Security & Threat Intelligence

The Watch

The Signal

OpenClaw — the fastest-growing open source project in history

Simultaneously, AI agents are autonomously transacting $1.6M/month via embedded HTTP payment protocols while non-human identities outnumber humans 100:1 in financial services — and no production identity verification standard exists for any of them.

In Play

  1. Supply Chain Trust Models Breaking at Scale

    OpenClaw has 20%+ malicious contributions and 60x curl's security incident volume — community review can't scale. Meanwhile, SimpleClosure's Asset Hub is selling defunct startups' Slack, email, and code to AI training pipelines. Your dead vendors are now data brokers.

    Ask Clarity
  2. Non-Human Identity & Agent Economy Attack Surface

    NHIs outnumber humans 100:1 in financial services. AI agents now transact autonomously via x402 ($1.6M/month) and Stripe MPP (34K transactions in week one). Computer-use agents like Codex have full desktop, Slack, and browser access — functionally indistinguishable from insider threats. No KYA standard exists.

    Ask Clarity
  3. AI Workloads Now Uninsurable — Silent Financial Exposure

    Insurance carriers are quietly excluding AI workloads from cyber and E&O coverage, citing output unpredictability. If your insurer can't price the risk, your internal risk models are almost certainly insufficient too. SOC 2 reports and vendor questionnaires representing adequate coverage may now contain material misstatements.

    Ask Clarity
  4. Hormuz Crisis Opens Iranian Cyber Escalation Window

    US-Iran Hormuz standoff is the highest-probability trigger for Iranian retaliatory cyber ops since the 2020 Soleimani strike. 135M barrels stranded, contradictory diplomatic claims, and Iran's explicit threat to re-close the strait. APT33, APT34, APT35, and MuddyWater all have documented escalation patterns during crises.

    Ask Clarity
  5. Mythos Model: Reality Check — Hype Outpaces Evidence

    Four sources covered Mythos this cycle. VulnCheck found only 1 confirmed CVE from Project Glasswing — but researchers replicated dangerous capabilities with commodity models, meaning the capability is diffusing regardless. Pentagon blocked Anthropic as 'supply chain risk' while Treasury seeks access; White House intervening.

    Ask Clarity

Deep Dives

Your Supply Chain Trust Model Just Failed Twice: OpenClaw's 20% Poison Rate and Your Dead Vendors Selling Your Data

Two Simultaneous Supply Chain Crises

Two distinct supply chain trust failures surfaced today that compound each other. The first is OpenClaw — described as the fastest-growing open source project in history — which is under active adversarial siege at industrial scale. Peter Steinberger's dual TED/AIE talk revealed the project receives 60x more security incident reports than curl (the internet's HTTP backbone) and that at least 20% of skill contributions are confirmed malicious. This isn't a theoretical risk assessment — it's a live, quantified poisoning campaign against a hypergrowth dependency.

The second: SimpleClosure launched Asset Hub, a platform enabling defunct startups to sell their internal Slack messages, emails, source code, and operational data to AI training pipelines. The claimed safeguard is PII removal — unverified, and privacy advocates are already raising alarms. If your organization ever shared proprietary information with a startup that subsequently failed — via Slack Connect, shared repos, pilot programs, or email threads — that data may now be commercially available to any buyer.


Why OpenClaw Breaks the Open Source Trust Model

The foundational assumption of open source security — "many eyes make bugs shallow" — collapses when 1-in-5 contributions are adversarial and growth outpaces maintainer capacity by 60x. Community review does not scale against organized supply chain attackers targeting a project growing faster than anything before it.

MetriccurlOpenClawImplication
Security incidentsBaseline60x higherReview capacity overwhelmed
Malicious contributionsNear-zero20%+ confirmedTrust model broken
Growth trajectoryMature, stableFastest in historySecurity cannot scale with adoption

Any unvetted OpenClaw component in your dependency tree is, statistically, a coin-flip from compromise. Blocklisting is insufficient when 1 in 5 submissions is adversarial — you need explicit allowlisting with cryptographic verification.

SimpleClosure: Your DPA Didn't Survive Dissolution

The blast radius here is retrospective. Every startup vendor, partner, or acquisition target that shut down in the past 24 months potentially held your proprietary data — and your data processing agreement almost certainly didn't account for the company selling that data as a training asset during wind-down. This is a GDPR, SOC 2, and contractual representation problem that exists right now, not hypothetically.

At 20% malicious contributions, OpenClaw proves that open-source trust models break at hypergrowth scale — and SimpleClosure proves your dead vendors are still a live supply chain risk.

