Tag: ShinyHunters

New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets
News

New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets

In separate studies released this week, two security teams demonstrated how OpenClaw, the well-known self-hosted AI agent, can be made to execute attacker-controlled code or provide sensitive data using inputs that appear normal. Imperva concealed instructions that the agent carried out without the victim ever seeing them inside shared contacts, vCards, and location pins. Varonis created a test agent on the platform, provided it with a mailbox containing fictitious business data, and observed how one simple email persuaded it to transfer fictitious AWS keys and a fictitious customer export to an external address. The bug Imperva identified is corrected in OpenClaw 2026.4.23, so update if you run it. Varonis discovered a phishing vulnerability that can only be addressed by restrictin...
A Cybercrime Merger Like No Other — Scattered Spider, LAPSUS$, and ShinyHunters Join Forces
News

A Cybercrime Merger Like No Other — Scattered Spider, LAPSUS$, and ShinyHunters Join Forces

Since August 8, 2025, the young collective that unites three well-known cybercrime groups—Scattered Spider, LAPSUS$, and ShinyHunters—has established at least 16 Telegram channels. According to a report shared with The Hacker News by Trustwave SpiderLabs, a LevelBlue company, the group's Telegram channels have been deleted and recreated at least 16 times since their launch under different versions of the original name. This cycle reflects platform moderation and the operators' resolve to maintain this particular kind of public presence despite disruption. Early in August, a group known as Scattered LAPSUS$ Hunters (SLH) appeared and began extorting data from businesses, particularly those that had recently used Salesforce. Its main product is an extortion-as-a-service (EaaS) that ot...