Google’s disruption rips millions out of devices out of malicious network

0

Millions of devices used as proxies by cybercriminals, espionage groups and data thieves have been removed from circulation following Google’s disruption of IPIDEA, a China-based residential proxy network. The reduction in available proxy devices came after Google’s Threat Intelligence Group used legal action and intelligence sharing to target the company’s domain infrastructure, Google said in a blog post Wednesday. 

Google’s action, aided by Cloudflare, Lumen’s Black Lotus Labs and Spur, impaired some of IPIDEA’s proxy infrastructure, but not all of it. The coordinated strikes against malicious infrastructure underscore the back-and-forth struggle threat hunters confront when they take out pieces of cybercriminals’ vast and growing infrastructure. 

Initial data indicates IPIDEA’s proxy network was cut by about 40%.

“We have still seen around 5 million distinct bots communicating with the IPIDEA command and control servers, so as of now they are still able to operate with a large volume of proxies,” Chris Formosa, senior lead information security engineer at Lumen Technologies’ Black Lotus Labs, told CyberScoop Thursday.

Lumen was tracking a daily average of about 8.5 million proxies connecting to IPIDEA’s servers before some of its domains were taken offline this week. “The true population was likely closer to 10-11 million, but we could only see 8.5 million of them with our visibility,” Formosa said.

Google researchers discovered a cluster of seemingly independent proxy and virtual private network brands controlled by IPIDEA. Google found several domains also owned by IPIDEA supporting software development kits for residential proxies embedded into existing applications.

Developers who add these SDKs to their apps are paid by IPIDEA, typically on a per-download basis. “These SDKs are the key to any residential proxy network—the software they get embedded into provides the network operators with the millions of devices they need to maintain a healthy residential proxy network,” Google said in the report.

Residential proxy networks can serve a legitimate purpose, but researchers have been warning that unethical or outright criminal operators are abusing these networks to build and support botnets, cybercrime campaigns, espionage and other malicious activity.

“The residential proxy industry appears to be rapidly expanding, and GTIG’s research indicates that the vast majority of its growth is fueled by malicious use,” Charley Snyder, senior manager at GTIG, told CyberScoop. “GTIG found that these proxies are overwhelmingly misused by bad actors.”

Researchers said many service providers are packaging proxy malware in software that users are downloading, and unwittingly allowing proxy networks to hijack consumer bandwidth to obscure cybercrime.

Earlier this month, Google said it observed more than 550 distinct threat groups, including some from China, North Korea, Iran and Russia, using IP addresses tracked as IPIDEA exit notes during a seven-day period. These threat groups accessed victim cloud environments, on-premises infrastructure and initiated password-spray attacks, according to Google.

Security teams and cyber authorities are placing more attention on the systems and scaffolding that support cybercrime, effectively trying to squeeze resources and place additional pressure on their activities.

“By targeting the tools criminals use rather than just the criminals themselves, defenders can impose significant costs on the ecosystem in a way that can’t easily or quickly be regenerated,” Snyder said. 

Google’s actions severed the command-and-control links between operators and millions of devices, and took down storefronts, negating the investments IPIDEA made to gain brand awareness and traction, he added. 

While Google took a big bite out of IPIDEA’s infrastructure, the fight against the company and others continues. 

“This is a very complex ecosystem with dozens, if not hundreds, of brands and shell entities,” Snyder said. “While our disruption is significant, this ecosystem is built on anonymity and shared resources. They’ve survived takedowns before, so we are pleased by the progress we’ve made but know there is more to do.”

Matt Kapko

Written by Matt Kapko

Matt Kapko is a reporter at CyberScoop. His beat includes cybercrime, ransomware, software defects and vulnerability (mis)management. The lifelong Californian started his journalism career in 2001 with previous stops at Cybersecurity Dive, CIO, SDxCentral and RCR Wireless News. Matt has a degree in journalism and history from Humboldt State University.



Source link

‘I don’t think this was a good decision’: Labor’s Ed Husic holds ‘deep concerns’ over Israeli president Isaac Herzog’s visit | Australia news

0

Labor MP Ed Husic has “deep concerns” about the impending visit of Israel’s president, Isaac Herzog, saying it is hard to reconcile concepts of social cohesion with the 2023 image of the leader signing an artillery shell about to be dropped on Gaza.

Husic said he did not believe it was a good decision for his Labor government to issue an invitation for Herzog to visit Australia, which was done in the wake of the Bondi terror attack.

He also said he backed the right of Australians to peacefully protest against the actions of the Israeli government over its bombardment of Gaza, calling it a “slur” to link major protests against the war to the Bondi shooting at a Jewish festival.

“I’m obviously very uncomfortable about this visit, largely because president Herzog has said some things that have attempted to sheet home responsibility for October 7 to an entire population,” Husic told Guardian Australia’s Full Story podcast.

“This had attracted the attention of the international court of justice. And you’ve got, obviously, indictments from the international criminal court that are at play.

