ToxSec's Avatar

ToxSec

@toxsec.bsky.social

⚠️ AI Security Engineer M.S. Cybersecurity, CISSP. Amazon, NSA, Defense Contractor, USMC. 🫟 www.toxsec.com

169 Followers  |  32 Following  |  999 Posts  |  Joined: 07.09.2025  |  1.5462

Latest posts by toxsec.bsky.social on Bluesky

The lethal trifecta: private data access + untrusted content exposure + external comms. #OpenClaw adds a fourthβ€”persistent memory. Now attackers can fragment payloads across days and assemble them later. The self-hosted AI dream is real. The security model isn’t.​​​​​​​​​​​​​​​​

02.02.2026 20:41 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
OpenClaw and Moltbook: The Viral AI Agent and Security Nightmare πŸ¦€ How self-hosted AI assistants with shell access, plaintext credentials, and persistent memory created the lethal trifecta--plus the bots built their own social network

www.toxsec.com/p/openclaw-a...

02.02.2026 20:39 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

OpenClaw hit 123K GitHub stars in 48 hours. Self-hosted AI with shell access, plaintext creds, and WhatsApp integration.

Cisco called it β€œan absolute nightmare.” Then somebody built a social network where the bots prompt-inject each other.

02.02.2026 20:34 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

bug hunting is archaeology with curl. #bugbounty

01.02.2026 17:05 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

llms are basically web apps that answer politely while leaking secrets. #AIsecurity

31.01.2026 03:33 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
PSA:Moltbot Is Wildly Insecure How open-source AI agents expose API keys, enable RCE via prompt injection, and why your β€œlocal” butler is probably internet-facing right now

Bet? Most aren't secured. Defaults win, security loses.
Full breakdown of the architecture flaws, real exploits (one researcher grabbed an SSH key in 5 mins via email), and a hardening checklist in the article:
PSA: Moltbot Is Wildly Insecure
www.toxsec.com/p/moltbot-is...

30.01.2026 16:18 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

My fresh Shodan pull (post-rebrand, filtered to Clawdbot favicon + port): ~3k exposed instances still sitting there.
Many leaking everything: creds in plaintext (~/.moltbot/credentials/), full histories via WebSocket, unauth command exec, prompt injection turning Gmail into an exfil vector.

30.01.2026 16:18 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

The Moltbot hype train went viral β†’ 60k+ GitHub stars in weeks β†’ people spinning up on Mac Minis, VPSes, home servers with defaults that bind to 0.0.0.0:18789 and trust localhost like it's 2005.

30.01.2026 16:18 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0

hunting logs is just digital birdwatching for blue teamers. #cybersecurity

30.01.2026 00:49 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

timeline: 45-day opt-in May 2026, 64-day default Feb 2027, full 45-day rollout Feb 2028. check your cron jobs. that hardcoded 60-day renewal interval is now a ticking outage.

28.01.2026 02:05 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

the security logic is sound. shorter cert lifetimes = smaller blast radius when keys get popped. revocation has always been a polite fiction anyway. this forces the automation that should’ve happened years ago.

28.01.2026 02:05 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

let’s encrypt is cutting cert lifetimes to 45 days by 2028. the real pain: authorization reuse drops from 30 days to 7 hours. if you’re still manually renewing certs, congrats β€” you now have a part-time job.

28.01.2026 02:05 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0
Preview
The Hacker News | #1 Trusted Source for Cybersecurity News The Hacker News is the top cybersecurity news platform, delivering real-time updates, threat intelligence, data breach reports, expert analysis, and actionable insights for infosec professionals and d...

china-linked hackers have been inside north american critical infrastructure for over a year, quietly grabbing access

cisco talos spotted a china-nexus apt (uat-8837) targeting key sectors like energy and utilities since at least last year.

27.01.2026 02:45 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

securing rag is like securing a search engine that doesn’t know when to shut up. #AIsecurity

27.01.2026 02:09 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

ai models are like cats: you think you own them, but they do whatever they want. #AIsecurity

25.01.2026 18:10 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

pentesters get the glory, defenders get the alerts. #cybersecurity

24.01.2026 03:33 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Built a perfect exploit chain, only to learn the target patched it this morning because a different researcher reported it first. #bugbounty

22.01.2026 02:15 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Spent half the night chasing a weird auth bug…turns out someone rotated the API key during your test window. #bugbounty

20.01.2026 02:09 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

pentests feel like chess, bug bounties feel like dumpster diving. #bugbounty

18.01.2026 17:05 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

why do all staging servers have cooler bugs than prod? #bugbounty

17.01.2026 03:33 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Track deployments and changelogs.
Subscribe to status pages, RSS feeds, or GitHub commits. New code means fresh attack surface before defenders patch. #BugBounty

15.01.2026 17:10 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

red team writes poetry with payloads, blue team answers with firewalls. #infosec

13.01.2026 02:09 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

prompt injection is just sql injection for robots. #bugbounty #AIsecurity

10.01.2026 03:33 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

The scariest zero-day isn’t in codeβ€”it’s the coworker who clicks β€œEnable Macros” before finishing their morning coffee. #infosec

09.01.2026 00:49 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Video thumbnail

BREAKING: xAI Shatters All Records with $20 Billion Funding Round.

#xAI has just made history by securing the largest funding round ever recorded.

xAI is building #Colossus. A supercomputer of unprecedented scale designed to train their AI assistant Grok.

08.01.2026 15:41 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Video thumbnail

OpenAI introduces Health mode.

You can now upload your lab results and get instant, easy-to-understand breakdowns of what those numbers actually mean.
#openai #medicalAI #health #ai

08.01.2026 15:30 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 1

Bug bounty reality: 3 days of recon, 2 days of exploitation, and a $0 β€œduplicate” payout in 3 seconds. #BugBounty

08.01.2026 02:15 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Video thumbnail

If you're running n8n in production, treat this as a top priority emergency patch. Your automation security depends on it.

#n8n #CyberSecurity #SecurityAlert #WorkflowAutomation #CriticalUpdate #InfoSec #TechNews #SecurityPatch #Automation #DevOps

07.01.2026 14:37 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

yeah i agree. wasn’t impressed with the direction they took it!

07.01.2026 07:04 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

πŸ”₯

07.01.2026 07:03 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@toxsec is following 20 prominent accounts