<p>OpenClaw has become one of the fastest adopted open source tools in recent memory. Originally released in late 2025 under the name Clawdbot, this autonomous AI agent now boasts hundreds of thousands of GitHub stars and a rapidly expanding ecosystem of third-party skills.</p>
<p>For enterprise CISOs and other business leaders, <a href=”https://www.techtarget.com/searchcio/feature/OpenClaw-and-Moltbook-explained-The-latest-AI-agent-craze”>OpenClaw’s appeal is obvious</a>: It can automate routine workflows, manage calendars and inboxes, and interact with SaaS platforms through natural language commands. But that convenience comes with a threat surface that traditional security models were never designed to address.</p>
<section class=”section main-article-chapter” data-menu-title=”Why CISOs should care about OpenClaw”>
<h2 class=”section-title”><i class=”icon” data-icon=”1″></i>Why CISOs should care about OpenClaw</h2>
<p>OpenClaw operates by bridging large language models and local system resources. It can run shell commands, control browsers, read/write files and interact with external services, which users can trigger from chat messages on platforms such as Slack, Signal and Discord.</p>
<p>The very permissions that make it useful, however, also make OpenClaw dangerous. When connected to corporate tools such as Google Workspace or Microsoft 365, OpenClaw gains access to emails, documents, calendar entries and OAuth tokens that could enable lateral movement across your environment. Security researchers have described this combination of private data access, external communication capability and exposure to untrusted content as a <a href=”https://www.techtarget.com/searchsecurity/tip/The-agentic-AI-lethal-trifecta-What-CISOs-should-know”><i>lethal trifecta</i> for enterprise AI risk</a>.</p>
<h3>OpenClaw security risks</h3>
<p><a href=”https://www.techtarget.com/searchsecurity/tip/The-OpenClaw-security-risks-every-CISO-needs-to-know”>OpenClaw risks</a> are not theoretical. Security researchers have <a target=”_blank” href=”https://declawed.io/” rel=”noopener”>identified</a> more than a million OpenClaw instances exposed to the public internet, including 100,000-plus that were directly vulnerable to remote code execution. A critical vulnerability, <a target=”_blank” href=”https://nvd.nist.gov/vuln/detail/CVE-2026-25253″ rel=”noopener”>CVE-2026-25253</a>, was disclosed with a CVSS score of 8.8, alongside multiple command injection advisories. Making matters worse, in early 2026, researchers <a target=”_blank” href=”https://www.bitdefender.com/en-us/blog/labs/helpful-skills-or-hidden-payloads-bitdefender-labs-dives-deep-into-the-openclaw-malicious-skill-trap” rel=”noopener”>found</a> roughly 17% of the public ClawHub skills registry contained malicious code, including payloads that enable credential theft and data exfiltration.</p>
<p>Perhaps most concerning for enterprise security teams is the shadow AI dimension: OpenClaw requires no administrator privileges to install and generates no distinctive network signatures that standard monitoring tools would flag.</p>
</section>
<section class=”section main-article-chapter” data-menu-title=”Actionable steps to manage OpenClaw risk”>
<h2 class=”section-title”><i class=”icon” data-icon=”1″></i>Actionable steps to manage OpenClaw risk</h2>
<p>Despite their considerable security risks, agentic AI tools such as OpenClaw are likely here to stay. Given the technology’s productivity benefits, CISOs might find employee adoption continues whether security teams sanction it or not.</p>
<blockquote class=”main-article-pullquote”>
<div class=”main-article-pullquote-inner”>
<figure>
Given the technology’s productivity benefits, CISOs might find employee adoption continues whether security teams sanction it or not.
</figure>
<i class=”icon” data-icon=”z”></i>
</div>
</blockquote>
<p>The most effective approach is not to ban OpenClaw outright, but to incorporate it into your existing risk management framework. Start with clear policies, isolated environments, vetted supply chains and continuous monitoring.</p>
<h3>Establish governance before deployment</h3>
<p>Before permitting OpenClaw in any capacity, define an <a href=”https://www.techtarget.com/searchsecurity/tip/How-to-create-an-AI-acceptable-use-policy-plus-template”>acceptable use policy</a> that specifies which teams can deploy the agent, what data it can access and which integrations are approved.</p>
<p>Treat OpenClaw instances as you would any privileged service account, using formal provisioning, review cycles and offboarding procedur
[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.
Read the original article: