
Sign up to save your podcasts
Or


OpenClaw AI Agent Hijack, CISA Leadership Shakeup, Iran Cyber Campaign, Air-Gap Malware, and Robot Vacuum Flaw
Jim Love covers multiple cybersecurity stories: Oasis Security revealed "ClawJacked," a high-severity OpenClaw AI agent framework flaw caused by missing rate limiting on the local gateway, enabling malicious web pages to brute-force passwords via WebSockets, register a trusted device, and take over agents; OpenClaw patched it within 24 hours and users are urged to update to version 2020 6.2 0.25 and tighten governance for non-human identities. CISA sees a leadership change as acting director Madhu Gottumukkala steps down amid criticism and reports he uploaded sensitive contracting documents to public ChatGPT and canceled key security tool contracts; Nick Anderson becomes acting director. The episode also discusses a coordinated cyber campaign alongside US/Israeli operations against Iran and risks of Iranian retaliation against exposed US critical infrastructure, North Korea's Scarcruft using "Ruby Jumper" to bridge air-gapped networks via USB, and a DJI Romo robot vacuum MQTT flaw that exposed control and camera access across 7,000 devices before being patched.
00:00 Sponsor Message Meter 00:19 Headlines And Intro 00:46 Claw Jacked AI Agents 02:21 CISA Leadership Shakeup 06:02 Cyber Front In Iran War 08:48 North Korea Air Gap Breach 10:06 Robot Vacuum Takeover 13:04 Wrap Up And Thanks
By Jim Love4.5
174174 ratings
OpenClaw AI Agent Hijack, CISA Leadership Shakeup, Iran Cyber Campaign, Air-Gap Malware, and Robot Vacuum Flaw
Jim Love covers multiple cybersecurity stories: Oasis Security revealed "ClawJacked," a high-severity OpenClaw AI agent framework flaw caused by missing rate limiting on the local gateway, enabling malicious web pages to brute-force passwords via WebSockets, register a trusted device, and take over agents; OpenClaw patched it within 24 hours and users are urged to update to version 2020 6.2 0.25 and tighten governance for non-human identities. CISA sees a leadership change as acting director Madhu Gottumukkala steps down amid criticism and reports he uploaded sensitive contracting documents to public ChatGPT and canceled key security tool contracts; Nick Anderson becomes acting director. The episode also discusses a coordinated cyber campaign alongside US/Israeli operations against Iran and risks of Iranian retaliation against exposed US critical infrastructure, North Korea's Scarcruft using "Ruby Jumper" to bridge air-gapped networks via USB, and a DJI Romo robot vacuum MQTT flaw that exposed control and camera access across 7,000 devices before being patched.
00:00 Sponsor Message Meter 00:19 Headlines And Intro 00:46 Claw Jacked AI Agents 02:21 CISA Leadership Shakeup 06:02 Cyber Front In Iran War 08:48 North Korea Air Gap Breach 10:06 Robot Vacuum Takeover 13:04 Wrap Up And Thanks

187 Listeners

2,010 Listeners

371 Listeners

373 Listeners

652 Listeners

1,025 Listeners

318 Listeners

419 Listeners

8,079 Listeners

316 Listeners

194 Listeners

73 Listeners

140 Listeners

45 Listeners

167 Listeners