OpenClaw AI Agent Flaws Could Enable Prompt Injection and Data Exfiltration

0

Ravie LakshmananMar 14, 2026Artificial Intelligence / Endpoint Security

China’s National Computer Network Emergency Response Technical Team (CNCERT) has issued a warning about the security stemming from the use of OpenClaw (formerly Clawdbot and Moltbot), an open-source and self-hosted autonomous artificial intelligence (AI) agent.

In a post shared on WeChat, CNCERT noted that the platform’s “inherently weak default security configurations,” coupled with its privileged access to the system to facilitate autonomous task execution capabilities, could be explored by bad actors to seize control of the endpoint.

This includes risks arising from prompt injections, where malicious instructions embedded within a web page can cause the agent to leak sensitive information if it’s tricked into accessing and consuming the content.

The attack is also referred to as indirect prompt injection (IDPI) or cross-domain prompt injection (XPIA), as adversaries, instead of interacting directly with a large language model (LLM), weaponize benign AI features like web page summarization or content analysis to run manipulated instructions. This can range from evading AI-based ad review systems and influencing hiring decisions to search engine optimization (SEO) poisoning and generating biased responses by suppressing negative reviews.

OpenAI, in a blog post published earlier this week, said prompt injection-style attacks are evolving beyond simply placing instructions in external content to include elements of social engineering.

“AI agents are increasingly able to browse the web, retrieve information, and take actions on a user’s behalf,” it said. “Those capabilities are useful, but they also create new ways for attackers to try to manipulate the system.”

The prompt injection risks in OpenClaw are not hypothetical. Last month, researchers at PromptArmor found that the link preview feature in messaging apps like Telegram or Discord can be turned into a data exfiltration pathway when communicating with OpenClaw by means of an indirect prompt injection.

The idea, at a high level, is to trick the AI agent into generating an attacker-controlled URL that, when rendered in the messaging app as a link preview, automatically causes it to transmit confidential data to that domain without having to click on the link.

“This means that in agentic systems with link previews, data exfiltration can occur immediately upon the AI agent responding to the user, without the user needing to click the malicious link,” the AI security company said. “In this attack, the agent is manipulated to construct a URL that uses an attacker’s domain, with dynamically generated query parameters appended that contain sensitive data the model knows about the user.”

Besides rogue prompts, CNCERT has also highlighted three other concerns –

  • The possibility that OpenClaw may inadvertently and irrevocably delete critical information due to its misinterpretation of user instructions.
  • Threat actors can upload malicious skills to repositories like ClawHub that, when installed, run arbitrary commands or deploy malware.
  • Attackers can exploit recently disclosed security vulnerabilities in OpenClaw to compromise the system and leak sensitive data.

“For critical sectors – such as finance and energy – such breaches could lead to the leakage of core business data, trade secrets, and code repositories, or even result in the complete paralysis of entire business systems, causing incalculable losses,” CNCERT added.

To counter these risks, users and organizations are advised to strengthen network controls, prevent exposure of OpenClaw’s default management port to the internet, isolate the service in a container, avoid storing credentials in plaintext, download skills only from trusted channels, disable automatic updates for skills, and keep the agent up-to-date.

The development comes as Chinese authorities have moved to restrict state-run enterprises and government agencies from running OpenClaw AI apps on office computers in a bid to contain security risks, Bloomberg reported. The ban is also said to extend to the families of military personnel.

The viral popularity of OpenClaw has also led threat actors to capitalize on the phenomenon to distribute malicious GitHub repositories posing as OpenClaw installers to deploy information stealers like Atomic and Vidar Stealer, and a Golang-based proxy malware known as GhostSocks using ClickFix-style instructions.

“The campaign did not target a particular industry, but was broadly targeting users attempting to install OpenClaw with the malicious repositories containing download instructions for both Windows and macOS environments,” Huntress said. “What made this successful was that the malware was hosted on GitHub, and the malicious repository became the top-rated suggestion in Bing’s AI search results for OpenClaw Windows.”



