<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #OpenClaw</title><description>Cybersecurity articles tagged #OpenClaw on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>OpenClaw AI Agent Vulnerabilities: Code Execution &amp; Data Leakage</title><link>https://runtimerebel.com/blog/openclaw-ai-agent-vulnerabilities-code-execution-data-leakage</link><guid isPermaLink="true">https://runtimerebel.com/blog/openclaw-ai-agent-vulnerabilities-code-execution-data-leakage</guid><description>New research reveals OpenClaw AI agents can be tricked into executing malicious code or exfiltrating sensitive data via seemingly benign inputs like vCards and location…</description><pubDate>Thu, 11 Jun 2026 20:56:08 GMT</pubDate><category>OpenClaw</category><category>AI Agent</category><category>Code Execution</category><category>Data Leakage</category><category>Imperva</category><category>Varonis</category><category>Input Validation</category></item><item><title>OpenClaw &apos;Claw Chain&apos; Vulnerabilities: Credential Theft, Persistence</title><link>https://runtimerebel.com/blog/openclaw-claw-chain-vulnerabilities-credential-theft-persistence</link><guid isPermaLink="true">https://runtimerebel.com/blog/openclaw-claw-chain-vulnerabilities-credential-theft-persistence</guid><description>Analysis of &apos;Claw Chain&apos; vulnerabilities in OpenClaw, an AI agent framework, detailing credential theft, privilege escalation, and persistence risks.</description><pubDate>Tue, 19 May 2026 00:58:13 GMT</pubDate><category>OpenClaw</category><category>AI Agent Framework</category><category>Claw Chain</category><category>Credential Theft</category><category>Privilege Escalation</category><category>Persistence</category><category>Application Security</category></item><item><title>CVE-2024-41662: Chaining OpenClaw Flaws for Sandbox Escape</title><link>https://runtimerebel.com/blog/cve-2024-41662-chaining-openclaw-flaws-for-sandbox-escape</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-41662-chaining-openclaw-flaws-for-sandbox-escape</guid><description>CyberArk researchers uncover the Claw Chain in OpenClaw, allowing attackers to escape sandboxes, steal credentials, and deploy persistent backdoors.</description><pubDate>Mon, 18 May 2026 13:24:51 GMT</pubDate><category>OpenClaw</category><category>CVE-2024-41662</category><category>Sandbox Escape</category><category>CyberArk</category><category>RCE</category></item><item><title>OpenClaw &quot;Claw Chain&quot; Flaws: Data Theft and Persistence Risks</title><link>https://runtimerebel.com/blog/openclaw-claw-chain-flaws-data-theft-and-persistence-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/openclaw-claw-chain-flaws-data-theft-and-persistence-risks</guid><description>Researchers at Cyera have identified the Claw Chain, a set of four OpenClaw vulnerabilities enabling data theft, privilege escalation, and persistent access.</description><pubDate>Fri, 15 May 2026 16:40:35 GMT</pubDate><category>OpenClaw</category><category>Cyera</category><category>Claw Chain</category><category>Privilege Escalation</category><category>Cloud Security</category></item><item><title>Emerging Reconnaissance: Attackers Actively Probe AI Models</title><link>https://runtimerebel.com/blog/emerging-reconnaissance-attackers-actively-probe-ai-models</link><guid isPermaLink="true">https://runtimerebel.com/blog/emerging-reconnaissance-attackers-actively-probe-ai-models</guid><description>DShield sensors detect increasing scanning activity targeting popular AI models like Claude and Hugging Face, signaling a potential new attack vector for threat actors.</description><pubDate>Wed, 15 Apr 2026 00:46:56 GMT</pubDate><category>AI Models</category><category>Scanning</category><category>Reconnaissance</category><category>Threat Intelligence</category><category>DShield</category><category>Hugging Face</category><category>Claude</category><category>OpenClaw</category></item><item><title>Governing Agentic AI: Security Risks and Governance Lessons from OpenClaw</title><link>https://runtimerebel.com/blog/governing-agentic-ai-security-risks-and-governance-lessons-from-openclaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/governing-agentic-ai-security-risks-and-governance-lessons-from-openclaw</guid><description>Explore the security implications of agentic AI systems like OpenClaw. Learn about the shift to autonomous AI actions and the need for robust governance.</description><pubDate>Tue, 24 Mar 2026 20:20:16 GMT</pubDate><category>Agentic AI</category><category>OpenClaw</category><category>AI Security</category><category>LLM Security</category><category>Governance</category></item><item><title>Malicious GitHub OpenClaw Deployer Repos Deliver Trojans</title><link>https://runtimerebel.com/blog/malicious-github-openclaw-deployer-repos-deliver-trojans</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-github-openclaw-deployer-repos-deliver-trojans</guid><description>Analysts uncover an AI-assisted campaign using over 300 poisoned GitHub repositories like OpenClaw Deployer to distribute infostealers to developers.</description><pubDate>Tue, 24 Mar 2026 16:30:07 GMT</pubDate><category>GitHub</category><category>OpenClaw</category><category>Infostealer</category><category>Supply Chain Attack</category><category>Ai Assisted Threats</category></item><item><title>OpenClaw AI Agent Flaws: Prompt Injection and Data Exfiltration Risk</title><link>https://runtimerebel.com/blog/openclaw-ai-agent-flaws-prompt-injection-and-data-exfiltration-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/openclaw-ai-agent-flaws-prompt-injection-and-data-exfiltration-risk</guid><description>CNCERT warns of critical security flaws in OpenClaw AI agents, enabling prompt injection and data exfiltration due to weak default configurations.