Infosec In Brief So-hot-right-now AI assistant OpenClaw, which is very much not secure right now, has teamed up with security scanning service VirusTotal. The tie-up means “skills” in the ClawHub – custom plugins for the OpenClaw assistant – will be scanned by over 70 antivirus scanners and URL/domain blocklisting services. “OpenClaw skills are powerful. They extend what your AI agent can do—from controlling smart home devices to managing finances to automating workflows. But with that power comes risk,” the assistant’s developers wrote in a Saturday post that explains the decision to work with VirusTotal. The post points out that working with the scanning service won’t totally secure OpenClaw. “Let’s be clear: this is not a silver bullet,” the developers wrote. “VirusTotal scanning won’t catch everything. A skill that uses natural language to instruct an agent to do something malicious won’t trigger a virus signature. A carefully crafted prompt injection payload won’t show up in a threat database.” Fallout from the Salt Typhoon hack of leading American telcos continues, and one US Senator isn't convinced that victim companies are being honest. Senator Maria Cantwell (D-WA), the ranking member of the Senate Committee on Commerce, Science, and Transportation, last week sent a letter to her Republican counterpart demanding the CEOs of AT&T and Verizon appear before the group to explain why they keep withholding security assessments performed in the wake of 2024 revelations of w...
Apache warns of 10.0-rated flaw in Tika metadata toolkit
The Register
·Brandon Vigliarolo and Simon Sharwood
·Published Dec 8, 2025
·Updated
Affected Software
3 affected components
SmarterTools SmarterMail=2026-23760
SmarterTools SmarterMail=2025-52691
SmarterTools SmarterMail=2026-24423
Frequently Asked Questions
1
What security vulnerability is highlighted in the article?
The article highlights a 10.0-rated flaw in the Apache Tika metadata toolkit.
2
What specific flaw was fixed by Meta regarding Instagram?
Meta fixed a flaw that allowed third parties to generate password reset emails.
3
Did the password reset flaw on Instagram lead to any personal data theft?
Meta denies that the password reset flaw led to the theft of users' personal information.
4
Which product from Veeam Backup is mentioned as affected by a security issue?
The article mentions a security vulnerability identified as CVE-2025-59470 affecting Veeam Backup.
5
Who reported the security issues discussed in the article?
The security issues were reported by the software vendor Malwarebytes.