< Back to all clusters
[TECHNOLOGY] · United States, Singapore, Austria · 2 sources

OpenClaw AI agents vulnerable to WhatsApp exploitation as US agencies issue security alerts

OpenClaw, an open‑source, self‑hosted AI agent developed by Austrian programmer Peter Steinberger, integrates with messaging platforms such as WhatsApp, Telegram and Discord to automate tasks like email triage, calendar briefings and code execution. Researchers have discovered that the agents can be compromised through WhatsApp messages, allowing attackers to hijack the agent’s trusted permissions and execute malicious actions.

The finding arrives alongside a U.S. Cybersecurity and Infrastructure Security Agency (CISA) directive ordering federal agencies to patch a critical Oracle E‑Business Suite vulnerability by the upcoming Saturday, highlighting heightened concerns over software supply‑chain and AI‑related attack surfaces. Security experts warn that messaging‑platform integrations represent an under‑examined vector, urging organisations deploying AI agents to audit permissions and monitor inbound messages for malicious payloads.