</description><pubDate>Sat, 14 Mar 2026 20:09:05 GMT</pubDate><category>OpenClaw</category><category>AI Security</category><category>Prompt Injection</category><category>CNCERT</category><category>Data Exfiltration</category></item><item><title>npm Malware @openclaw-ai/openclawai: macOS Credential Theft Alert</title><link>https://runtimerebel.com/blog/npm-malware-openclaw-ai-openclawai-macos-credential-theft-alert</link><guid isPermaLink="true">https://runtimerebel.com/blog/npm-malware-openclaw-ai-openclawai-macos-credential-theft-alert</guid><description>Security alert for @openclaw-ai/openclawai, a malicious npm package targeting macOS users to deploy remote access trojans and steal sensitive credentials.</description><pubDate>Mon, 09 Mar 2026 20:11:58 GMT</pubDate><category>NPM</category><category>macOS</category><category>Malware</category><category>RAT</category><category>OpenClaw</category><category>Supply Chain Attack</category></item><item><title>Bing AI Promotes Fake GitHub Repositories Spreading Info-Stealers</title><link>https://runtimerebel.com/blog/bing-ai-promotes-fake-github-repositories-spreading-info-stealers</link><guid isPermaLink="true">https://runtimerebel.com/blog/bing-ai-promotes-fake-github-repositories-spreading-info-stealers</guid><description>Microsoft Bing AI search promoted malicious GitHub repositories hosting fake OpenClaw software, leading to info-stealing and proxy malware deployment.</description><pubDate>Fri, 06 Mar 2026 00:39:09 GMT</pubDate><category>Bing AI</category><category>OpenClaw</category><category>Infostealer</category><category>Proxy Malware</category><category>GitHub</category><category>SEO Poisoning</category><category>AI Powered Search</category></item><item><title>Critical OpenClaw Flaw in AI Agents: Risks and Remediation Guide</title><link>https://runtimerebel.com/blog/critical-openclaw-flaw-in-ai-agents-risks-and-remediation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-openclaw-flaw-in-ai-agents-risks-and-remediation-guide</guid><description>A critical OpenClaw vulnerability in widely adopted AI agents could lead to severe security risks. Understand the impact and crucial remediation steps.</description><pubDate>Tue, 03 Mar 2026 00:36:48 GMT</pubDate><category>OpenClaw</category><category>AI Agents</category><category>Vulnerability</category><category>Application Security</category><category>Patching</category></item><item><title>OpenClaw Hijacking Vulnerability: How Malicious Sites Control AI Agents</title><link>https://runtimerebel.com/blog/openclaw-hijacking-vulnerability-how-malicious-sites-control-ai-agents</link><guid isPermaLink="true">https://runtimerebel.com/blog/openclaw-hijacking-vulnerability-how-malicious-sites-control-ai-agents</guid><description>A critical vulnerability in the OpenClaw AI gateway allows malicious websites to hijack local AI agents via WebSocket connections and password brute-forcing.</description><pubDate>Mon, 02 Mar 2026 16:19:46 GMT</pubDate><category>OpenClaw</category><category>AI Security</category><category>WebSocket Hijacking</category><category>Cross Site Attack</category><category>AI Gateway</category></item><item><title>ClawJacked Vulnerability in OpenClaw AI Agent Enables Data Hijacking</title><link>https://runtimerebel.com/blog/clawjacked-vulnerability-in-openclaw-ai-agent-enables-data-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/clawjacked-vulnerability-in-openclaw-ai-agent-enables-data-hijacking</guid><description>Analysis of the ClawJacked attack where malicious websites can hijack local OpenClaw instances to steal sensitive LLM API keys and private conversation data.</description><pubDate>Mon, 02 Mar 2026 00:34:36 GMT</pubDate><category>ClawJacked</category><category>OpenClaw</category><category>AI Security</category><category>Local API Hijacking</category><category>Salt Security</category></item><item><title>ClawJacked: Hijacking Local OpenClaw AI Agents via WebSocket</title><link>https://runtimerebel.com/blog/clawjacked-hijacking-local-openclaw-ai-agents-via-websocket</link><guid isPermaLink="true">https://runtimerebel.com/blog/clawjacked-hijacking-local-openclaw-ai-agents-via-websocket</guid><description>A high-severity vulnerability in the OpenClaw AI gateway allows malicious websites to take control of local AI agents by exploiting WebSocket flaws.</description><pubDate>Sat, 28 Feb 2026 20:08:47 GMT</pubDate><category>OpenClaw</category><category>AI Security</category><category>WebSocket Hijacking</category><category>ClawJacked</category><category>Localhost Security</category></item><item><title>OpenClaw Underground Trends: Assessing Hype vs. Operational Risk</title><link>https://runtimerebel.com/blog/openclaw-underground-trends-assessing-hype-vs-operational-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/openclaw-underground-trends-assessing-hype-vs-operational-risk</guid><description>Flare telemetry reveals a gap between high OpenClaw chatter on Telegram and actual exploitation, highlighting the need to distinguish hype from threat.</description><pubDate>Wed, 25 Feb 2026 16:32:59 GMT</pubDate><category>OpenClaw</category><category>Dark Web</category><category>Telegram</category><category>Threat Intelligence</category><category>Flare</category><category>Supply Chain</category></item></channel></rss>