January 29, 2026

Infostealers added Clawdbot to their target lists before most security teams knew it was running

architectural photography of black and brown hallway
Nastuh Abootalebi / Unsplash

Clawdbot's MCP implementation has no mandatory authentication, allows prompt injection, and grants shell access by design. Monday's VentureBeat article documented these architectural flaws. By Wednesday, security researchers had validated a...