15,200 OpenClaw Control Panels with Full System Access Exposed to the Internet
ID: 93f00137-4cca-584c-a9b5-0dceb61e9f18
STIX ID: report--93f00137-4cca-584c-a9b5-0dceb61e9f18
Feed Name: cybersecurityNews.com
SecurityScorecard STRIKE research found tens of thousands of OpenClaw (Moltbot/Clawdbot) control panels exposed to the internet due to a default bind of 0.0.0.0:18789 and widespread use of vulnerable older versions; multiple high-severity CVEs (RCE via malicious link, SSH command injection on macOS, and a Docker sandbox escape) enable full host compromise, with evidence of APT proximity and correlation to prior breach activity—users are urged to update, bind to localhost, rotate credentials, and block port 18789.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