“It’s really hard for me to reconcile the vision of him signing bombs that went on to be dropped on Palestinian homes … with the notion of social cohesion. So from that perspective, I’ve obviously got deep concerns.”

A charge of genocide against Israel has been brought before the international court of justice by South Africa, but the court has yet to issue its judgment.

Separately, the international criminal court has issued arrest warrants for the Israeli prime minister, Benjamin Netanyahu, and the former defence secretary Yoav Gallant over allegations of war crimes.

Sign up: AU Breaking News email

No warrant has been issued for Herzog.

Herzog will visit Australia next week at the invitation of the governor general, Sam Mostyn, to meet Jewish communities after the Bondi terror attack, where 15 people were killed at a Hanukah festival in December 2025.

Herzog is Israel’s head of state, as opposed to Netanyahu, who wields executive power as the nation’s prime minister.

Asked whether it was a mistake for the government to invite Herzog to visit, Husic said: “I’m entitled to have a differing view and my view is I don’t think that this was a good decision, but it’s going to happen. Nothing I can say about that is going to stop that.”

Albanese has said it is “entirely appropriate for the head of state to visit” Australia after the Bondi attack, but Herzog’s visit will be met by protests from pro-Palestine groups as a growing number of politicians – both inside and outside Labor – raise concern about Israel’s war on Gaza and resulting civilian death toll.

Critics of Herzog’s visit have pointed to the United Nations commission of inquiry’s conclusion in September 2025 that Israel had committed genocide in Gaza. That commission, which does not speak on behalf of the UN, stated Herzog, Netanyahu and Gallant “incited the commission of genocide”.

The report quoted Herzog in October 2023 saying about Gaza: “It’s an entire nation out there that is responsible. It is not true, this rhetoric about civilians who were not aware and not involved. It is absolutely not true.”

Israel’s foreign ministry has previously rejected the report, calling it “distorted and false” and claiming it “relies entirely on Hamas falsehoods”.

Herzog has denied the incitement allegations and has called the separate genocide case against Israel in the international court of justice a “form of blood libel”. He pushed back on criticism of his comments about the Gaza war, saying they were taken out of context and noting he had said Israel would respect international law and there was no excuse for the killing of innocent civilians.

The ICJ is yet to issue its final ruling.

Husic said he understood that Herzog had claimed to have been misrepresented by the criticisms against him, and suggested the president could use his visit to discuss a lasting peace in the Middle East and Palestinian statehood.

“But in the absence of that, I just don’t see how his visit would add, given the concerns that exist around his positioning,” Husic said. “He’s part of the leadership of a nation that has undertaken, or its conduct has failed to distinguish between civilian and combatants in devastating ways when you see the number of people that have been killed.

“The hardest thing for me has been the impact on children, that they should not be shouldering the burden for what happened on October 7. And we should have leaders be able to say, ‘that’s not the way to go’.”

Three state Labor MPs have said they would join demonstrations against Herzog, while concerns about the visit have been raised by federal MP Sophie Scamps and the federal Greens. The Labor Friends of Palestine group has also asked the government to rescind Herzog’s invitation.

The Palestinian death toll in the Israel-Gaza war has surpassed 70,000, Gaza’s health ministry said in November, after 1,200 Israelis were killed in the Hamas terror attack of 7 October 2023. Israel’s military recently accepted that death toll was broadly accurate.

Husic said international bodies should be allowed to investigate the conflict in Gaza, and that decisions made through that campaign required “accountability”. He went on to say that protests against Israel’s bombardment of Gaza – one of which he attended at the Sydney Harbour Bridge – had been unfairly maligned.

“I do think it’s a massive slight against Australians who had genuine concern about what they were seeing in Gaza and who came out in record numbers, who have marched peacefully week in, week out to show the depth of their concern – that that be linked to that horrific event we saw in Bondi,” he said.



Source link

21 Republicans break with Trump, Speaker Johnson on $1.2T spending bill

0

NEWYou can now listen to Fox News articles!

Twenty-one Republicans broke with President Donald Trump and Speaker Mike Johnson, R-La., on Tuesday evening in an attempt to derail a $1.2 trillion spending bill to end a government shutdown, citing concerns that the legislation didn’t do enough to advance GOP priorities.

Among a range of reasons, lawmakers argued the bill needed to include provisions shoring up election integrity, come with full-year funding for the Department of Homeland Security (DHS) and eliminate Democrat-requested earmarks.

The lawmakers that voted against the measure included:

Reps. Andy Biggs, R-Ariz., Lauren Boebert, R-Colo., Josh Brecheen, R-Okla., Tim Burchett, R-Tenn., Eric Burlison, R-Mo., Kat Cammack, R-Fla., Eli Crane, R-Ariz., Byron Donalds, R-Fla., Randy Fine, R-Fla., Brandon Gill, R-Texas, Anna Paulina Luna, R-Fla., Thomas Massie, R-Ky., Cory Mills, R-Fla., Andy Ogles, R-Tenn., Scott Perry, R-Pa., Chip Roy, R-Texas, David Schweikert, R-Ariz., Keith Self, R-Texas, Victoria Spartz, R-Ind., Greg Steube, R-Fla., and William Timmons, R-S.C.