What to do

  1. Run a complete dependency scan for OpenClaw skills and plugins across all codebases and CI/CD pipelines immediately — switch to explicit allowlisting with cryptographic verification for any retained components

  2. Identify all startup vendors, partners, and acquisition targets that shut down in the past 24 months and determine what proprietary data they held — complete by end of this sprint

  3. Update vendor contract templates to include data disposition clauses covering dissolution, wind-down, and asset sale scenarios — specifically prohibiting AI training use — by end of quarter

  4. Pin versions and verify signatures for Hermes Agent, LangChain, deepagents, and Ollama-distributed models — these derivative ecosystems have no centralized security review

Non-Human Identities Are Spending Your Money: The Agent Economy Attack Surface You Don't Have Controls For

Agents Are Now Autonomous Economic Actors

Two independent intelligence streams converge on the same conclusion: AI agents have crossed the threshold from data processors to autonomous economic actors, and your identity, authorization, and detection infrastructure wasn't built for them.

Non-human identities in financial services already outnumber humans 100:1. Coinbase's x402 protocol is processing $1.6M/month in agent-driven crypto payments embedded directly in HTTP requests. Stripe and Tempo's MPP marketplace processed 34,000+ transactions in its first week with 60+ agent services. Tools like Merit Systems' AgentCash let agents autonomously purchase data enrichment from Apollo, Google Maps, and Whitepages via CLI — financial authority with no human approval per transaction.

Simultaneously, OpenAI's Codex Computer Use can drive Slack, browser flows, and arbitrary desktop applications. Greg Brockman explicitly framed Codex as evolving into a "full agentic IDE." These agents operate under legitimate user sessions, at machine speed, with the same UI-level access as your most privileged insiders.


The Detection Gap

A compromised or prompt-injected computer-use agent is functionally indistinguishable from a sophisticated insider threat — except it operates at machine speed, doesn't sleep, and your DLP rules probably don't fire on UI-level data movement. Map these to MITRE ATT&CK and the coverage gaps become clear:

  • T1059 — Agents executing arbitrary actions via UI automation
  • T1078 — Agents operating under legitimate user sessions
  • T1020 — Agents capable of copying data across apps at machine speed
  • T1071 — Agent communications via Slack, browser, application layer

The Identity Vacuum

KYA (Know Your Agent) has been proposed as the agent equivalent of KYC — cryptographically signed credentials linking agents to principals, permissions, and constraints. But this is a proposal, not a production standard. Today, there is no reliable mechanism to verify whether an agent calling your API is who it claims to be, what permissions its principal delegated, or who is liable when it exceeds its mandate.

The emergence of headless merchants — API-only services with no frontend, storefront, or legal entity — as primary vendors for AI agent purchases creates a gap in traditional vendor due diligence that affects SOC 2, GDPR, and any framework requiring third-party risk assessment.

Human-in-the-loop oversight is described as a 'physical impossibility' given agent throughput — plan for automated trust assessment, not manual approval gates.

What to do

  1. Inventory all non-human identities (service accounts, API keys, bot tokens, agent credentials) and flag any with financial transaction capabilities or access to x402/MPP/Stripe integrations — complete within two weeks

  2. Define and enforce an agent access control framework before any computer-use agent (Codex, Claude Code) touches production: separate agent identity model, scoped UI permissions, immutable session recording, and automated kill switches

  3. Add agent-specific detection rules to SIEM/EDR: sub-second UI interaction sequences, cross-application data flows within single sessions, credential access via UI elements, bulk operations exceeding human speed

  4. Deploy automated detection for agent-initiated outbound transactions to unvetted headless merchant endpoints and monitor for CLI procurement tools (AgentCash) appearing in your environment

Your AI Workloads Are Now Uninsurable — And That's a Board Disclosure Problem

Insurance Carriers Are Telling You Something Important

Cyber insurance carriers are quietly exempting AI workloads from cybersecurity and E&O coverage, citing AI output unpredictability. This isn't a pricing adjustment — it's a structural refusal. If the insurance industry, whose entire business is pricing risk, can't model your AI exposure, your organization's internal risk models are almost certainly insufficient too.

The implications are threefold:

1. Silent Financial Exposure

If you deployed AI in the last year, your risk transfer assumptions may already be wrong. An AI-related incident — a hallucinating model generating actionable misinformation, a compromised AI pipeline exfiltrating data, an AI-driven decision causing regulatory liability — may now be an entirely uninsured event. The exclusion language to search for in your policies: "artificial intelligence," "machine learning," "algorithmic decision-making," or "automated outputs."

2. Compliance and Disclosure Gap

If you represent to customers, partners, or regulators that you carry adequate cyber insurance, and your policy now silently excludes AI workloads processing their data, you have a disclosure problem. SOC 2 Type II reports, vendor risk questionnaires, and contract representations may contain material misstatements. This is the kind of gap that surfaces in post-incident litigation, not during routine audits.

