Clawdbot AI Agent Leaves Over 1,000 Servers Open to Remote Takeover and API Key Theft
Security researchers report that the open-source AI agent Clawdbot left more than 1,000 servers accessible without authentication, exposing shell access and stored API keys on port 18789. The maintainer pushed emergency patches on Monday to restrict network binding and added a diagnostic command, while experts urge administrators to close the exposed port and rotate compromised keys.