Rep. Thomas Massie

Rep. Thomas Massie, R-Ky., arrives for a news conference outside the US Capitol in Washington, D.C., on Sept. 3, 2025 (Graeme Sloan/Bloomberg via Getty Images)

TRUMP UNDERCUTS GOP PUSH TO ATTACH SAVE ACT TO SHUTDOWN BILL AS CONSERVATIVES THREATEN MUTINY

Thomas Massie, R-Ky., condemned what he saw as a failure to shore up election integrity with the exclusion of the Safeguard American Voter Eligibility (SAVE) Act — a bill requiring photo ID for registering voters looking to participate in federal elections.

“And most importantly… BLOCKED: the inclusion of the SAVE Act to protect our elections from illegal aliens — a top priority for conservatives,” Massie said in a long list of reasons he posted to X on why he had voted against the package.

Massie alongside other Republicans like Anna Paulina Luna, R-Fla., had called for Republicans to tie the SAVE Act into the 2026 funding bill.

He wasn’t the only Republican to vent frustrations online.

Other lawmakers voted against the bill because of a distrust that Democrats would negotiate in good faith over outstanding considerations to fund DHS.

“The fact that Chuck Schumer is able to somehow get Republicans to pass a version that includes all of their stuff — but only a two-week funding measure for Homeland Security, I think, is a fool’s bet,” Rep. Eric Burlison, R- Mo. said.

The bill, which now heads to the desk of President Donald Trump for his signature, includes funding for the departments of War, Education, Transportation, Housing and Urban Development and Health and Human Services.

REPUBLICANS, DEMS BREAK THROUGH RESISTANCE, MOVE FORWARD WITH TRUMP-BACKED FUNDING PACKAGE

Donald Trump speaking at the Andrew W. Mellon Auditorium in Washington.

President Donald Trump speaks during the launch of a program known as Trump Accounts at the Andrew W. Mellon Auditorium, Jan. 28, 2026, in Washington. (Jose Luis Magana/AP Photo)

Despite the opposition from the 21 Republicans, the bill passed by a bipartisan 217-214 vote.

Tuesday marks the second time the House of Representatives has considered this legislation.

The bill hit roadblocks after the House passed it for the first time in January, when Democrats in the Senate balked at its lack of safeguards for Immigration and Customs Enforcement (ICE) in the wake of two fatal confrontations in Minnesota between immigration enforcement and civilians.

Democrats across both chambers of Congress have demanded new restrictions on ICE’s operations, such as a prohibition against wearing masks, an elimination of ICE’s roaming patrols, body camera requirements, stronger warrant restrictions and visible law enforcement identification.

As a part of the package, lawmakers included a two-week extension to DHS funding, giving negotiators time to work through disagreements on provisions for ICE while avoiding a broader government shutdown.

Having passed that compromise bill, lawmakers have until the end of next week to hammer out an agreement on funding for DHS or else risk a lapse in its funding.

In addition to ICE, the DHS bill covers funding for the Coast Guard, the Transportation Security Administration (TSA) and the Federal Emergency Management Agency (FEMA).

Lawmakers concerned about that funding also voted against the bill on Tuesday, expressing disappointment Republicans hadn’t used the moment to push for DHS fundng. 

“I voted NO on the 5-bill minibus,” Rep. Lauren Boebert, R-Colo., said in a post to X on Tuesday.

ICE-agents-garage

US Immigration and Customs Enforcement (ICE) agents on Sunday, Jan. 26, 2025. (Christopher Dilts/Bloomberg via Getty Images)

“Republicans have the trifecta and we should fund DHS at Trump levels for strong border security,” Boebert said.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Rep. Tim Burchett, R-Tenn., blasted the bill for, in his view, not utilizing Republican negotiating power.

“We gotta start negotiating from power,” Burchett said in a video he posted. “Trump will tell you: negotiate from power.”



Source link

Up: Order issued for cashless treatment for teachers, the cabinet had approved it recently; Know who will get the benefit – Up: Order Issued For Cashless Treatment For Teachers, Recently Approved By The Cabinet; Find Out Who Will Become

0

After the green signal from the state cabinet, the government on Wednesday issued a government order to provide cashless medical facilities to the teachers of the Secondary Education Department. A total of 2.97 lakh teachers and their dependent families including teachers of non-government aided schools, teachers of self-financed secondary schools, subject experts and honorarium teachers of vocational education, teachers of aided schools recognized by Sanskrit Shiksha Parishad will get its benefit.
Trending Videos


In the order issued by Additional Chief Secretary Partha Sarathi Sen Sharma, it has been said that apart from government hospitals, teachers and their dependent family members will get cashless treatment facility in private hospitals also. The estimated annual premium for teachers and their family members is Rs 3000 per teacher. The scheme will be implemented through Sachij. The nominated nodal officer of the Secondary Education Department will provide the complete details of the beneficiaries and their families to the Chief Executive Officer Sachij by 30th June every year.


