AI / ML / Autonomous Systems — 2026-03-22

OpenClaw Security Crisis: 40,000 Exposed Instances, Cisco Labels It 'Security Nightmare'

Cisco found 40,000 OpenClaw instances exposed on the public internet with no authentication. Gartner called it 'a dangerous preview of agentic AI with unacceptable cybersecurity risk.' Cisco's Skill Scanner found nine flaws in a vulnerable third-party skill, including active data exfiltration via curl to external servers. CVE-2026-25253 (auth token theft) patched in v2026.1.29.

Analysis
Prior INTSUM covered OpenClaw's 'ChatGPT moment' as agentic AI commoditization story. Cisco's 'security nightmare' characterization and Gartner's warning represent the security backlash to rapid adoption. Prior cyber coverage of Langflow CVE exploitation within 20 hours shows the pattern: open-source AI tools deployed faster than secured.
2 sources
  1. Personal AI Agents like OpenClaw Are a Security Nightmare - Cisco Blogs
  2. OpenClaw Security Issues Continue as SecureClaw Open Source Tool Debuts - SecurityWeek

View in full brief →

UNCLASSIFIED // OPEN SOURCE