Source link

LIVE: Real Madrid vs Elche – La Liga | Football News

0



Source link

UP Politics: Ruckus on the question of UP Police SI exam! BJP MLA cornered Yogi government, wrote letter to CM

0

Controversy has arisen regarding a question of the UP Police Sub-Inspector (SI) recruitment examination held in Uttar Pradesh. Objecting to a question asked in the Hindi paper, the BJP MLA appealed to the Chief Minister. Yogi Adityanath Have written a letter demanding action.

In the Hindi section of this examination held on March 14, 2026, a question was asked, “Answer in one word for those who change as per the occasion.” Its options were Pandit, Opportunist, Sincere and Virtuous. In this, a controversy has started over the inclusion of the word ‘Pandit’ as an option. Some people say that this may hurt the sentiments of a particular section.

There should be a departmental inquiry against the committee that sets the paper – Ramesh Chandra Mishra

On this issue, BJP MLA from Badlapur, UP, Ramesh Chandra Mishra wrote a letter to the Chief Minister saying that this question asked in the Hindi paper is very objectionable and sensitive. According to him, the correct answer to ‘changes according to the occasion’ is opportunist, but it is wrong to include the word ‘Pandit’ among the options. He said that the word ‘Pandit’ is associated with a scholar and religious respect, hence associating it with a negative meaning is inappropriate and insensitive. He has demanded a departmental inquiry and strict action against the committee that sets the paper.

Read this also- Bulandshahr News: 8 year old child shot in harsh firing at a wedding, brother of the accused committed suicide by consuming poison

Abhijat Mishra wrote a letter to CM demanding action

BJP state minister Abhijat Mishra has also raised questions in this matter by writing a letter to the Chief Minister. He said that such a question raises questions on the fairness of the examination and can send a wrong message to the society.

BJP leaders have demanded from the government that this question should be officially rejected and special care should be taken of sensitivity and social harmony while preparing exam questions in future. After this matter came to light, the discussion has intensified in the politics of the state also.

Read this also- Clash over ‘Pandit’ question in UP Police SI exam, Brajesh Pathak said – this is absolutely not acceptable

America targeted more than 90 targets on Iran’s Kharg Island, video surfaced

0

Show Quick Read

Key points generated by AI, verified by newsroom

On Friday (March 13, 2026), the US military carried out a large-scale, precision attack on Kharg Island, which is said to be Iran’s largest oil export hub. Giving this information on Saturday (March 14, 2026), America’s Central Command (CENTCOM) has also released a video of the attack.

Centcom released video on social media

Centcom shared the video of the attack on Kharg Island by the US Army on social media platform X. The post said that the US military successfully targeted more than 90 Iranian military targets on Kharg Island, while oil-related infrastructure was protected.

Along with this, a silent video of about one minute was also released, in which missiles were seen falling on the island and huge clouds of smoke were seen rising. Centcom’s black and white video footage shows massive devastation. According to the US Army, naval mine storage bunkers, missile storage bunkers and many other military bases were destroyed in this attack.

Kharg exports crude oil to China

Most of Iran’s oil is exported from Kharg Island, a large part of which is sent to China. China is the world’s largest importer of crude oil and has taken several steps, including a ban on exports of refined fuel, to secure supplies due to the growing crisis in the Middle East.

US President threatened

US President Donald Trump threatened on Friday (March 13, 2023) that if Tehran does not stop attacks on ships in the Strait of Hormuz, the oil-related infrastructure of Kharg Island could be targeted.

Shortly after the bombing, Trump said in a post on Truth Social that military bases on Kharg Island had been completely destroyed in one of the most powerful bombing campaigns in the history of the Middle East.

Also read: Big attack on American embassy in Baghdad, missile fell on helipad, sky filled with smoke

‘Don’t wear new clothes…read Namaz wearing black clothes’, message of jailed Azam Khan

0

The holy month of Ramadan is going on and March 13 was the last Friday of Ramadan. There is a lot of enthusiasm about Eid among the followers of Islam across the country, while amidst the preparations for Eid, former cabinet minister of Uttar Pradesh and senior Samajwadi Party leader Azam Khan has given a message to the Muslims from jail regarding Eid.