Markets open cautiously after strong rally; IT stocks drag on global tech selloff

0

Benchmark indices opened cautiously on Wednesday morning after the previous session’s strong rally, with IT stocks dragging following a sharp selloff in technology shares on Wall Street amid concerns over artificial intelligence competition.

The Sensex opened at ₹83,252.06 against the previous close of ₹83,739.13 and was trading at ₹83,868.64, up 129.51 points or 0.15 per cent at 9.45 am. The Nifty opened at ₹25,675.05 compared to the previous close of ₹25,727.55 and was trading at ₹25,790.35, up 62.80 points or 0.24 per cent.

“AI Anxiety Hits Wall Street: Wall Street ended sharply lower on Tuesday as investors worried that AI could create more competition for software makers, keeping them on edge ahead of quarterly reports from Alphabet and Amazon later this week,” said Devarsh Vakil, Head of Prime Research, HDFC Securities. “The tech-heavy Nasdaq fell 1.4 per cent as software stocks extended losses, Anthropic’s launch of workplace productivity tools intensified worries, with the sector shedding approximately $300 billion in market value.”

IT stocks bore the brunt of the selloff with Infosys falling 5.97 per cent to ₹1,557.10, TCS declining 5.23 per cent to ₹3,056.60, HCL Technologies down 4.63 per cent at ₹1,616.80, Tech Mahindra losing 4.37 per cent to ₹1,641.50, and wipro dropping 3.70 per cent to ₹233.70.

Among the gainers, ONGC led with a surge of 4.01 per cent to ₹267.30, Coal India rose 2.34 per cent to ₹439.45, Mahindra & Mahindra gained 2.28 per cent to ₹3,608.20, NTPC advanced 2.22 per cent to ₹366.50, and Jio Financial Services climbed 1.99 per cent to ₹269.15.

“The rally fueled by the US-India trade deal will face hurdles to sustain. The IT selloff in the US yesterday will drag the Indian IT index, too, constraining the rally in the Indian market,” said Dr VK Vijayakumar, Chief Investment Strategist, Geojit Investments Limited. “Since valuations continue to be high there is no fundamental support for a sustained rally.”

On Tuesday, benchmark indices witnessed a strong rally with the Nifty ending 639 points higher at 25,727 while the Sensex surged 2,073 points to close at 83,729, driven by optimism over the India-US trade deal.

“Indian equity markets continue to draw support from positive progress in India–US trade discussions, which remains the key sentiment driver,” said Ponmudi R, CEO of Enrich Money. “After the strong multi-day rally, some profit-booking and range-bound action cannot be ruled out.”

Shrikant Chouhan, Head – Equity Research at Kotak Securities, noted that “the short-term market outlook remains positive, but a strategy of buying on dips and selling on rallies would be ideal for traders.”

On the institutional front, foreign institutional investors turned net buyers on February 3, purchasing equities worth ₹5,236 crore after remaining net sellers for the previous two sessions. Domestic institutional investors extended their buying streak for a second consecutive day, investing over ₹1,000 crore.

Crude oil Futures traded higher on Wednesday morning as tensions re-emerged between the US and Iran. February crude oil futures were trading at ₹5,785 on Multi Commodity Exchange against the previous close of ₹5,709, up by 1.33 per cent, and March futures were trading at ₹5,770 against the previous close of ₹5,696, up by 1.30 per cent.

“Given persistent global uncertainties and elevated volatility, traders are advised to remain selective and disciplined, focusing on fundamentally strong stocks during market declines,” said Aakash Shah, Technical Research Analyst at Choice Equity Broking Private Limited.

Published on February 4, 2026

Thousands march in Venezuela to demand US frees President Maduro, wife | Nicolas Maduro News

0

Thousands of people marched through Venezuela’s capital, Caracas, demanding the release of President Nicolas Maduro and his wife, Cilia Flores, exactly one month since US forces abducted the couple in a bloody nighttime raid.

“Venezuela needs Nicolas!” the crowd chanted in Tuesday’s demonstration, titled “Gran Marcha” (The Great March).

Recommended Stories

list of 4 itemsend of list

Thousands carried signs in support of the abducted president, and many wore shirts calling for the couple’s return from detention in a US prison.

“The empire kidnapped them. We want them back,” declared one banner carried by marchers.

Nicolas Maduro Guerra, the detained president’s son and a member of Venezuela’s National Assembly, addressed the crowds from a stage, stating that the US military’s abduction of his father on January 3 “will remain marked like a scar on our face, forever”.

“Our homeland’s soil was desecrated by a foreign army”, Maduro Guerra said of the night US forces abducted his father.

