Close Menu
AI News TodayAI News Today

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    OpenAI Has a New AI Model Built for Biology and Science

    Today’s NYT Wordle Hints, Answer and Help for April 18 #1764

    Today’s NYT Connections Hints, Answers for April 18 #1042

    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook X (Twitter) Instagram Pinterest Vimeo
    AI News TodayAI News Today
    • Home
    • Shop
    • AI News
    • AI Reviews
    • AI Tools
    • AI Tutorials
    • Chatbots
    • Free AI Tools
    AI News TodayAI News Today
    Home»AI News»OpenClaw gives users yet another reason to be freaked out about security
    AI News

    OpenClaw gives users yet another reason to be freaked out about security

    By No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    A blue crayfish on a countertop
    Share
    Facebook Twitter LinkedIn Pinterest Email

    For more than a month, security practitioners have been warning about the perils of using OpenClaw, the viral AI agentic tool that has taken the development community by storm. A recently fixed vulnerability provides an object lesson for why.

    OpenClaw, which was introduced in November and now boasts 347,000 stars on Github, by design takes control of a user’s computer and interacts with other apps and platforms to assist with a host of tasks, including organizing files, doing research, and shopping online. To be useful, it needs access—and lots of it—to as many resources as possible. Telegram, Discord, Slack, local and shared network files, accounts, and logged in sessions are only some of the intended resources. Once the access is given, OpenClaw is designed to act precisely as the user would, with the same broad permissions and capabilities.

    Severe impact

    Earlier this week, OpenClaw developers released security patches for three high-severity vulnerabilities. The severity rating of one in particular, CVE-2026-33579, is rated from 8.1 to 9.8 out of a possible 10 depending on the metric used—and for good reason. It allows anyone with pairing privileges (the lowest-level permission) to gain administrative status. With that, the attacker has control of whatever resources the OpenClaw instance does.

    “The practical impact is severe,” researchers from AI app-builder Blink wrote. “An attacker who already holds operator.pairing scope—the lowest meaningful permission in an OpenClaw deployment—can silently approve device pairing requests that ask for operator.admin scope. Once that approval goes through, the attacking device holds full administrative access to the OpenClaw instance. No secondary exploit is needed. No user interaction is required beyond the initial pairing step.”

    The post continued: “For organizations running OpenClaw as a company-wide AI agent platform, a compromised operator.admin device can read all connected data sources, exfiltrate credentials stored in the agent’s skill environment, execute arbitrary tool calls, and pivot to other connected services. The word ‘privilege escalation’ undersells this: the outcome is full instance takeover.”

    freaked OpenClaw reason security users
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleAs Artemis II zooms to the Moon, everything seems to be going swimmingly
    Next Article Anthropic is having a moment in the private markets; SpaceX could spoil the party
    • Website

    Related Posts

    AI Reviews

    Best Smart Locks of 2026: Your High-Tech Security Starter

    AI News

    SaySo is a new short-form video app that aims to restore users’ trust in news

    AI News

    With US spy laws set to expire, lawmakers are split over protecting Americans from warrantless surveillance

    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    OpenAI Has a New AI Model Built for Biology and Science

    0 Views

    Today’s NYT Wordle Hints, Answer and Help for April 18 #1764

    0 Views

    Today’s NYT Connections Hints, Answers for April 18 #1042

    0 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    AI Tutorials

    Quantization from the ground up

    AI Tools

    David Sacks is done as AI czar — here’s what he’s doing instead

    AI Reviews

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    OpenAI Has a New AI Model Built for Biology and Science

    0 Views

    Today’s NYT Wordle Hints, Answer and Help for April 18 #1764

    0 Views

    Today’s NYT Connections Hints, Answers for April 18 #1042

    0 Views
    Our Picks

    Quantization from the ground up

    David Sacks is done as AI czar — here’s what he’s doing instead

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Terms & Conditions
    • Privacy Policy
    • Disclaimer

    © 2026 ainewstoday.co. All rights reserved. Designed by DD.

    Type above and press Enter to search. Press Esc to cancel.