Firewall integrations

Fortinet

Elevate the power of your Fortinet Fortigate Firewall using by adding our Intelligence.

Palo Alto

Palo Alto Firewalls can be hardened with our threat intelligence as well.

Sophos XGS

Enhance the Sophos XGS Firewall with our threat intelligence.

OPNsense

Enhance your OPNsense Firewall with our threat intelligence using the native plugin.

SIEM integrations

Splunk

Splunk is a great platform, but without the right Threat Intelligence it's just a log server. Try our threat intelligence today. 

Microsoft Sentinel

One of the most used SIEM solutions should be enriched with the right Intelligence. At Q-Feeds you're at the right place!

Other

Luckily there are many other SIEM vendors whom support 3rd party threat intelligence.

Threat Intelligence Portal

Darkweb Monitoring

Darkweb monitoring is one of our services, not only for threat intelligence but also for you most important assets.

Threat Lookup

With Threat Lookup you get full insights in our IOC database, including full MITRE ATT&K mapping.

External Attack Surface Management

A toolset to check your external facing assets exposed on the internet

Vulnerability Scanner

A comprehensive vulnerability scanner which can scan your infrastructure and web applications

Brand Protection

Protect your brand for look-a-likes and potential phishing attempts

Services

TAXII Feeds & Server Software

TAXII/STIX2.1 standard. Both in form of feeds and server software available

Implementation

Need help with implementations? No worries, we have a strong network of partners who are able to help you.

Solutions

Enrich my SIEM

Elevate the power of your SIEM solution using by adding our Intelligence.

Enrich my Firewall

Firewalls can be hardened with our threat intelligence as well.

Prevent phishing

Enhance your protection against phishing

Achieve compliancy

Achieve compliancy by correlating the best threat intelligence to your logs

Futuristic eye design with circuits and geometric shapes.

Company

About

Read here all about Q-Feeds

News and Updates

Cybersecurity news and updates about us

Publications

All of our media coverage in one place

Become a reseller

Strengthen your portfolio with our comprehensive reseller program

Partner locator

Find our certified partners here

Contact

For all your questions or inquiries

Neural network representation of a human brain

Support

My Account

Access your account and manage your licenses

Downloads & Manuals

On this page you find white papers and manuals

Knowledge base

Our knowledge base full of implementation instructions

Start for free

Start your cyber security intelligence journey here

Abstract geometric wireframe human head

Harnessing OpenClaw’s Skill Marketplace: Navigating the rising AI supply chain threat in cybersecurity

Jun 24, 2026 | Threat Intelligence Research

Rise of Malicious Skills in AI Agent Ecosystems

TL;DR The emergence of OpenClaw, an AI agent ecosystem, has led to the proliferation of malicious skills targeting vulnerabilities in the software supply chain. Despite enhancements in security screenings, several malicious packages remain unnoticed and pose risks to users.

The research conducted by Palo Alto Networks highlights critical vulnerabilities in the OpenClaw ecosystem, particularly through its marketplace, ClawHub. The platform allows third-party skills that possess substantial local system access, creating a significant risk vector for malware distribution. As a result, various malicious campaigns have surfaced since the platform’s inception, prompting ClawHub to implement security measures, including partnerships with VirusTotal and ClawScan for preemptive skill screening. Nevertheless, analyses between February and May 2026 unearthed five malicious skills that remained undetected for extended periods.

Five distinct malicious skills were identified under categories such as information theft, evasion techniques, and agentic threats. Infostealer skills that targeted macOS systems connected to command-and-control infrastructure, revealing ongoing threats from adversarial actors. One skill effectively bypassed detection mechanisms by inflating its file size, while others manipulated the AI’s decision-making process to facilitate financial fraud. Notably, these agentic threats exploit the AI’s interpretation capabilities, allowing unauthorized actions without traditional exploit mechanisms.

Defensive Context
Organizations with exposure to OpenClaw and its ecosystems must remain vigilant as adversaries exploit AI agent environments for intrusion and financial fraud. Enterprises utilizing AI agents, particularly in finance and productivity sectors, should prioritize validating the skills being deployed within their devices. Conversely, smaller or non-technical organizations may not need immediate concerns unless they leverage such AI-driven applications or engage with the ClawHub marketplace directly.

Why This Matters
The real-world risks from these malicious skills are substantial, particularly for financial institutions and organizations that depend on AI-driven efficiencies. Users accessing skills from sources like ClawHub may unknowingly introduce malware into their systems, leading to data breaches or financial exploitations.

Defender Considerations
While traditional security measures may not detect these sophisticated threats, monitoring for outbound communications to known threat infrastructure can help identify skills that exhibit unusual behaviors. Specific cases of malicious skills that progressed through ClawHub’s security assessments indicate that prior detection tools are not effective against these novel attack vectors.

Indicators of Compromise (IOCs)

  • IP Addresses:
    • 2.26.75[.]16
    • 91.92.242[.]30
  • SHA256 Hashes:
    • 818aea6143282b352fdfdc0f3ebf77a36e54eb3befb5cad1a355a99ab97c6aa7
    • b30eaed1f7478c28f4ec50d07ed5ef014ffbc4b2bc5a38d689ba9f7abb5e19c2
    • f4e41aa269c88bf11a2022701a9cf41e9a186aa1b224d837c31bf34e0b875d0e

This analysis underscores the necessity of strict scrutiny and validation within AI ecosystems, emphasizing that without due diligence, organizations risk compromising their security and financial integrity.

Click here for the full article

Try our Intelligence today!

Streamline your security operations with a free Q-Feeds trial and see the difference.

Other articles