3. AI Risk Governance Signal

The insurance exclusion is itself a risk indicator. Carriers are saying your AI governance isn't mature enough for the exposure you're carrying. CISOs are reporting three drivers of AI security blind spots: the speed of AI deployments, the ease of accessing AI capabilities (just an API key, no infrastructure required), and the inherent technology complexity. Shadow AI creates decision-making attack surface — a compromised or hallucinating model doesn't just leak data, it generates wrong outputs that get acted on.

If your insurer won't cover your AI workloads, that's not just a coverage gap — it's a signal that your AI risk governance isn't mature enough for the exposure you're carrying.

Converging with the Insurance Gap: Sub-30-Second Attack Windows

Reports indicate attackers now operating at machine speed with timelines under 30 seconds from initial access to lateral movement. The concept of an "AI parity window" — the gap between attacker automation and defender automation — is emerging as a critical operational metric. If your SOC's median alert-to-containment time is measured in minutes, you are structurally unable to respond to machine-speed attacks. The insurance industry may be recognizing what many security teams haven't yet quantified: the speed differential between AI-enabled offense and human-gated defense is becoming uninsurable.

What to do

  1. Pull current cyber and E&O policies this week and search for AI exclusion language — brief risk committee and general counsel if exclusions exist

  2. Conduct a shadow AI discovery exercise within 30 days — use CASB logs, DNS/proxy telemetry, and API gateway traffic to identify AI service endpoints, then cross-reference with procurement records

  3. Identify 3-5 SOC response workflows where human approval gates can be replaced with automated containment actions (with rollback capability) — deploy within 30 days

  4. Register 'AI debt' as a formal risk category in your enterprise risk register with defined KRIs: ratio of deployed agents to verified agents, drift detection coverage, average time from AI deployment to first security review

Hormuz Standoff Creates the Highest Iranian Cyber Escalation Risk Since 2020 — Review Your Detection Rules Now

Geopolitical Trigger, Documented Cyber Consequence

The Strait of Hormuz situation is volatile and directly maps to your threat environment. Iran reopened commercial shipping on April 17, but the US is maintaining a blockade of Iran-affiliated traffic. Iran responded by threatening re-closure. President Trump claims a deal is imminent; Iran's top negotiator says Trump made "seven false claims in one hour." There are 135 million barrels of oil stranded in Gulf tankers.

For security teams, geopolitical tensions between the US and Iran have a documented correlation with elevated Iranian cyber operations. The combination of a US military blockade, contradictory diplomatic claims, and Iran's explicit threat creates the highest-probability window for Iranian retaliatory cyber operations since the Soleimani strike in January 2020.


Threat Groups and Target Sets

GroupMITRE IDPrimary TargetsKey TTPs
APT33 / ElfinG0064Energy, aerospace, petrochemicalSpearphishing, destructive wipers (Shamoon)
APT34 / OilRigG0049Financial, government, energyCredential harvesting, DNS tunneling
APT35 / Charming KittenG0059Government, defense, mediaSocial engineering, credential theft
MuddyWaterG0069Government, telecoms, energySpearphishing, PowerShell abuse

Who Needs to Act

If your organization touches energy, financial services, defense, critical infrastructure, or maritime/logistics, this is not theoretical — this is the active threat environment. Historically, Iranian cyber escalation follows geopolitical escalation by days to weeks, not months. The preference for destructive attacks (wipers over ransomware) during crisis periods is well-documented.

Even organizations outside primary target sectors should be alert: Iranian groups have demonstrated supply chain compromise capabilities (APT34) that can propagate through vendor relationships into unexpected targets.

When the Strait of Hormuz becomes a flashpoint, Iranian APTs historically go kinetic on US networks within days. If you're in energy, finance, or defense, refresh your detection rules this week — not next month.

What to do

  1. Review and refresh SIEM/EDR detection rules for Iranian APT indicators this week — prioritize T1566 (Phishing), T1078 (Valid Accounts), T1059.001 (PowerShell), and T1485 (Data Destruction/Wipers)

  2. If you have OT/ICS environments, verify network segmentation and monitoring are active and tested within one week

  3. Brief your SOC on elevated Iranian APT activity likelihood and distribute updated IOC feeds from CISA and sector ISACs

  4. Activate geopolitical risk playbook for Hormuz disruption scenarios if in energy, maritime, or logistics — include cyber-physical attack modeling on OT systems

The bottom line

Your supply chain trust model just broke in two places simultaneously — OpenClaw's 20% malicious contribution rate proves open source review can't scale at hypergrowth, while defunct startups are actively selling your proprietary Slack and email data on SimpleClosure's Asset Hub. Meanwhile, non-human identities outnumber humans 100:1 and are autonomously spending money via protocols your controls weren't designed to monitor, insurance carriers are quietly refusing to cover any of your AI workloads, and the Hormuz standoff has Iranian APTs loading their cyber rifles. The connecting thread: every governance model built for human-speed, human-scale operations is failing against AI-speed, AI-scale reality.