Clawdbot's MCP implementation has no mandatory authentication, allows prompt injection, and grants shell access by design. Monday's VentureBeat article documented these architectural flaws. By Wednesday, security researchers had validated all three attack surfaces and found new ones.Commodity infostealers are already exploiting this. RedLine, Lumma, and Vidar added the AI agent to their target lists before most security teams knew it was running in their environments. Shruti Gandhi, general partner at Array VC, reported 7,922 attack attempts on her firm's Clawdbot instance.The reporting prompted a coordinated look at Clawdbot's security posture. Here's what emerged:SlowMist warned on January 26 that hundreds of Clawdbot gateways were exposed to the internet, includ [...]
OpenClaw, the open-source AI assistant formerly known as Clawdbot and then Moltbot, crossed 180,000 GitHub stars and drew 2 million visitors in a single week, according to creator Peter Steinberger. S [...]
After (what felt like) a long delay, Nintendo Switch 2 pre-orders have opened in the US and Canada. Nintendo finally opened up pre-orders in both regions on April 24, after previously announcing (and [...]
Nintendo Switch 2 pre-orders are technically open in North America, but if you haven't managed to grab one already, you may have a tough time doing so before the console's June 5 release dat [...]
While Nintendo Switch 2 pre-orders are technically open, you may have a tough time grabbing the new console before it's June 5 release date if you haven't secured one already. After an exten [...]