logo

Anatomy of an Autonomous AI Agent Risk: How Qualys ETM Connects the Dots on OpenClaw

ID: 503db1b1-009d-506c-93d3-e35af0bd7f99

STIX ID: report--503db1b1-009d-506c-93d3-e35af0bd7f99

Feed Name: Qualys Blog

Threat Score
78/100

Date Published: 2026-04-13

Date Updated: 2026-04-28

Author: Viren Chaudhari

...
...

Qualys ETM detected an unauthorized OpenClaw (clawdbot) autonomous agent on a Windows Server: vulnerable versions (including CVE-2026-25253 and CVE-2025-55130) with public exploit intelligence were confirmed by VMDR and Microsoft Defender, EASM observed a live Node.js service listening on TCP/18792, and ETM Identity identified stale SID history and disabled Kerberos pre-authentication that together create an attack path enabling potential domain compromise; the report demonstrates how correlating endpoint, exposure, and identity telemetry prioritizes remediation and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.