This website uses cookies

Read our Privacy policy and Terms of use for more information.

In partnership with

Welcome Automaters, 👋

So here’s the absolute latest tech gossip: OpenClaw has officially announced that its standalone companion apps are live on both the Apple App Store and the Google Play Store. 

This is an incredibly massive paradigm shift because it means autonomous AI agents are no longer sneaking around in the background of your phone. They can now sit front and center on your home screen with their own dedicated, grown-up software package.

Once you download the mobile node and pair it with your central OpenClaw Gateway using a quick QR code, the app politely asks for permission to peek into practically everything:

  • The Vision: It wants access to your live camera and realtime screen capture.

  • The Essentials: It requests your exact GPS location, photos, and contact lists.

  • The Agenda: It links directly into your calendar, reminders, and system notifications.

Basically, this agent wants the keys to your entire digital house! Is that a little bit spooky? Absolutely. Is it also mind-blowingly useful for seamless, device-aware automation? One hundred percent yes.

For anyone in the group chat who completely missed the backstory, OpenClaw went from a viral, experimental project to a dominant open-source AI powerhouse almost overnight. The project is now completely steered by the non-profit OpenClaw Foundation, a necessary transition that happened after its legendary creator, Austrian vibe coder Peter Steinberger, packed his bags to join OpenAI earlier this year.

The best part of the drama? OpenAI has publicly stated that they will be chipping in with backend support for the project, though nobody in Silicon Valley has spelled out exactly what that operational partnership looks like just yet.

Oh and, the juiciest plot twist in this entire rollout is definitely on Apple's side of the fence. Historically, Apple has acted like the ultimate, ultra-strict hall monitor of agentic AI. They have spent months blocking a wave of these tools over intense security worries and classic prompt injection anxieties tied to unvetted "vibe coding."

Before this official app store drop, iPhone power users were forced to chat with their self-hosted OpenClaw agents through third-party encrypted channels like Telegram, Slack, or WhatsApp.

Now? There’s an official, front-door native application. It gives you a beautiful live Canvas interface, voice trigger forwarding, and direct approvals right from your notification tray.

So what do you think? Are you rushing to download the mobile node and grant OpenClaw full access to your screen, or are you keeping the keys to your digital house locked tight? You should definitely go look up the official OpenClaw repository and test the setup for yourself.

Oh, and don't forget: We go even deeper on YouTube.

So go over there, hit Subscribe, hit the notification bell and come hang with us where the real conversation happens! 

Here's what we have for you today

😳 Claude Code Security Flaw: Innocent-Looking GitHub Repos Can Hijack Developer Machines via Hidden DNS Attack

So picture this: you clone a completely innocent looking GitHub repository, casually ask Anthropic's Claude Code to get it set up, and congratulations, you just blindly handed a total stranger the complete keys to your laptop.

Cybersecurity researchers over at Mozilla's 0Din team just demonstrated a brilliant new attack vector that is so deeply devious it barely even looks like a cyberattack at all. There is absolutely no malicious code hidden in the project files, and there are zero sketchy attachments. It’s just a routine repository that looks completely harmless, right up until Claude Code attempts to initialize it.

🎣 The "Helpful Assistant" Trap

The actual mechanics of the trick are delightfully simple yet terrifying. The repository includes a standard installation step utilizing a custom Python package that’s intentionally programmed to throw an error message the very first time it executes.

  • The Prompt: The error message politely suggests a quick fix, instructing the user to run a routine initialization command to resolve the issue.

  • The Action: Claude Code, acting like a highly efficient, helpful little assistant, automatically reads that error log and executes the suggested recovery command on your behalf.

  • The Exploit: That single initialization script quietly reaches out to pull a hidden configuration value directly from a standard DNS TXT record out on the open internet.

Because the underlying command is base64-encoded inside the internet's address book, it executes an interactive reverse shell straight on the developer's local machine. There’s no security pop-up, there’s no scary system warning, and there’s absolutely nothing for traditional antivirus tools to flag.

