Token Security Warns of Widespread Clawdbot Use Inside Enterprises
According to a report by Token Security, one in five enterprises have employees running the open-source AI assistant Clawdbot—also known as Moltbot—inside their organizations. The company’s analysis found that 22% of customers showed evidence of the tool being used, highlighting a growing 'shadow AI' issue in corporate environments.
Clawdbot, created by developer Peter Steinberger, runs locally on Mac or Linux systems and integrates with popular messaging platforms such as Slack, WhatsApp, Telegram, and Microsoft Teams. Unlike browser-based chatbots, it can access and manipulate files, emails, calendars, and even execute terminal commands, giving it deep control over user systems.
Token Security’s researchers identified multiple critical risks, including plaintext credential storage, exposed control servers, and remote code execution vulnerabilities. They discovered hundreds of Clawdbot instances accessible over the internet without authentication, exposing sensitive tokens and conversation histories. The tool’s lack of centralized logging and sandboxing means that corporate data can flow outside security perimeters without detection.
The company advises enterprises to detect Clawdbot installations, audit OAuth and API permissions, and enforce clear AI usage policies. Token Security also offers tools to identify and control AI agent activity, enabling organizations to monitor access to corporate systems and restrict unauthorized integrations.
We hope you enjoyed this article
Consider subscribing to one of our newsletters like Cybersecurity AI Weekly or Daily AI Brief.
Also, consider following us on social media:
More from Cybersecurity
Sep 19 Researchers Used Anthropic Tool to Access OpenAI Employee Account Sep 18 Cyble Signs Threat Intelligence Agreement With UAE Cybersecurity Council Sep 17 NeuralTrust Named Pioneer in Gartner AI Application Security Quadrant Sep 17 LogicGate Named a Leader in IDC Third Party Risk Software Assessment Sep 17 Arcjet Launches Runtime Security for AI AgentsCybersecurity AI Weekly
Weekly newsletter about AI in Cybersecurity.
Whitepaper
Tensordyne Napier: What If One Rack Could Do the Work of Nine?
Tensordyne
This Tensordyne whitepaper presents Napier, an inference-focused AI processor and rack-scale system based on the company’s TDN Math logarithmic number system. It examines infrastructure requirements for large mixture-of-experts and agentic models, compares major inference architecture approaches, and details the TDN AIP processor, TDN72 pod, TDN Link fabric, and Napier Ultra configuration. The paper reports simulation-based performance, cost, and accuracy-validation results, including Tensordyne’s projected comparison of one Napier rack with a nine-rack Nvidia Rubin plus Groq deployment; the chip is reported as taped out and in fabrication.
Read moreYou may also like
Anthropic's Threat Report Finds AI Moving From Assistant to Orchestrator
Anthropic Attributes Its Largest Measured Distillation Campaign to Alibaba
Researchers Used Anthropic Tool to Access OpenAI Employee Account
OpenAI Executive Warns of Persistent AI Cyber Attacks
Harness Survey Finds AI Agent Controls Lag Enterprise Confidence
Daily AI Brief: the AI news that matters, in your inbox.