ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket

2026-03-04T22:33:54Z1ce8c24530df57eda2a04a3f523d9fd02594741f103ce9ab096ff81f7d4c2a2a
CVE-2025-40538CVE-2026-20127CVE-2026-25108active-exploitationai-securitybackdoorbotnetcloud-credentialsmalicious-packagesnation-statepkg-repo-malwareransomwareremote-code-executionsoftware-supply-chainsupply-chainvulnerabilityweb-shellzero-day

What happened

A broad set of high‑impact security reports: a CVSS 10.0 Cisco SD‑WAN zero‑day (CVE-2026-20127) has been exploited in the wild since 2023, CISA confirmed active exploitation of FileZen (CVE-2026-25108), and SolarWinds patched multiple critical Serv‑U RCE flaws (CVE-2025-40538). Threats also include AI/LLM-specific attacks (OpenClaw “ClawJacked” local agent hijack; multiple Claude/Claude Code flaws enabling RCE and API key exfiltration), exposed Google Cloud API keys permitting access to Gemini endpoints, widespread FreePBX web‑shell infections, malicious packages and trojanized developer repos

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
1ce8c24530df57eda2a04a3f523d9fd02594741f103ce9ab096ff81f7d4c2a2a
Enrichment time
2026-03-04T22:33:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.