The march, called by the government and involving many public sector workers, stretched for several hundred metres, accompanied by trucks blaring music.

A supporter of Venezuela's government holds placards during a rally to demand the release of ousted President Nicolas Maduro and his wife, Cilia Flores, one month after their capture by the U.S. during recent U.S. strikes on the country, in Caracas, Venezuela, February 3, 2026. REUTERS/Maxwell Briceno
A demonstrator holds a placard during a rally to demand the US releases abducted Venezuelan President Nicolas Maduro and his wife, Cilia Flores, in Caracas, Venezuela [Maxwell Briceno/Reuters]

Local media outlet Venezuela News said the march was part of a “global day of action” to demand the couple’s release. Protesters showed their solidarity around the world, demonstrating under banners with slogans like “Bring them back” and “Hands off Venezuela”.

The international event united voices “from diverse ideological trends”, who agreed “that the detention of President Maduro and Cilia Flores represents a flagrant violation of international law and a dangerous precedent for the sovereignty of nations”, the news outlet said.

“We feel confused, sad, angry. There are a lot of emotions,” said Jose Perdomo, a 58-year-old municipal employee, who marched in Caracas.

“Sooner or later, they will have to free our president”, he said, adding that he also backed Venezuela’s interim leader, Delcy Rodriguez.

Rodriguez has been walking a thin line since taking over as acting president, trying to appease Maduro’s supporters in government and accommodating the demands being placed on Caracas by US President Donald Trump.

Trump has said he is willing to work with Rodriguez, as long as Caracas falls in line with his demands, particularly on the US taking control of Venezuela’s vast oil reserves.

Striking a conciliatory tone with Washington, and promising reform and reconciliation at home, Rodriguez has already freed hundreds of political prisoners and opened Venezuela’s nationalised hydrocarbons sector to private investment.

Earlier on Tuesday, hundreds of university students and relatives of political prisoners also marched in the capital, calling for the quick approval of an amnesty law promised by Rodriguez that would free prisoners from the country’s jails.

Legislation on the amnesty has not yet come before parliament.



Source link

12-year-old girl falls from chairlift at California Mammoth Mountain ski resort

0

NEWYou can now listen to Fox News articles!

A jaw-dropping video captured the traumatic moment a 12-year-old girl plunged to the ground after dangling momentarily from a ski chairlift in California.

The frightening incident happened Saturday at Mammoth Mountain Ski Resort, when the visiting snowboarder appeared to be unsecured on the chairlift.

In a video that went viral on social media, the girl appeared to grip the chairlift in a desperate struggle as her feet flailed in the air, still strapped to her snowboard. 

Several mountain staff members were then seen rushing over to help, placing padding and a safety net below in an attempt to catch her fall.

SKYDIVER SURVIVES AFTER RESERVE PARACHUTE ACCIDENTALLY DEPLOYS, LEAVING HIM DANGLING FROM FLYING AIRPLANE

Wide view shows ski patrol positioning safety net below chairlift

Ski resort staff scramble to position a safety net beneath a chairlift as a child dangles above the snow at Mammoth Mountain in California on Jan. 31, 2026. (Kristen Tellez via Storyful)

The girl then crashed to the ground, tragically missing most of the safety net, according to the footage. Rescuers appeared briefly in shock before scrambling over in alarm.

A woman claiming to be the girl’s mother commented on the post, saying her daughter “miraculously walked away with no broken bones or major injuries.” 

“As the mother of my 12 yo daughter that fell today I really want to thank everyone who came out to help her,” she said. “The mammoth team did their best to get to her as quickly as possible. It was an incredibly traumatic experience and everyone supported us.”

COLORADO JURY AWARDS FAMILY $205M AFTER 6-YEAR-OLD FALLS TO DEATH FROM THEME PARK RIDE

Girl dangles from ski lift high above snowy slope at California resort

A 12-year-old girl dangles from a ski chairlift moments before falling at Mammoth Mountain Ski Resort in California on Jan. 31, 2026. (Kristen Tellez via Storyful)

Addressing questions about why the chair’s safety bar was not lowered, the mother emphasized that no one was at fault. She indicated that the chair slipped almost immediately after her daughter got on, leaving no time to secure it.

“As to the bar – we had no chance,” she added. “She slipped down right away. There was nothing that anyone did wrong. It was a series of small choices that happened quickly that led to a fluke accident.”

In the video, the girl appeared to be sitting next to two other people before falling. According to her mother, the group held onto her as long as possible, which gave rescuers time to respond.

Ski patrol rushes to help after girl falls from chairlift

Ski patrol respond after a 12-year-old girl fell from a chairlift at Mammoth Mountain Ski Resort in California on Jan. 31, 2026. (Kristen Tellez via Storyful)

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

“As a mother I know it is my job to protect my child,” she said. “We held on as long as we could. Long enough to have people get into position to allow her to walk away.”

