The Oasis researchers document a vulnerability chain that can be initiated from any website the AI agent (or its user) visits, without users needing to interact in any way or being at all aware that they are being compromised. The attack targets the OpenClaw "gateway" that essentially acts as the AI agent's nerve center.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Security researchers discovered 9,000 unsecured internet-facing VNC servers that threat actors could use to access internal networks, including critical infrastructure organizations.
New research from security firm Dragos finds that Volt Typhoon, one of the primary groups of state-sponsored Chinese hackers menacing the US as of late, was able to dwell in the Massachusetts electric grid for more than 300 days beginning in early 2023.
Security researchers at SafeBreach discovered a method to collect millions of stolen user credentials through Google's malware analysis platform, VirusTotal without compromising any organizations.
Researchers document some 18,000 posts that appear to have come from OpenAI agents in a short amount of time, as they worked away at some sort of task and collaborated to break out of their own sandbox restrictions.
A ChatGPT vulnerability documented in a new report causes training data, some containing personal information, to randomly appear when one tells the chatbot to repeat a particular word.
XIoT devices are laden with security risks. 68% have a known vulnerability with a CVSS score of at least 8 and 18% are carrying a vulnerability of at least 9. And the average organization has three to five XIoT devices per employee.
Security Service Edge (SSE) converges multiple cybersecurity capabilities within a single, cloud-native software stack, and is designed to protect all enterprise edges – sites, users and applications, including the IoT-connected points — even as the contours of those edges shift.
Code obfuscation prevents the reverse-engineering of programs and is used to protect sensitive intellectual property (IP) such as algorithms that a company doesn’t want bad actors or competitors to see; the foremost example of this being security code.
Check Point discovered another security vulnerability in Qualcomm chips affecting 40% of smartphones, allowing hackers to inject code in Android phones, including Google, Samsung, LG, Xiaomi, and One Plus brands.










