
Malwarebytes Calls OpenClaw 'An Over-Eager Intern' — Here's What To Do About It
Malwarebytes just published their assessment of OpenClaw, and the headline quote is brutal: "An over-eager intern with an adventurous nature, a long memory, and no real understanding of what should stay private." Source: Malwarebytes Blog This comes the same week as: SecurityScorecard : 40,214 exposed instances, 63% vulnerable, 12,812 RCE-exploitable Endor Labs : 6 new CVEs (SSRF, path traversal, auth bypass) Kaspersky : Enterprise risk management guide for OpenClaw Dutch DPA : Formal warning against deploying on sensitive systems Hudson Rock : First documented case of an infostealer grabbing a complete OpenClaw identity The Core Problem Malwarebytes nails the fundamental tension: OpenClaw is designed to be adventurous — browse the web, run shell commands, read/write files, chain skills together. But this adventurousness + open source + rapid growth = a security nightmare. The Meta AI safety director who couldn't prevent OpenClaw from deleting her email inbox? That's not a bug. That's
Continue reading on Dev.to DevOps
Opens in a new tab




