
Researchers Disclose Critical Vulnerabilities in OpenClaw and JobStealer Malware Campaign
Tech
Researchers disclosed a four-bug exploit chain in OpenClaw, a widely used open-source network scanning tool, allowing remote code execution on affected systems. The vulnerabilities, identified during a Mythos penetration testing evaluation, include memory corruption and improper input validation flaws. A fake job interview campaign was also reported, distributing JobStealer malware via malicious PDF attachments to target professionals in the tech and finance sectors. The malware, disguised as a legitimate interview scheduling tool, exfiltrates credentials and sensitive data to attacker-controlled servers. No specific CVE IDs or patch release dates were provided for the OpenClaw vulnerabilities.