Sicurezza AI · Attacco ad app web
L'attacco poteva brute-forzare la password e auto-registrare un dispositivo trusted senza prompt utente.
5 fonti · 6 mar
BleepingComputer
Bing AI promoted fake OpenClaw GitHub repo pushing info-stealing malware
Fake OpenClaw installers hosted in GitHub repositories and promoted by Microsoft Bing's AI-enhanced search feature instructed users to run commands that deployed information stealers and proxy malware.
originaleDark Reading
Critical OpenClaw Vulnerability Exposes AI Agent Risks
The now-patched flaw is the latest in a growing string of security issues with the viral AI tool, which has seen rapid adoption among developers.
originaleSecurityWeek
OpenClaw Vulnerability Allowed Websites to Hijack AI Agents
Malicious websites could open a WebSocket connection to localhost on the OpenClaw gateway port, brute force passwords, and take control of the agent.
originalePart of the PlainSec briefing for 2026-03-03
Every edition of this story: OpenClaw: vulnerabilità consente dirottamento agenti AI locali