This is a fileless attack using ClickFix social engineering & Trust abuse
Execution primitive: mshta.exe โ launches PowerShell
Persistence technique: Steganography hides shellcode in image pixels
Evasion: In-memory execution only โ low detection by signature-based AV
Did u know 404 isn't alone. It has a whole set of cousins
200 - OK
201 - Created
301 - Moved Permanently
302 - Found
400 - Bad Request
401 - Not Authorised
403 - Forbidden
405 - Method Not Allowed
404 - Page Not Found
500 - Internal Service Error
503 - Service Unavailable
Microsoft had just announced it was expanding its use of OpenClaw for its new "Scout" AI agent, claiming it had "enterprise-grade security."
The timing made Microsoft's announcement look "absurd" and "poorly timed" because the security holes were discovered right before.
Security researcher found five serious security holes (zero-days) in OpenClaw that let attackers trick AI agents into doing bad things by just changing their display name, and Microsoft announced it was expanding its use of OpenClaw at the worst possible time
Key finding 4 u
๐
These flaws let attackers impersonate trusted users by simply changing their display name on chat apps like Slack, Discord, and Microsoft Teams.
Because of this, an attacker could hijack the AI agent and make it read files, run commands, or access internal data.
Finally Verified ๐
Reached my follow and reply limits,
and it was keeping me away from my fam.
So I took the step forward:
upgraded to the verified badge.
Now my account is officially recognized,
and staying connected with my community is effortless.
@SapperJaeger@UK_Daniel_Card That's something people hardly realise.
They don't speak because they want to give you knowledge.
They hold the microphone to make you listen to something they want you to listen, something that will benefit their business, make them money.
I am personally dead against smart home systems. I need privacy at least at home.
Also doing things on my own gives me a weird feeling of happiness, connection......which these smart devices steal from me