What makes this 0Din discovery a total game-changer for hackers is where the actual attack lives. Because the malicious payload resides entirely in the external DNS infrastructure rather than inside the GitHub repository itself, code review teams and static security scanners have absolutely nothing to catch. The attackers can even swap out the payload commands in real time without ever making a single new Git commit.

As the Mozilla researchers perfectly summarized the bottleneck, the repository, the external DNS network, and the developer's absolute trust in their autonomous AI agent are never evaluated together. Individually, none of those pieces look malicious.

But the second that silent reverse shell spawns, it’s essentially game over. Attackers can effortlessly scrape your private environment variables, swipe your enterprise API keys, harvest cloud credentials, and plant a permanent backdoor for later use. 

0Din warns that bad actors could easily distribute these booby-trapped repositories through fake job applications, coding tutorials, or casual developer Slack messages. If you run an autonomous agent against it, they own your machine.

You should definitely go look this up and read the full research notes for yourself; it is an incredible architectural wake-up call that is well worth exploring if you use AI tools in your daily pipeline!

From Our Partners:

The Lithium Boom is Heating Up

Lithium stock prices have more than doubled in the past year in response to ballooning costs and shortages. $ALB climbed 185%. $SQM, 133%.

This $1B unicorn’s patented technology can recover up to 3X more lithium than traditional methods. That’s earned investment from leaders like General Motors.

Now they’re preparing for commercial production just as experts project 5X demand growth by 2040. EnergyX is tapping into 100,000+ acres of lithium deposits in Chile, a potential $1.1B annual revenue opportunity at projected market prices.

Energy Exploration Technologies, Inc. (“EnergyX”) has engaged Beehiiv to publish this communication in connection with EnergyX’s ongoing Regulation A offering. Beehiiv has been paid in cash and may receive additional compensation. Beehiiv and/or its affiliates do not currently hold securities of EnergyX.

This compensation and any current or future ownership interest could create a conflict of interest. Please consider this disclosure alongside EnergyX’s offering materials. EnergyX’s Regulation A offering has been qualified by the SEC. Offers and sales may be made only by means of the qualified offering circular. Before investing, carefully review the offering circular, including the risk factors. The offering circular is available at invest.energyx.com/.

Comparisons to other companies are for informational purposes only and should not imply similar results. Past performance is not indicative of future results. Market shortfall are forward‑looking estimates and are subject to substantial uncertainty.

🧱 Around The AI Block

👩‍🎓 AI Tutorials

And: How to Use HeyGen in 2026 (Step-by-Step Beginner Tutorial).

So tell us, what’s the single most annoying, tedious task in your daily workflow that you desperately wish an AI could just handle for you?

Hit reply and the next video might just be around your exact problem!

Your Crypto Read Is Worth More Than You Think.

Kalshi has markets on BTC targets, ETH moves, and where crypto lands this cycle. No coin required. Just trade what you think happens. Peer-to-peer, no house edge, cash out anytime. Start with $10 free.

Trade responsibly.

🤖 AI Workout Of The Day: Custom Weekly Workout Plan Request

A custom weekly workout plan tailors the exercise routine to your specific fitness goals, body type, lifestyle, and current health condition. 

This way, you can focus on exercises that give you the best results.

💡 Prompts to try:

You are an expert fitness coach. I am [mention the problem you’re facing in detail with context]. Create a customized weekly workout plan for a [describe your age] year-old [specify gender] who aims to [state your fitness goal, e.g., lose weight, gain muscle, improve endurance]. I’m available to workout [mention number of days] days per week and have access to [specify equipment or no equipment]. I want you to [mention how you want the output in detail with examples].

Is this your AI Workout of the Week (WoW)? Cast your vote!

Login or Subscribe to participate

That's all we've got for you today.

Did you like today's content? We'd love to hear from you! Please share your thoughts on our content below👇

What'd you think of today's email?

Login or Subscribe to participate

Your feedback means a lot to us and helps improve the quality of our newsletter.

Reply

Avatar

or to participate

More From The Automated