ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket

2026-03-04T22:34:44Z2cebeb21227abb349ed068babebbc91755ef895a3a3fae9d6eb4de1f82fde106
CVE-2025-40538CVE-2026-20127CVE-2026-25108active-exploitationai-agentsapi-keysbackdoorblockchain-c2botnetdeveloper-targetinggeminigithub-codespacesgoogle-cloudmalicious-go-modulemalicious-npm/nugetransomwarerekoobescarcruftsupply-chain-riskusb-malwarewebsocket-hijackzero-dayzoho-workdrive

What happened

A wide-ranging set of high-risk security incidents and disclosures was reported: a WebSocket hijack vulnerability in OpenClaw ("ClawJacked") that could let malicious sites commandeer local AI agents; research revealing ~3,000 exposed Google Cloud API keys (AIza) that can be abused to access sensitive Gemini endpoints; active exploitation of a critical Cisco SD‑WAN zero-day (CVE-2026-20127, CVSS 10.0) enabling unauthenticated admin access; CISA-confirmed active exploitation of FileZen (CVE-2026-25108) command-injection; SolarWinds Serv-U fixes for multiple critical RCE flaws (including CVE-2025

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
2cebeb21227abb349ed068babebbc91755ef895a3a3fae9d6eb4de1f82fde106
Enrichment time
2026-03-04T22:34:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.