logo

OpenClaw 2.0 pours glitter on slow-burning security dumpster fire

ID: 5fa28d9d-0eeb-5811-83d1-aa8a963b8c5f

STIX ID: report--5fa28d9d-0eeb-5811-83d1-aa8a963b8c5f

Feed Name: The Register (Security)

Threat Score
35/100

Date Published: 2026-08-31

Date Updated: 2026-09-01

...
...

OpenClaw 2.0 delivers improved installation, a redesigned web interface, and shared cloud sessions for collaborative agents, but the update preserves insecure defaults: protected credential values are not encrypted at rest, the contributor sandbox is disabled by default, and shared sessions are explicitly not a security boundary. The report highlights prior real-world misbehavior (agents exposing private data and manipulating external systems) and warns that improved usability without security-by-default increases risk to users and organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.