The lethal trifecta: private data access + untrusted content exposure + external comms. #OpenClaw adds a fourthβpersistent memory. Now attackers can fragment payloads across days and assemble them later. The self-hosted AI dream is real. The security model isnβt.ββββββββββββββββ
02.02.2026 20:41 β π 0 π 0 π¬ 0 π 0
OpenClaw hit 123K GitHub stars in 48 hours. Self-hosted AI with shell access, plaintext creds, and WhatsApp integration.
Cisco called it βan absolute nightmare.β Then somebody built a social network where the bots prompt-inject each other.
02.02.2026 20:34 β π 1 π 0 π¬ 1 π 0
bug hunting is archaeology with curl. #bugbounty
01.02.2026 17:05 β π 2 π 0 π¬ 0 π 0
llms are basically web apps that answer politely while leaking secrets. #AIsecurity
31.01.2026 03:33 β π 2 π 0 π¬ 0 π 0
PSA:Moltbot Is Wildly Insecure
How open-source AI agents expose API keys, enable RCE via prompt injection, and why your βlocalβ butler is probably internet-facing right now
Bet? Most aren't secured. Defaults win, security loses.
Full breakdown of the architecture flaws, real exploits (one researcher grabbed an SSH key in 5 mins via email), and a hardening checklist in the article:
PSA: Moltbot Is Wildly Insecure
www.toxsec.com/p/moltbot-is...
30.01.2026 16:18 β π 2 π 0 π¬ 0 π 0
My fresh Shodan pull (post-rebrand, filtered to Clawdbot favicon + port): ~3k exposed instances still sitting there.
Many leaking everything: creds in plaintext (~/.moltbot/credentials/), full histories via WebSocket, unauth command exec, prompt injection turning Gmail into an exfil vector.
30.01.2026 16:18 β π 2 π 0 π¬ 0 π 0
The Moltbot hype train went viral β 60k+ GitHub stars in weeks β people spinning up on Mac Minis, VPSes, home servers with defaults that bind to 0.0.0.0:18789 and trust localhost like it's 2005.
30.01.2026 16:18 β π 1 π 0 π¬ 2 π 0
hunting logs is just digital birdwatching for blue teamers. #cybersecurity
30.01.2026 00:49 β π 3 π 0 π¬ 0 π 0
timeline: 45-day opt-in May 2026, 64-day default Feb 2027, full 45-day rollout Feb 2028. check your cron jobs. that hardcoded 60-day renewal interval is now a ticking outage.
28.01.2026 02:05 β π 1 π 0 π¬ 0 π 0
the security logic is sound. shorter cert lifetimes = smaller blast radius when keys get popped. revocation has always been a polite fiction anyway. this forces the automation that shouldβve happened years ago.
28.01.2026 02:05 β π 1 π 0 π¬ 0 π 0
letβs encrypt is cutting cert lifetimes to 45 days by 2028. the real pain: authorization reuse drops from 30 days to 7 hours. if youβre still manually renewing certs, congrats β you now have a part-time job.
28.01.2026 02:05 β π 1 π 0 π¬ 2 π 0
The Hacker News | #1 Trusted Source for Cybersecurity News
The Hacker News is the top cybersecurity news platform, delivering real-time updates, threat intelligence, data breach reports, expert analysis, and actionable insights for infosec professionals and d...
china-linked hackers have been inside north american critical infrastructure for over a year, quietly grabbing access
cisco talos spotted a china-nexus apt (uat-8837) targeting key sectors like energy and utilities since at least last year.
27.01.2026 02:45 β π 0 π 0 π¬ 0 π 0
securing rag is like securing a search engine that doesnβt know when to shut up. #AIsecurity
27.01.2026 02:09 β π 0 π 0 π¬ 0 π 0
ai models are like cats: you think you own them, but they do whatever they want. #AIsecurity
25.01.2026 18:10 β π 2 π 1 π¬ 0 π 0
pentesters get the glory, defenders get the alerts. #cybersecurity
24.01.2026 03:33 β π 0 π 0 π¬ 0 π 0
Built a perfect exploit chain, only to learn the target patched it this morning because a different researcher reported it first. #bugbounty
22.01.2026 02:15 β π 1 π 0 π¬ 1 π 0
Spent half the night chasing a weird auth bugβ¦turns out someone rotated the API key during your test window. #bugbounty
20.01.2026 02:09 β π 0 π 0 π¬ 0 π 0
pentests feel like chess, bug bounties feel like dumpster diving. #bugbounty
18.01.2026 17:05 β π 0 π 0 π¬ 0 π 0
why do all staging servers have cooler bugs than prod? #bugbounty
17.01.2026 03:33 β π 0 π 0 π¬ 0 π 0
Track deployments and changelogs.
