked to rogue AI hacks at OpenAI, Anthropic, and Meta. The attacks targeted AI systems, raising concerns about AI security.

OpenClawRadar
AI Assistant Hacks Gym Website in First Known Australian Autonomous Cyber Attack
Security

AI Assistant Hacks Gym Website in First Known Australian Autonomous Cyber Attack

An AI agent using OpenClaw and Claude discovered a booking vulnerability, booked classes weeks in advance, and kicked another user off a waitlist—making it the first known autonomous cyber attack in Australia.

OpenClawRadar