Despite the traumatic experience, she said the family will not be deterred from skiing and “will be riding again when she’s ready.”



Source link

OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link

0

Ravie LakshmananFeb 02, 2026Vulnerability / Artificial Intelligence

A high-severity security flaw has been disclosed in OpenClaw (formerly referred to as Clawdbot and Moltbot) that could allow remote code execution (RCE) through a crafted malicious link.

The issue, which is tracked as CVE-2026-25253 (CVSS score: 8.8), has been addressed in version 2026.1.29 released on January 30, 2026. It has been described as a token exfiltration vulnerability that leads to full gateway compromise.

“The Control UI trusts gatewayUrl from the query string without validation and auto-connects on load, sending the stored gateway token in the WebSocket connect payload,” OpenClaw’s creator and maintainer Peter Steinberger said in an advisory.

“Clicking a crafted link or visiting a malicious site can send the token to an attacker-controlled server. The attacker can then connect to the victim’s local gateway, modify config (sandbox, tool policies), and invoke privileged actions, achieving 1-click RCE.”

OpenClaw is an open-source autonomous artificial intelligence (AI) personal assistant that runs locally on user devices and integrates with a wide range of messaging platforms. Although initially released in November 2025, the project has gained rapid popularity in recent weeks, with its GitHub repository crossing 149,000 stars as of writing.

“OpenClaw is an open agent platform that runs on your machine and works from the chat apps you already use,” Steinberger said. “Unlike SaaS assistants where your data lives on someone else’s servers, OpenClaw runs where you choose – laptop, homelab, or VPS. Your infrastructure. Your keys. Your data.”

Mav Levin, founding security researcher at depthfirst who is credited with discovering the shortcoming, said it can be exploited to create a one-click RCE exploit chain that takes only milliseconds after a victim visits a single malicious web page.

The problem is that clicking on the link to that web page is enough to trigger a cross-site WebSocket hijacking attack because OpenClaw’s server doesn’t validate the WebSocket origin header. This causes the server to accept requests from any website, effectively getting around localhost network restrictions.

A malicious web page can take advantage of the issue to execute client-side JavaScript on the victim’s browser that can retrieve an authentication token, establish a WebSocket connection to the server, and use the stolen token to bypass authentication and log in to the victim’s OpenClaw instance.

To make matters worse, by leveraging the token’s privileged operator.admin and operator.approvals scopes, the attacker can use the API to disable user confirmation by setting “exec.approvals.set” to “off” and escape the container used to run shell tools by setting “tools.exec.host” to “gateway.”

“This forces the agent to run commands directly on the host machine, not inside a Docker container,” Levin said. “Finally, to achieve arbitrary command execution, the attacker JavaScript executes a node.invoke request.”

When asked whether OpenClaw’s use of the API to manage the safety features constitutes an architectural limitation, Levin told The Hacker News in an emailed response that, “I would say the problem is those defenses (sandbox and safety guardrails) were designed to contain malicious actions of an LLM, as a result of prompt injection, for example. And users might think these defenses would protect from this vulnerability (or limit the blast radius), but they don’t.”

Steinberger noted in the advisory that “the vulnerability is exploitable even on instances configured to listen on loopback only, since the victim’s browser initiates the outbound connection.”

“It impacts any Moltbot deployment where a user has authenticated to the Control UI. The attacker gains operator-level access to the gateway API, enabling arbitrary config changes and code execution on the gateway host. The attack works even when the gateway binds to loopback because the victim’s browser acts as the bridge.”



Source link

Access Denied

0

Access Denied You don’t have permission to access “http://hindi.gadgets360.com/wearable/oakley-meta-vanguard-launched-in-india-with-12-megapixel-camera-know-price-features-news-10942677” on this server.

Reference #18.b3560e17.1774143999.4bcd4229

https://errors.edgesuite.net/18.b3560e17.1774143999.4bcd4229

Q3 Results 04th Feb Live: Bajaj Finserv, Trent, Bajaj Holdings, Tata Power, Apollo Tyres, Hexaware, Cummins India, Tube Investments, Kalpataru Projects, Emcure Pharma to announce Q3 results, Adani Ports, Adani Enterprises, Bajaj Finance, MobiKwik, BCCL, Solar, Ather shares in focus

0

Business people using pen,tablet,notebook are planning a marketing plan to improve the quality of their sales in the future. istock photo for BL

Business people using pen,tablet,notebook are planning a marketing plan to improve the quality of their sales in the future. istock photo for BL | Photo Credit: Jirapong Manustrong

3 Results Today, 04th Feb 2026 Live Updates: Find all the latest Q3 results 2026 updates of Bajaj Finserv, Trent, Bajaj Holdings & Investment, The Tata Power Company and more.

  • February 4, 2026 09:56

    Adani Ports Q3 results live: Shares swing

    Adani Ports stock traded flat at Rs 1,532.80 on the NSE at 9.55 am, after moderating between Rs 1,508.50-Rs 1,545.90.