Subscribe to status pages, RSS feeds, or GitHub commits. New code means fresh attack surface before defenders patch. #BugBounty
15.01.2026 17:10 β π 1 π 0 π¬ 0 π 0
red team writes poetry with payloads, blue team answers with firewalls. #infosec
13.01.2026 02:09 β π 0 π 0 π¬ 0 π 0
prompt injection is just sql injection for robots. #bugbounty #AIsecurity
10.01.2026 03:33 β π 0 π 0 π¬ 0 π 0
The scariest zero-day isnβt in codeβitβs the coworker who clicks βEnable Macrosβ before finishing their morning coffee. #infosec
09.01.2026 00:49 β π 1 π 0 π¬ 0 π 0
BREAKING: xAI Shatters All Records with $20 Billion Funding Round.
#xAI has just made history by securing the largest funding round ever recorded.
xAI is building #Colossus. A supercomputer of unprecedented scale designed to train their AI assistant Grok.
08.01.2026 15:41 β π 1 π 0 π¬ 0 π 0
OpenAI introduces Health mode.
You can now upload your lab results and get instant, easy-to-understand breakdowns of what those numbers actually mean.
#openai #medicalAI #health #ai
08.01.2026 15:30 β π 2 π 0 π¬ 0 π 1
Bug bounty reality: 3 days of recon, 2 days of exploitation, and a $0 βduplicateβ payout in 3 seconds. #BugBounty
08.01.2026 02:15 β π 0 π 0 π¬ 0 π 0
If you're running n8n in production, treat this as a top priority emergency patch. Your automation security depends on it.
#n8n #CyberSecurity #SecurityAlert #WorkflowAutomation #CriticalUpdate #InfoSec #TechNews #SecurityPatch #Automation #DevOps
07.01.2026 14:37 β π 1 π 0 π¬ 0 π 0
yeah i agree. wasnβt impressed with the direction they took it!
07.01.2026 07:04 β π 1 π 0 π¬ 0 π 0
π₯
07.01.2026 07:03 β π 0 π 0 π¬ 0 π 0
blogger, thinker, space, tennis, manutd, ferarri F1, and other random bs.
visit: https://spacesanjeet.github.io/Sanjeet-Homepage/
and: https://astrosanjeet.wordpress.com/
Global leader in AI cybersecurity, securing almost 10,000 organizations by learning from unique data in real time to detect and counter threats with precision and speed.
AI, Cloud, Productivity, Computing, Gaming & Apps βοΈ
We build secure, scalable, and private enterprise-grade AI technology to solve real-world business problems. Join us: http://cohere.com/careers
We're an Al safety and research company that builds reliable, interpretable, and steerable Al systems. Talk to our Al assistant Claude at Claude.ai.
Print design >> environmental design >> experience design >> AI design
Creative Director / AI Strategist / Artist / Curator / Book Nerd / Flower Lover
Parent, spouse, Australian, Professor of Machine Learning in Oxford. Long Covid, trans rights, music, reggae on Fridays, AI must be good for humans, https://www.robots.ox.ac.uk/~mosb
Visiting Postdoc Scholar @UVA
Previously: PhD Imperial, Evidation Health, Samsung AI
Researching core ML methods as well as computational/statistical methods in biomedicine, health and law
arinbjorn.is
πSwitzerland
Situationist Cybernetics. Gates Scholar researching AIβs impacts on the Humanities, University of Cambridge. Affiliated Researcher, Machine Visual Culture Research Group (Max Planck Institute, Rome). Aim to be kind. cyberneticforests.com
Assistant professor of biomedical data science and dermatology at Stanford. AI for healthcare. Associate editor at NEJM AI and the Journal of Investigative Dermatology. Mother of a sassy girl and a baby boy.
The latest technology news and analysis from the world's leading engineering magazine.
Canadian in Taiwan. Emerging tech writer, and analyst with a flagship Newsletter called A.I. Supremacy reaching 115k readers
Also watching Semis, China, robotics, Quantum, BigTech, open-source AI and Gen AI tools.
https://www.ai-supremacy.com/archive
Prof (CS @Stanford), Co-Director @StanfordHAI, Cofounder/CEO @theworldlabs, CoFounder @ai4allorg #AI #computervision #robotics #AI-healthcare
Professor, researcher, maker of things
~Book: Atlas of AI
~Installation: Calculating Empires
~NYT video: AI's Real Environmental Impact https://www.nytimes.com/2025/09/26/opinion/ai-quartz-mining-hurricane-helene.html
Personal Account
Founder: The Distributed AI Research Institute @dairinstitute.bsky.social.
Author: The View from Somewhere, a memoir & manifesto arguing for a technological future that serves our communities (to be published by One Signal / Atria
Book: https://thecon.ai
Web: https://faculty.washington.edu/ebender
A LLN - large language Nathan - (RL, RLHF, society, robotics), athlete, yogi, chef
Writes http://interconnects.ai
At Ai2 via HuggingFace, Berkeley, and normal places