Azam Khan is in jail in two PAN card cases

Abdullah Azam and Azam Khan are lodged in Rampur District Jail and are serving a sentence of 7 years each in two PAN card cases. Today (14 March 2026) Yusuf Malik, close to Azam Khan and Abdullah’s friend and Azam Khan’s wife Tanzeem Fatima met Abdullah Azam and Azam Khan.

Tanzin Fatima did not talk to the media

It was told that this meeting lasted for about one to one and a half hours, after the meeting all three people came out of the jail. However, Azam Khan’s wife Tanzeem Fatima did not talk to the media. After meeting Azam Khan, Tanzeem Fatima sat in the car and left for home. Yusuf Malik told the media, “I, Abdullah’s friend and Azam Khan’s wife, all three of us met Azam Khan and Abdullah Khan.”

Yusuf, close to Azam Khan, told the message of Eid

Yusuf Malik told the media, “Azam Khan has given a message to Muslims, especially Sunni Muslims, that this time on Eid, wear black clothes and if possible, do not wear new clothes.” According to Yusuf Malik, Azam Khan said, “The incident that happened with the girls in Iran, the 160 girls killed by Israel and America, they should wear black bands and offer prayers and support Sunni Muslims. They were also our girls.”

Trump-Putin’s secret conversation on phone, Iran’s offer to send uranium to Russia? Know the whole matter

0

Show Quick Read

Key points generated by AI, verified by newsroom

Amidst efforts to end the ongoing war between America, Israel and Iran, the top leaders of the world’s two superpower countries have spoken to each other on the phone. Yes… the leaders of these two superpower countries are America’s President Donald Trump and Russia’s President Vladimir Putin. Both the leaders had talked to each other on phone only last week. During this time the President of Russia Vladimir Putin Reportedly made a proposal to US President Donald Trump, in which it was said to transfer Iran’s enriched uranium to Russia. However, President Trump has completely rejected this proposal from Russia.

According to the report of Axios, this proposal was made by Russia as part of efforts to end the ongoing tension between America, Israel and Tehran. Putin had suggested to Trump that Iran’s enriched uranium be sent to Russia.

Trump’s comment on Russia’s role

During this time, President Trump also indicated that Russia can provide limited help to Iran. He said in an interview to Fox News, ‘I think he (Putin) might be helping them a little and he might also think that we are helping Ukraine. So yes, we are also helping them. He said that such situations are common in global politics. Countries often take steps according to their own interests. They say and China will also say exactly the same thing that look, they are also doing it, so we are also doing it. This is completely justified.

Separate statements from US officials

This comment of Trump appears different from the earlier statement given by his Middle East envoy Steve Witkoff. Witkoff had said that Russia has made it clear in talks with America that it is not sharing any intelligence information with Iran.

Also read: Iran-US War: ‘US’s biggest warship also failed…’, Iran’s big claim, know what is its appeal to Muslim countries

Protests erupt in Cuba as US restrictions spark food, energy shortages | Protests News

0

Authorities say a local communist party office was lit on fire during rare antigovernment demonstration on the island.

Protesters in central Cuba have torched a local communist party office, as conditions on the island continue to deteriorate under severe restrictions from the United States meant to squeeze the economy.

Authorities said on Saturday that five people were arrested amid what the government called “vandalism acts” in the city of Moron.

Recommended Stories

list of 3 itemsend of list

“What began peacefully, after an exchange with the authorities in the area, degenerated into vandalism against the headquarters of the municipal committee of the Communist Party,” the state-run newspaper Invasor said of the incident.

Unverified videos of the incident show protesters breaking into the office and throwing stones at a burning building. Shouts of “liberty” could be heard in one of the videos, according to the news agency Reuters.

Other government buildings were also reportedly damaged overnight. No injuries have been confirmed so far, though the details of the protest and its aftermath remain unclear.

The human rights group Justicia11 said that gunfire was heard in the area and a man may have been shot, but a state-run news outlet, Vanguardia de Cuba, meanwhile, denied those reports.

Protests are relatively rare in Cuba, given the threat of government repression. But in recent weeks, Cubans have expressed growing frustration with food and electricity shortages.

Some have taken to banging pots and pans at night — a protest tradition called “cacerolazo” — to express anger over the lack of food. Students, meanwhile, at the University of Havana held a sit-in on Monday after their classes were suspended due to energy restrictions.

