FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ /r/netsec - Information Security News & Discussion

OpenClaw (aka Clawdbot) gives malicious websites access to session cookies

By: /u/Prior-Penalty β€” February 2nd 2026 at 19:37

A recently-patched OpenClaw vulnerability allowed attackers to use malicious websites to steal session credentials from other browser tabs. The heart of the problem was a websocket service for orchestrating Chrome which accepted connections without authentication, including connections from javascript running in the user's browser.

OpenClaw users are encouraged to patch ASAP, and to use caution where and how they deploy it, given its ongoing security issues and security architecture concerns.

submitted by /u/Prior-Penalty
[link] [comments]
☐ β˜† βœ‡ /r/netsec - Information Security News & Discussion

Better-Auth Critical Account Takeover via Unauthenticated API Key Creation (CVE-2025-61928)

By: /u/Prior-Penalty β€” October 20th 2025 at 19:44

A complete account takeover found with AI for any application using better-auth with API keys enabled, and with 300k weekly downloads, it probably affects a large number of projects. Some of the folks using it can be found here: https://github.com/better-auth/better-auth/discussions/2581.

submitted by /u/Prior-Penalty
[link] [comments]
❌