Enterprise Security Weekly (Audio) Clickfixed, Zero Trust World, and OpenClaw is out of control - but that's the point - Rob Allen - ESW #445
12 snips
Feb 9, 2026 Rob Allen, Chief Product Officer at ThreatLocker, explains clickfix attacks, why they fool employees, and practical defenses. He previews ThreatLocker’s Zero Trust World conference with hands-on labs and speakers. The panel also digs into OpenClaw’s agent risks, prompt‑injection concerns, and the need for transparency in AI security tools.
AI Snips
Chapters
Transcript
Episode notes
Apply Default-Deny And Restrict Remote Tools
- Enforce default-deny for executables and restrict which apps can access the Internet by role.
- Audit and deny unnecessary remote-access tools like AnyDesk or TeamViewer to remove hidden footholds.
RMM Abuse Stopped In A Hospital Case
- Rob described an attack on a hospital where attackers tried enabling RMM tools to gain control across 6,000 machines.
- ThreatLocker blocked the RMM execution, preventing further compromise despite the attempted escalation.
Inventory Running Software, Not Just Installs
- Inventory running software, not just installed packages; scan for portable executables and one-off remote tools.
- Use visibility and a blocking mechanism to remove forgotten or unauthorized remote clients.

