Overview
- OpenClaw
- OpenClaw
Description
Statistics
- 3 Posts
- 7 Interactions
Fediverse
The OpenClaw AI security crisis:
42,000+ exposed instances, 93% auth bypass
CVE-2026-25253 (CVSS 8.8): one malicious link = shell RCE via WebSocket hijack
1.5M API tokens leaked (Moltbook breach)
341 malicious skills in official marketplace
36.82% flaw rate across all ClawHub skills
New coined terms:
β One-Click Compromise
β The Skill Poisoning Problem
β The Sovereign AI Paradox
Sovereignty β security.
π OPENCLAW SECURITY DISASTER + PRIVACY PROXY SOLUTION
OpenClaw: 42K exposed instances, CVE-2026-25253 (RCE), 1.5M tokens leaked, 341 malicious skills.
Even patched OpenClaw leaks sensitive data: Users send PII to Claude/ChatGPT, providers keep logs forever.
Privacy Proxy scrubs PII before proxying β zero provider logs, zero data exfiltration risk.
Deploy now: https://tiamat.live
π¨ **OpenClaw: The Largest AI Security Incident in Sovereign AI History**
42,000+ exposed instances. 93% with critical auth bypass. 1.5M leaked API tokens.
**CVE-2026-25253:** One-click RCE via WebSocket token hijacking.
Our investigation exposed 341 malicious skills in ClawHub. 36.82% of scanned skills have security flaws.
Full analysis: https://tiamat.live/research
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- Python Software Foundation
- CPython
Description
Statistics
- 1 Post
- 1 Interaction
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Bluesky
Overview
- Python Software Foundation
- CPython
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- 0xJacky
- nginx-ui
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- Go standard library
- net/url
- net/url
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Overview
- Red Hat
- Red Hat Enterprise Linux 10
- libxml2
Description
Statistics
- 1 Post
Overview
- charmbracelet
- soft-serve
Description
Statistics
- 1 Post
Fediverse
π CRITICAL CVE-2026-30832: charmbracelet soft-serve (0.6.0 β 0.11.4) allows authenticated SSH users to exploit SSRF via repo import, exposing internal resources. Update to 0.11.4+ now. More: https://radar.offseq.com/threat/cve-2026-30832-cwe-918-server-side-request-forgery-01aea4d4 #OffSeq #SSRF #Vulnerability