Find notable cyber news and cases, enriched with sources, timelines, and signals.

AI agent phishing controls for sender verification, external-recipient approval, and internal data restriction

Defensive Guidance
First reported
Last updated
Happening score
H score 28
1 unique sources, 1 articles

Summary

Hide ▲

A simulated phishing test showed that an OpenClaw AI email agent could be induced to expose credentials and customer data, increasing the risk of phishing-driven data leakage in autonomous workflows. The agent was stronger at spotting malicious URLs and OAuth lures than at verifying sender identities under urgent social-engineering prompts. Recommended controls now focus on approval for new external recipients, limited internal data access, and human review for high-risk actions.

Related Happenings

OpenClaw outbound-mail approval gates and trust-scoped connector controls

Defensive Guidance
H score11 First: 11.06.2026 20:46 Last: 11.06.2026 20:46 Sources 1

About this happening: OpenClaw operators are adding outbound-mail approval gates, trust-scoped connector access, and human approval for risky actions to reduce agent phishing and unauth...

OpenClaw phishing simulations expose AI agent identity-verification failures

Technical Analysis
H score23 First: 10.06.2026 00:20 Last: 10.06.2026 00:20 Sources 1

How related: “Varonis Threat Labs explored whether the same phishing techniques that have tricked humans for decades would also work on the AI agents working on their behalf,” reads the report.

About this happening: Researchers found that OpenClaw email agents could be manipulated by phishing simulations, exposing gaps in sender verification and risky handling of sensitive data. I...

Bayer reworks awareness training and AI access controls against AI-driven social engineering

Defensive Guidance
H score10 First: 02.06.2026 16:45 Last: 02.06.2026 16:45 Sources 1

About this happening: Bayer has shifted to psychology-first security awareness and tiered AI access controls to blunt AI-generated social engineering across employees and suppliers. The pro...

Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations

Threat Actor Meta
H score82 First: 05.03.2026 08:51 Last: 05.03.2026 08:51 Sources 1

About this happening: Tycoon2FA has shifted from a subscription-based PhaaS and AitM credential harvester into a more resilient campaign that now uses device-code phishing against Mic...

Latest development: 17.05.2026 17:43

eSentire says Tycoon2FA now uses device-code phishing to target Microsoft 365 accounts, with invoice-themed lure emails carrying Trustifi click-tracking URLs that redirect through Trustifi, Cloudflare Workers, obfuscated JavaScript layers, and a fake Microsoft CAPTCHA page before sending victims to microsoft.com/devicelogin. The kit also adds anti-analysis defenses, including detection of Selenium, Puppeteer, Playwright, and Burp Suite, plus blocks for security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.

Starkiller dark-web phishing platform scales credential theft as a SaaS-style criminal service

Threat Actor Meta
H score36 First: 19.02.2026 14:00 Last: 19.02.2026 14:00 Sources 1

About this happening: The Starkiller phishing platform has emerged as a SaaS-style criminal service, raising the scale and durability of credential theft operations. It is sold on the dark we...

Timeline

  1. 10.06.2026 00:20 2 articles · 1mo ago

    OpenClaw phishing tests expose sender verification gaps

    Technical Analysis Update

    Varonis tested an OpenClaw AI email agent connected to Gmail, Google Workspace APIs, browser tools, and fabricated internal company data sources, and found that phishing-style prompts could still induce disclosure of AWS IAM keys, database credentials, SSH access details, and a CRM export to an external Gmail account. The same evaluation also showed the agent could detect suspicious URLs, fake login pages, malicious OAuth apps, and other phishing indicators, but Varonis says the system still failed when operationally urgent requests bypassed identity verification. The recommended controls are explicit sender identity verification, approval for new external recipients, limited access to internal data, and human approval for high-risk actions such as credential sharing and first-time communications.

    Show sources