    It reported a profit after tax of ₹3,043 crore for the third quarter ended December 31, 2025, up 21% yoy.

  • February 4, 2026 09:50

    Bajaj Finance Q3 results live: Shares flat

    Bajaj Finance shares traded flat on the NSE at Rs 964.40. It posted 6% yoy fall in consolidated net profit for the quarter ended December at ₹4,066 crore.

  • February 4, 2026 09:28

    CUB Q3 RESULTS LIVE

    City Union Bank Ltd. | CMP Rs. 285 | M Cap Rs. 21150 Cr | 52 WH/L 305/143

    (Nirmal Bang Retail Research)

    Result is ahead of expectations

    Advances came at Rs. 60892 Cr (+21% YoY, +7.4% QoQ)

    Net Interest Income came at Rs. 752 Cr (28% YoY), YoY Rs. 588 Cr, QoQ Rs. 667 cr

    NIM came at 3.89% vs QoQ 3.63%

    Non-Interest Income came at Rs. 245.3 Cr vs YoY Rs. 228.4 Cr, QoQ Rs. 259.1 Cr

    PBP came at Rs. 513 Cr (17.7% YoY) vs expectation of Rs. 485 Cr, YoY Rs. 436 Cr, QoQ Rs. 471 cr

    Provisions came at Rs. 96 Cr vs expectation of Rs. 60 Cr, YoY Rs. 75 Cr, QoQ Rs. 57 Cr

    Credit Cost came at 0.6% vs YoY 0.6%, QoQ 0.4%

    Adj. PAT came at Rs. 332 Cr (16.1% YoY) vs expectation of Rs. 322 Cr, YoY Rs. 286 Cr, QoQ Rs. 329 cr

  • February 4, 2026 09:28

    Indus Towers Q3 results live

    Indus Towers Ltd. | CMP Rs. 432 | M Cap Rs. 113969 Cr. 52 WH/L 455/313

    (Nirmal Bang Retail Research)

    Result is marginally above expectations

    Revenue from Operations came at Rs. 8146.3 Cr (-0.5% QoQ, 7.9% YoY) vs expectation of Rs. 8248.6 Cr, QoQ Rs. 8188.2 Cr, YoY Rs. 7547.4 Cr

    EBIDTA came at Rs. 4459.5 Cr (1.9% QoQ, 13.4% YoY) vs expectation of Rs. 4343.8 Cr, QoQ Rs. 4376.9 Cr, YoY Rs. 3934 cr

    EBITDA Margin came at 54.7% vs expectation of 52.7%, QoQ 53.5%, YoY 52.1%

    Adj. PAT came at Rs. 1783 Cr vs expectation of Rs. 1745.6 Cr, QoQ Rs. 1839.3 Cr, YoY Rs. 4003.2 Cr

    Quarter EPS is Rs. 6.8

    Stock is trading at P/E of 14.8x FY27E EPS

  • February 4, 2026 09:28

    VBL Q4 results live

    Varun Beverages Ltd. | CMP Rs. 481 | M Cap Rs. 171230 Cr. 52 WH/L 593/419

    (Nirmal Bang Retail Research)

    Result below Expectation

    Revenue from Operations came at Rs. 4204.4 Cr (-14.1% QoQ, 14% YoY) vs expectation of Rs. 4326.9 Cr, QoQ Rs. 4896.7 Cr, YoY Rs. 3688.8 Cr

    EBIDTA came at Rs. 639 Cr (-44.3% QoQ, 10.2% YoY) vs expectation of Rs. 742.2 Cr, QoQ Rs. 1147.4 Cr, YoY Rs. 580 Cr

    EBITDA Margin came at 15.2% vs expectation of 17.2%, QoQ 23.4%, YoY 15.7%

    Adj. PAT came at Rs. 251.8 Cr vs expectation of Rs. 319.6 Cr, QoQ Rs. 741.2 Cr, YoY Rs. 185.1 Cr

    Quarter EPS is Rs. 0.7

    Stock is trading at P/E of 41.4x FY27E EPS

  • February 4, 2026 09:27

    HFCL Q3 results live:

    HFCL Ltd. | CMP Rs. 69 | M Cap Rs. 10561 Cr. 52 WH/L 107/61

    (Nirmal Bang Retail Research)

    Result has improved

    Revenue from Operations came at Rs. 1210.8 Cr (16% QoQ, 19.6% YoY) vs QoQ Rs. 1043.3 Cr, YoY Rs. 1012 Cr

    EBIDTA came at Rs. 228.1 Cr (19.8% QoQ, 50.2% YoY) vs QoQ Rs. 190.3 Cr, YoY Rs. 151.9 Cr

