Treatmybrand


a Kainjoo SA Venture
Ch. du Vernay 14a
1196 Gland
+41.21.561.34.96
[email protected]

Support


Monday to Friday
8AM to 8PM
[email protected]
Back

Clawdbot Emerges as Primary Target for Infostealers Amid Rapid Adoption and Security Flaws

Clawdbot, an open-source AI agent that automates tasks across email, files, calendar, and development tools, has quickly become a prime target for infostealers. Its MCP implementation lacks mandatory authentication, allowing for prompt injection and shell access by design, exposing hundreds of instances to the public internet. Infostealers like RedLine, Lumma, and Vidar exploited these vulnerabilities before security teams could respond. The malware not only steals credentials but also psychological profiles, aiding sophisticated social engineering attacks. Despite quick patches, fundamental architectural issues remain, such as plaintext storage of sensitive data and no supply chain vetting. Security experts urge treating AI agents as critical infrastructure, emphasizing inventory, access controls, runtime monitoring, and provenance verification. The rapid weaponization underscores the need for immediate and comprehensive security measures as AI agent integration in enterprise applications surges.

Venturebeat
Venturebeat