ClawJacked attack let malicious websites hijack OpenClaw to steal data

2026-03-04T20:06:20Z70f34e7c68fa307e20f6294c96cdf39f4188cbf3b61bc1aa8d4ac59cceb10d12
CVE-2025-0282APT37Apex-OneCISAClawJackedClickFixIvantiJuniper-PTXManoManoOpenClawQuickLensRESURGESamsungTrend-Microair-gappedchrome-extensioncritical-flawcrypto-theftdata-breachexploitmnemonic-seed-exposureprivacy-breach','google-api-keys'rcesmart-tvvulnerability

What happened

BleepingComputer roundup of multiple high-impact security stories: a high-severity “ClawJacked” flaw in the OpenClaw AI agent that let malicious websites hijack local instances; a maliciously altered QuickLens Chrome extension used to push malware and steal crypto (ClickFix-style attack); a South Korean tax agency leaking a wallet mnemonic leading to a $4.8M crypto theft; CISA reporting RESURGE implants persisting on Ivanti Connect Secure devices (linked to CVE-2025-0282); Trend Micro patching critical Apex One RCE flaws; a critical Juniper PTX Junos OS Evolved vulnerability allowing full root

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
70f34e7c68fa307e20f6294c96cdf39f4188cbf3b61bc1aa8d4ac59cceb10d12
Enrichment time
2026-03-04T20:06:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.