    EBITDA Margin came at 18.8% vs QoQ 18.2%, YoY 15%

    Adj. PAT came at Rs. 97.6 Cr vs QoQ Rs. 67.9 Cr, YoY Rs. 73.6 Cr

    Quarter EPS is Rs. 0.6

    Stock is trading at P/E of 203.9x TTM EPS

  • February 4, 2026 09:27

    Adani Ports Q3 results live

    Adani Ports and Special Economic Zone Ltd. | CMP Rs. 1517 | M Cap Rs. 327693 Cr. 52 WH/L 1549/1011

    (Nirmal Bang Retail Research)

    Result inline with Expectation

    Revenue from Operations came at Rs. 9704.6 Cr (5.9% QoQ, 21.9% YoY) vs expectation of Rs. 9444.4 Cr, QoQ Rs. 9167.5 Cr, YoY Rs. 7963.6 Cr

    EBIDTA came at Rs. 5785.9 Cr (4.2% QoQ, 20.5% YoY) vs expectation of Rs. 5634.8 Cr, QoQ Rs. 5550.3 Cr, YoY Rs. 4802.1 Cr

    EBITDA Margin came at 59.6% vs expectation of 59.7%, QoQ 60.5%, YoY 60.3%

    Adj. PAT came at Rs. 3199.7 Cr vs expectation of Rs. 3323.7 Cr, QoQ Rs. 3109.1 Cr, YoY Rs. 2548.1 Cr

    Quarter EPS is Rs. 14.8

    Stock is trading at P/E of 21.7x FY27E EPS

  • February 4, 2026 09:27

    Aether Industries Q3 results live:

    Aether Industries Ltd. | CMP Rs. 1046 | M Cap Rs. 13869 Cr. 52 WH/L 1086/723

    (Nirmal Bang Retail Research)

    Result is above expectations

    Revenue from Operations came at Rs. 317.1 Cr (15.3% QoQ, 44.4% YoY) vs expectation of Rs. 288.4 Cr, QoQ Rs. 275.1 Cr, YoY Rs. 219.7 Cr

    EBIDTA came at Rs. 110.6 Cr (25.7% QoQ, 70.9% YoY) vs expectation of Rs. 90.5 Cr, QoQ Rs. 88 Cr, YoY Rs. 64.7 Cr

    EBITDA Margin came at 34.9% vs expectation of 31.4%, QoQ 32%, YoY 29.5%

    Adj. PAT came at Rs. 66.8 Cr vs expectation of Rs. 57.1 Cr, QoQ Rs. 56.6 Cr, YoY Rs. 46.1 Cr

    Quarter EPS is Rs. 5

    Stock is trading at P/E of 46.6x FY27E EPS

  • February 4, 2026 09:27

    Kalyani Steels Q3 results live:

    Kalyani Steels Ltd. | CMP Rs. 702 | M Cap Rs. 3062 Cr | 52 WH/L 1032/667

    (Nirmal Bang Retail Research)

    Result is ok

    Revenue from Operations came at Rs. 462.4 Cr (1.4% QoQ, -4.5% YoY) vs QoQ Rs. 456.1 Cr, YoY Rs. 484 cr

    EBIDTA came at Rs. 91.5 Cr (7.2% QoQ, 9.8% YoY) vs QoQ Rs. 85.4 Cr, YoY Rs. 83.4 Cr

    EBITDA Margin came at 19.8% vs QoQ 18.7%, YoY 17.2%

    Adj. PAT came at Rs. 68.7 Cr vs QoQ Rs. 62.5 Cr, YoY Rs. 56.4 Cr

    Quarter EPS is Rs. 15.7

    Stock is trading at P/E of 11.2x TTM EPS

  • February 4, 2026 09:26

    PCBL Chemical Q3 results live:

    PCBL Chemical Ltd. | CMP Rs. 304 | M Cap Rs. 11955 Cr. 52 WH/L 444/255

    (Nirmal Bang Retail Research)

    Result is below expectations

    Revenue from Operations came at Rs. 1845.6 Cr (-14.7% QoQ, -8.2% YoY) vs expectation of Rs. 2142.2 Cr, QoQ Rs. 2163.6 Cr, YoY Rs. 2010 cr

    EBIDTA came at Rs. 214.7 Cr (-19.4% QoQ, -32.4% YoY) vs expectation of Rs. 256.5 Cr, QoQ Rs. 266.2 Cr, YoY Rs. 317.3 Cr

    EBITDA Margin came at 11.6% vs expectation of 12%, QoQ 12.3%, YoY 15.8%

    Adj. PAT came at Rs. 22.9 Cr vs expectation of Rs. 85.8 Cr, QoQ Rs. 61.5 Cr, YoY Rs. 93.6 Cr

    Quarter EPS is Rs. 0.6

    Stock is trading at P/E of 17.4x FY27E EPS

  • February 4, 2026 09:24

    Stock market live updates: Sensex, Nifty trade flat

    Sensex traded 108.91 pts or 0.13 % lower at 83,630.22 at 9.18 am after opening at 83,252.06 against the previous close of 83,739.13, and Nifty 50 dipped 0.60 pts to 25,726.95.

Published on February 4, 2026