ClawJacked attack let malicious websites hijack OpenClaw to steal data
2026-03-04T20:06:20Z•70f34e7c68fa307e20f6294c96cdf39f4188cbf3b61bc1aa8d4ac59cceb10d12
CVE-2025-0282APT37Apex-OneCISAClawJackedClickFixIvantiJuniper-PTXManoManoOpenClawQuickLensRESURGESamsungTrend-Microair-gappedchrome-extensioncritical-flawcrypto-theftdata-breachexploitmnemonic-seed-exposureprivacy-breach','google-api-keys'rcesmart-tvvulnerability
What happened
BleepingComputer roundup of multiple high-impact security stories: a high-severity “ClawJacked” flaw in the OpenClaw AI agent that let malicious websites hijack local instances; a maliciously altered QuickLens Chrome extension used to push malware and steal crypto (ClickFix-style attack); a South Korean tax agency leaking a wallet mnemonic leading to a $4.8M crypto theft; CISA reporting RESURGE implants persisting on Ivanti Connect Secure devices (linked to CVE-2025-0282); Trend Micro patching critical Apex One RCE flaws; a critical Juniper PTX Junos OS Evolved vulnerability allowing full root
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 70f34e7c68fa307e20f6294c96cdf39f4188cbf3b61bc1aa8d4ac59cceb10d12
- Enrichment time
- 2026-03-04T20:06:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.