Vulnerability Allowed Hijacking Chrome’s Gemini Live AI Assistant

2026-03-04T21:52:37Z79e81e1ec7968ecdefc381357249472113c86aa210b525b472bacc3918f68ec2
ai-agent-hijackai-assisted-exploitationair-gappedbackdoorbrowser-extensionbrute-forcecanadian-tirechromeclaudedata-breachdata-exfiltrationgemini-livelnklocal-websocketmadison-square-gardennorth-korea-aptopenclaworacle-ebsus-israel-iran-cyberwiper-malware

What happened

This SecurityWeek roundup covers multiple high-impact security stories: a Chrome vulnerability allowed malicious extensions to hijack Gemini Live (spy on users and steal files); an OpenClaw flaw let websites open a localhost WebSocket to the gateway port, brute-force credentials, and seize AI agents; and Madison Square Garden confirmed a data breach tied to the 2025 Oracle E-Business Suite campaign. Other notable items: a North Korean APT targeted air-gapped systems using LNK files and new implants/backdoors; attackers weaponized Anthropic’s Claude to write exploits and automate exfiltration (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
79e81e1ec7968ecdefc381357249472113c86aa210b525b472bacc3918f68ec2
Enrichment time
2026-03-04T21:52:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.