Economic conditions on the island, already strained, have worsened since United States President Donald Trump cut off its access to oil as he seeks to topple the government in Havana, a longtime target of US ire.

Cuban President Miguel Diaz-Canel said on Friday that he had held talks with US officials and that no petroleum shipments have arrived in Cuba for three months.

Trump ordered an end to transfers of Venezuelan oil and funds to Cuba after the US carried out an attack on Venezuela on January 3. That attack culminated in the abduction of former Venezuelan President Nicolas Maduro, who had maintained friendly relations with Cuba.

On January 29, Trump upped the ante, issuing an executive order that effectively severed Cuba’s ability to import fossil fuels from other countries. The order threatened economic penalties against any country that supplied Cuba with oil, whether directly or indirectly.

Cuba’s ageing energy grid, however, largely relies on fossil fuel, as do everyday tools like cars and generators.

During remarks earlier this month, Trump said that Cuba would be “next” after the US war against Iran concludes.

“Cuba’s at the end of the line,” Trump told a group of Latin American leaders at his estate, Mar-a-Lago, on March 7.

“As we achieve a historic transformation in Venezuela, we’re also looking forward to the great change that will soon be coming to Cuba.”



Source link

Kuldeep Yadav Vanshika Chadha Wedding: Kuldeep Yadav got married, Vanshika looked very beautiful in lehenga, see first photo.

0

homegameCricket

Kuldeep Yadav tied the knot, Vanshika looked very beautiful in lehenga

Last Updated:

kuldeep yadav vanshika Chadha wedding first photo: Indian World Cup winning cricketer Kuldeep Yadav has tied the knot. In Mussoorie, Uttarakhand, Kuldeep took seven trips with his childhood friend Vanshika Chadha. Many stars of the cricket world were present in this function held in the luxury resort. Vanshika looked very beautiful in the wedding dress. The first photo of Kuldeep and Vanshika’s wedding has been revealed.

Kuldeep Yadav tied the knot, Vanshika looked very beautiful in lehengaZoom
Kuldeep Yadav took seven rounds with Vanshika Chadha.

New Delhi. Indian cricket team’s star spinner Kuldeep Yadav has started a new innings by marrying his childhood friend Vanshika Chadha in Mussoorie. The first picture of this couple’s wedding has also been revealed. This photo is also going viral on social media. Kuldeep and Vanshika’s wedding took place at a luxury resort in Mussoorie, which was attended by many of their friends including close family members. Many famous faces from the cricket world also came to enjoy Kuldeep’s wedding.

In the pictures going viral online, Kuldeep can be seen wearing a traditional sherwani, while Vanshika Chadha is looking very beautiful in a heavily embroidered scarlet lehenga. During the varmala, the couple was seen smiling while garlanding each other. During this time, relatives and friends were seen around him celebrating the occasion. Many videos of the function are also going viral on social media.

Kuldeep Yadav took seven rounds with Vanshika Chadha.

Many cricketers attended the wedding
Many big stars of Indian cricket world attended this grand wedding. Yuzvendra Chahal is already having a lot of fun at Kuldeep’s wedding, with the wedding function going on two days ago. Many of her dance videos went viral on social media. Apart from Chahal, former batsmen Suresh Raina and Mohammad Kaif were also seen at the wedding. Rinku Singh also arrived to attend the wedding with his future wife Priya Saroj. Apart from this, Piyush Chawla, Tilak Verma and coach T Dilip were also seen on this occasion.

Kuldeep Yadav took seven rounds with his childhood friend.

Pandit Dhirendra Shastri of Bageshwar Dham also reached Mussoorie to bless Kuldeep Yadav. Cricketer Nitish Rana also attended Kuldeep-Vanshika’s ceremony with his wife. Let us tell you that Kuldeep and Vanshika are also going to give a grand reception after the marriage. It will be organized on March 17 in a luxury hotel in Lucknow. Many big names of Indian cricket are expected to participate in this also. Uttar Pradesh Chief Minister Yogi Adityanath may also be present in the reception, whom Kuldeep’s father Ramsingh Yadav had met and invited.

