AI Security Incident
Evidence indicates that the affected technology is affected by a security issue.
What Happened
Evidence indicates that the affected technology is affected by a security issue.
Why This Matters
Current evidence identifies a security issue involving the affected technology, but does not yet support a more specific impact claim.
Recommended Action
No confirmed vendor remediation is available in the current evidence. Confirm whether the affected technology is present in your environment and review the affected configuration.
Exposure
Jan 29, 2026 05:30
Jan 29, 2026 05:30
Exploitation status: UNKNOWN
Primary entities:
Timeline
-
Incident first seen
Jan 29, 2026 05:30BugSkan first recorded this incident.
-
One Step Away From a Massive Data Breach: What We Found Inside MoltBot - OX Security
Jan 29, 2026 05:30ox.security · Vulnerability
Sources
ox.security · Jan 29, 2026 05:30
The AI personal assistant MoltBot (OpenClaw) insecurely stores sensitive credentials and API keys in cleartext within `~/.clawdbot` and retains "deleted" secrets in backup files, making them vulnerable to infostealers. Furthermore, the codebase exhibits numerous insecure patterns, including extensive use of `eval` and `execSync` with user input, which could lead to Remote Code Execution (RCE), XSS, and broader data breaches for its hundreds of thousands of users.
Open publisher sourceWatchlist Match
Create an account to see which incidents overlap with the technologies you monitor.