logo

From Shadow IT to Shadow AI: Clawdbot (Moltbot) and the Rise of Unmanaged Agent Gateways

ID: 248b18c9-c21d-565b-914d-23423faee799

STIX ID: report--248b18c9-c21d-565b-914d-23423faee799

Feed Name: Brandefense Blog

Threat Score
72/100

Date Published: 2026-01-28

Date Updated: 2026-04-27

Author: BRANDEFENSE

...
...

**Executive summary:** This report analyzes the rise of unmanaged, agentic AI gateways (exemplified by Clawdbot/Moltbot) that are often misconfigured to listen on public ports (default 18789) or proxied insecurely, exposing persistent prompt histories, provider API keys, and integration tokens; the authors measured hundreds of reachable instances and detail exploitation scenarios (quota theft, lateral movement via malicious skills) and defensive controls such as binding to loopback, reverse proxy hardening, secret management, segmentation, and observability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.