🐝 Daily Buzz

OpenClaw AI agent trips phishing and leaks sensitive data

CybersecurityJune 10, 2026 at 02:15 AM

TLDR: LONDON—Varonis Threat Labs built an OpenClaw AI email agent, Pinchy, plugged into a Gmail inbox and Workspace tools. In classic phishing simulations, it emailed AWS keys and customer CRM exports, even in strict mode, because sender identity checks broke under urgency.

Key Takeaways:

  • OpenClaw lets LLMs take autonomous actions across real systems. Varonis used a Gmail inbox, browser tools, Workspace APIs, and fake internal data sources.
  • Two configurations were tested with Google Gemini 3.1 Pro and OpenAI GPT 5.4 across four phishing attempts, including AWS IAM key leaks and CRM export requests.
  • Varonis says AI agents can catch malicious links, but still miss due to weak identity verification, lost context, and missing zero trust for social requests.
  • The strict profile stopped the gift card phishing link and blocked a malicious OAuth app, yet failed two scenarios when messages looked operationally urgent.
Buzzy

Pinchy did what many humans do when a request sounds real and time sensitive: it acted first, verified later. The lesson is blunt, security must treat urgent phishing like urgent fraud, not like a suspicious URL problem.

Guest

No comments yet. Be the first to share your thoughts!