‘Liquor ban is fake, 30 thousand crores are going into the pockets of mafia’, Prashant Kishore said loss to revenue

0

Jan Suraj Party founder Prashant Kishore has made the sharpest attack so far on the ground reality of complete prohibition in Bihar. While speaking to journalists in Jehanabad, he termed this law of the state government as ‘fraud’ and demanded its abolition with immediate effect.

His clear allegation is that under the cover of this law, people associated with power and liquor mafia have created a parallel economy.

huge loss of revenue and mafias Silver

Prashant Kishore exposed the economic and administrative hollowness of liquor ban and made serious allegations against the system. The state government is facing a huge loss of revenue of about Rs 30 thousand crores every year. The money which was supposed to be used for the development of Bihar, is now going directly into the pockets of liquor mafia and corrupt leaders.

Home Delivery Syndicate

Liquor prohibition is limited to papers only. In reality, smuggling is going on rampant from other states and liquor is being sold easily in every village and town of Bihar. The corrupt system deliberately wants to continue this so that their illegal earnings do not stop.

New consignment of drugs and scary figures of deaths

PK expressed deep concern over the social side effects of prohibition and said that due to this the young generation of the state is on the verge of ruin. After prohibition, a new and dangerous trend has started in the villages of Bihar. Due to non-availability of liquor or its being expensive, youth are now falling prey to ‘dry drugs’ like ganja and smack, which was not the reality in Bihar earlier.

Death toll due to poisonous liquor

Referring to the recent death of 5 people due to poisonous liquor, he reminded that 70-80 people had died simultaneously in Chapra. Since 2016, more than 5,000 people have become victims of poisonous liquor, but the government is adamant on its insistence.

Prashant Kishore clarified that this law has not done any good to the society, rather it has created a new nexus of corruption and deaths, which should be stopped immediately.

Data brokers hid opt-out pages from Google after Senate probe

0

NEWYou can now listen to Fox News articles!

If you have ever tried to opt out of a data broker site, you know the drill. You search. You scroll. You click through layers of legal jargon. Then you wonder if they even want you to find the exit door. Now we know the answer.

A U.S. Senate investigation found that several major data brokers placed code on their opt-out pages that blocked search engines from indexing them. In practical terms, that meant you could not easily find the page where you ask them to stop selling your data.

After pressure from Sen. Maggie Hassan, four companies have now removed that code.

Sign up for my FREE CyberGuy Report 
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Which data brokers hid their opt-out pages?

The companies named in the report include:

  • Comscore
  • IQVIA Digital
  • Telesign
  • 6sense Insights

These firms collect and sell personal information for marketing, analytics or identity verification. That data can include browsing behavior, device details, location history and in some cases highly sensitive identifiers.

List of company "no index" codes

A U.S. Senate investigation found major data brokers used no index code to hide opt-out pages from Google, making it harder for people to stop the sale of their personal data.   (Kurt “CyberGuy” Knutsson)

An earlier investigation by The Markup and CalMatters found that dozens of brokers used “no index” code to hide opt-out instructions from Google search results. Some removed the code after reporters reached out. However, Sen. Hassan’s office later found that the four companies above still had opt-out pages blocked from search engines. They have since removed the code.

MAKE 2026 YOUR MOST PRIVATE YEAR YET BY REMOVING BROKER DATA

One more company, Findem, has not removed the no-index code from its “Do not sell or share my personal information” page, according to the report. The company later said an email from the senator’s office did not reach its CEO due to spam filtering and that its privacy channels are actively monitored. The Committee report noted this lack of action raises serious concerns about responsiveness to privacy requests and about whether opt-out rights are being made truly accessible.

We reached out to all five companies for comment. A spokesperson for 6sense provided the following statement:

“6sense takes privacy transparency seriously and has always fully indexed our Privacy Center, where individuals may exercise their opt-out rights in compliance with applicable laws. For a period of time, we included a “no index” directive on the Privacy Policy page to reduce spam volume to privacy request email aliases and protect the integrity of request handling systems. Once the issue was raised by the Committee, that code was immediately removed. Our Privacy Center opt-out page has remained indexed, and our Privacy Policy has always been accessible and prominently visible on our web properties, as well as directly linked in our publicly available data broker registrations. We regularly review our security and privacy practices to meet evolving regulatory requirements, and our commitment has been independently validated annually through ISO/IEC 27001:2022, ISO/IEC 42001:2023, and SOC 2, Type II certifications.”

