AI · 110 giorni fa
Un agent della inbox non è più sicuro di una persona solo perché segue meccanicamente le istruzioni. Se può leggere la posta e agire sulle app collegate, una richiesta dall’aspetto ordinario può indurlo a consegnare credenziali e record interni a velocità macchina.
2 fonti che coprono questa storia
New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets
OpenClaw input flaws let hidden contacts and phishing emails trigger code execution and data leaks, exposing agent trust risks.
OpenClaw AI agent found falling for phishing attacks, spills user data
Phishing simulation on an OpenClaw email agent with various configuration profiles showed that it was susceptible to tactics commonly used to compromise human users.
Part of the PlainSec briefing for 2026-06-12