business intelligence tools

Your AI agent's autonomy just became a security risk

In a striking revelation, Etay Maor, VP of Threat Intelligence at Cato Networks, highlighted the alarming implications of OpenClaw's widespread adoption during an exclusive VentureBeat interview at RSAC 2026.

3 min readVentureBeat
Your AI agent's autonomy just became a security risk

The industry handed AI agents root access to the most sensitive systems in the enterprise, and the attackers just collected the keys. A U.K. CEO's OpenClaw instance sat on BreachForums for $25,000, offering not just a shell but every conversation, credential, and financial detail the CEO had entrusted to his AI assistant. The threat actor didn't need to steal anything. The CEO had already assembled it. This is not a hypothetical risk or a vendor talking point. It is a live intelligence feed that was for sale on the open web, and the security community is still waiting for a single native kill switch that can shut it down.

For every organization that has adopted or tolerated OpenClaw, the practical reality is stark. Nearly 500,000 instances are now internet-facing, and more than 30,000 of those carry observable security risks. Three high-severity CVEs have been patched, but there is no centralized patching mechanism and no fleet-wide kill switch. The CEO's instance stored everything in plain-text Markdown files with no encryption at rest. The attacker didn't exfiltrate data; the victim had already organized it. CrowdStrike's sensors already detect 1,800 distinct AI applications across customer fleets, and the OWASP Agentic Skills Top 10 now uses a malicious skill called ClawHavoc as its primary case study. Ghost agents, instances that were piloted, abandoned, and left running with active credentials, compound the exposure. If you cannot see which AI tools are running on your network, you cannot defend them.

Cisco, Palo Alto Networks, and Cato Networks all shipped responses at RSAC 2026, and each offers something useful. Cisco's DefenseClaw framework, running inside NVIDIA's OpenShell runtime, packages skill scanning, MCP verification, and runtime monitoring into a single open-source tool. Palo Alto's Prisma AIRS 3.0 requires every agent to register before operating, with credential validation and runtime monitoring. Cato CTRL delivered the adversarial proof that makes these products necessary. But none of these is the one control enterprises need most: a native kill switch for unsanctioned OpenClaw deployments that an administrator can trigger across the fleet in seconds. Until that exists, the Monday morning action list is the closest thing to one.

Start by discovering the install base. Use your existing EDR, MDM, or SASE platform to query for the ~/.openclaw/ directory. If you have no endpoint visibility at all, run Shodan and Censys queries against your corporate IP ranges. Then patch every discovered instance against the three known CVEs, or network-isolate the ones that cannot be patched. Audit every installed skill against Cisco's Skills Scanner or the Snyk and Koi research. Remove any skill from an unverified source immediately. Build a registry of every AI agent running in your environment, document its business justification and the credentials it holds, and revoke credentials for agents with no justification. Repeat that exercise weekly. The attackers are already watching. The only question is whether you are watching back.

From VentureBeat

“Your AI? It’s my AI now.” The line came from Etay Maor, VP of Threat Intelligence at Cato Networks, in an exclusive interview with VentureBeat at RSAC 2026 — and it describes exactly what happened to a U.K. CEO whose OpenClaw instance ended up for sale on BreachForums. Maor's argument is that the industry handed AI agents the kind of autonomy it would never extend to a human employee, discarding zero trust, least privilege, and assume-breach in the process.

Read the original at VentureBeat