2026 VALENTINE’S ROMANCE SCAMS AND HOW TO AVOID THEM

Woman on computer doing brain training session

6sense said it takes privacy transparency “seriously.” (iStock)

Why hidden data broker opt-out pages matter for your privacy

Opt-out pages are not a courtesy. In many states, they are required by law. When companies hide those pages from search engines, they make it harder for you to take control of your own information. And that matters. The more complicated the process feels, the more likely people are to give up halfway through. Meanwhile, data broker breaches have been expensive and damaging. Committee calculations estimate that identity theft tied to four major data broker breaches cost U.S. consumers more than $20 billion. That is not a minor privacy slip. That is real money, real consequences and real stress for families trying to clean up the mess.

Why scammers care about your data

When detailed personal information falls into the wrong hands, it fuels scams that feel alarmingly real. Criminal networks can use data like Social Security numbers, home addresses and phone numbers to create highly customized emails, texts and phone calls. The more accurate the details, the more convincing the scam. That is one reason data broker breaches are not just a privacy issue. They are a consumer protection issue.

Sen. Maggie Hassan’s investigation is part of her broader effort to combat scams, which now account for nearly half a trillion dollars in losses annually and have grown into one of the world’s largest illicit industries. She has also opened inquiries into the roles that satellite internet providers, online dating platforms, AI companies and federal agencies play in preventing fraud.

Maggie Hassan runs for reelection

The investigation was led by Democratic Sen. Maggie Hassan of New Hampshire. (Sen. Maggie Hassan reelection campaign)

What this means for your personal data and privacy

Here is the uncomfortable truth. Your personal data likely sits in dozens, maybe hundreds of databases you have never heard of. You did not sign up. You did not click agree. But your information still travels through a vast marketplace. Even when opt-out forms exist, finding and completing them can feel like a part-time job. And since the U.S. still lacks a comprehensive federal privacy law like Europe’s GDPR, rules vary by state. So yes, the opt-out pages are now easier to find for these companies. But the bigger system remains largely intact.

How to opt out of data brokers and protect your information

You cannot erase yourself from the internet overnight. However, you can reduce your exposure.

1) Search your name regularly

Type your full name and city into Google. Look for data broker listings. Many include an opt-out link buried in the privacy policy.

2) Use state privacy tools if available

California residents can use a free state-run tool called DROP at privacy.ca.gov/drop/ to request deletion from more than 500 registered brokers. Other states are rolling out similar systems.

3) Submit opt-out requests directly

Visit the privacy or “Do not sell my information” page on broker sites. Follow instructions carefully and keep confirmation emails.

4) Consider a data removal service

Data removal services can automate opt-out requests across dozens of brokers. They are not perfect, but they save time. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.

5) Lock down core accounts

Use strong, unique passwords stored in a password manager. Check out the best expert-reviewed password managers of 2026 at Cyberguy.com. Also, turn on two-factor authentication (2FA) for financial email and social accounts. That way, even if your data circulates, criminals have a harder time breaking in.

The larger problem with the data broker industry

The data broker industry is legal. It operates in plain sight. Yet most people have no idea how many companies trade in their information. Until Congress passes a national privacy law, oversight will remain patchwork. That leaves you to chase down your own records one company at a time. Transparency should not require a Senate investigation.

Kurt’s key takeaways 

This story is about more than hidden code. It is about control. When companies quietly block search engines from indexing opt-out pages, they tilt the playing field. After public scrutiny, those pages are easier to find. That is a step forward. Still, your data continues to move through an ecosystem designed to profit from it. So the real question is not whether opt-out pages appear on Google.

How much of your personal life are you comfortable leaving in the hands of companies you have never heard of? Let us know by writing to us at Cyberguy.com.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report 
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Copyright 2026 CyberGuy.com. All rights reserved.



Source link