Infosec In Brief So-hot-right-now AI assistant OpenClaw, which is very much not secure right now, has teamed up with security scanning service VirusTotal. The tie-up means “skills” in the ClawHub – custom plugins for the OpenClaw assistant – will be scanned by over 70 antivirus scanners and URL/domain blocklisting services. “OpenClaw skills are powerful. They extend what your AI agent can do—from controlling smart home devices to managing finances to automating workflows. But with that power comes risk,” the assistant’s developers wrote in a Saturday post that explains the decision to work with VirusTotal. The post points out that working with the scanning service won’t totally secure OpenClaw. “Let’s be clear: this is not a silver bullet,” the developers wrote. “VirusTotal scanning won’t catch everything. A skill that uses natural language to instruct an agent to do something malicious won’t trigger a virus signature. A carefully crafted prompt injection payload won’t show up in a threat database.” Fallout from the Salt Typhoon hack of leading American telcos continues, and one US Senator isn't convinced that victim companies are being honest. Senator Maria Cantwell (D-WA), the ranking member of the Senate Committee on Commerce, Science, and Transportation, last week sent a letter to her Republican counterpart demanding the CEOs of AT&T and Verizon appear before the group to explain why they keep withholding security assessments performed in the wake of 2024 revelations of w...
That didn't take long: Replacement for SORBS spam blacklist arises ... sort of
The Register
·Brandon Vigliarolo
·Published Jun 17, 2024
·Updated
Affected Software
4 affected components
Apache Tika
Apache tika-parser-pdf-module
Apache tika-core=3.2.2
Apache tika-parsers
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the release of new tools by Mandiant that can crack credentials quickly to address vulnerabilities in an outdated Microsoft security protocol.
2
What security implications are discussed in the article?
The article highlights the potential risks associated with the ancient Microsoft security protocol and the need for faster credential-cracking tools to mitigate these risks.
3
What products or software are affected by the security issues mentioned?
The software affected includes various components of Apache Tika, such as Apache Tika Core and Tika Parsers.
4
What is the purpose of the new tools released by Mandiant?
The tools are intended to accelerate the phasing out of the outdated Microsoft security protocol by enabling quick credential cracking.
5
How does this article relate to spam blacklists?
The article mentions a new replacement for the SORBS spam blacklist, indicating ongoing developments in spam management alongside credential security discussions.