Tag
medium
advisory
OpenClaw Agent Suspicious Child Process Execution
2 rules 10 TTPs 3 IOCsMalicious actors are exploiting OpenClaw, Moltbot, and Clawdbot AI coding agents via Node.js to execute arbitrary shell commands and download-and-execute commands, potentially targeting cryptocurrency wallets and credentials.
ai-agent
execution
malware
credential-theft
2r
10t
3i
medium
advisory
HushSpec: Security Policy Specification for AI Agent Action Boundaries
2 rules 1 TTP 2 IOCsHushSpec is an open specification under development to standardize security policies at the action boundary of AI agents, focusing on actions such as file access, network egress, and shell execution, aiming to create a portable and engine-agnostic policy layer.
AI-Agent
security-policy
action-boundary
2r
1t
2i
high
advisory
Unscoped API Keys in AI Agent Frameworks
2 rules 1 TTP 2 IOCsA research report auditing popular AI agent projects found that 93% rely on unscoped API keys as the only authentication mechanism, leading to potential credential exposure, privilege escalation, and lateral movement within multi-agent systems.
ai-agent
api-key
authorization
credential-theft
2r
1t
2i