Discussion about this post

User's avatar
Neural Foundry's avatar

Terrific roundup on the OpenClaw security issues. The VirusTotal finding of 3,016 skills with hundres showing malicious characteristics is kinda wild when you think about how fast this ecosystem emerged. Reminds me of early npm days where supply chain attacks wernt really on anyone's radar. One thing worth noting is that the CLI vs web server distinction for OpenClaw deployment creates totally differnt attack surfaces for defenders to monitor.

Roman D's avatar

We had a hard time with the Pyramid of Pain too. We found in the Summiting the Pyramid work we did that the lower levels mostly collapsed into similar amounts of "pain" for the adversary.

"Instance" is interesting. I like the additional details, which would be really helpful, but with the caveat that we don't want to get so specific that we recreate signature-based detections just with different observables.

2 more comments...

No posts

Ready for more?