Trending:
SECTION

Cybersecurity

Security threats, solutions, and policy in the Asia-Pacific region

230 malicious OpenClaw extensions stolen crypto data since January 27

230 malicious OpenClaw extensions stolen crypto data since January 27

Security researchers documented 230 malicious OpenClaw "skills" disguised as crypto trading tools uploaded to ClawHub since late January. The extensions exploit OpenClaw's unsandboxed architecture to steal browser data and cryptocurrency information. Enterprise deployments are exposed: hundreds of instances run online without authentication.

All Cybersecurity News

230 malicious OpenClaw extensions stolen crypto data since January 27
Cybersecurity

230 malicious OpenClaw extensions stolen crypto data since January 27

Security researchers documented 230 malicious OpenClaw "skills" disguised as crypto trading tools uploaded to ClawHub since late January. The extensions exploit OpenClaw's unsandboxed architecture to steal browser data and cryptocurrency information. Enterprise deployments are exposed: hundreds of instances run online without authentication.

Feb 2, 2026
175,000 open-source AI deployments exposed globally - most lack basic security controls
Cybersecurity

175,000 open-source AI deployments exposed globally - most lack basic security controls

SentinelLabs and Censys found thousands of Ollama instances running identical LLM configurations with no authentication, exposed APIs, and disabled guardrails. The monoculture setup means a single vulnerability could compromise substantial infrastructure simultaneously. Separately, Treasury terminated all Booz Allen Hamilton contracts after the firm's employee leaked 400,000+ tax records.

Feb 2, 2026
Android Private DNS encrypts queries by default - but most users never enable it
Cybersecurity

Android Private DNS encrypts queries by default - but most users never enable it

Android's built-in Private DNS feature encrypts DNS queries via DNS over TLS, preventing ISP tracking and DNS spoofing. Available since Android 9, the setting remains off by default on most devices, leaving query data exposed. Three billion Android users have access to the feature, yet adoption patterns suggest enterprise configuration tools may be driving most implementations.

Feb 2, 2026