ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket
2026-03-04T22:32:35Z•00be87dd07ec57be6313f720892a4ec9105bf45a8b9fd9c29a9fd87289b728bb
CVE-2025-40538CVE-2026-20127CVE-2026-25108AI-securityDoHblockchain-C2botnetcloudcredential-theftexploitationincident-responsemalicious-packagesmalwareransomwareremote-accesssupply-chainvulnerabilityzero-day
What happened
This collection of The Hacker News items (late Feb 2026) describes multiple high-impact security incidents: a high-severity 'ClawJacked' flaw in OpenClaw allowing local AI agents to be hijacked via WebSocket; widespread exposure of Google Cloud API keys enabling unauthorized access to Gemini endpoints; active exploitation of a maximum-severity Cisco SD‑WAN zero-day (CVE-2026-20127); and CISA-confirmed exploitation of FileZen (CVE-2026-25108). Other notable items include malicious supply‑chain/package attacks (trojanized Go module delivering Rekoobe, malicious NuGet/npm packages and a StripeApi
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 00be87dd07ec57be6313f720892a4ec9105bf45a8b9fd9c29a9fd87289b728bb
- Enrichment time
- 2026-03-04T22:32:35Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.