ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket
2026-03-04T22:41:04Z•c2cbfb72b746b0052d9906971871be3b76dc1e2d78a8bee7730e101f5191110b
CVE-2025-40538CVE-2026-20127CVE-2026-25108C2active-exploitationai-securitybackdoorbotnetcloud-credentialscredential-exposuredevsecopsmalicious-packagesransomwaresupply-chaintelecomvulnerability-managementwebshellszero-day
What happened
A large cluster of high-impact security incidents and vulnerabilities was reported across AI, cloud, networking, and software supply-chain ecosystems. Notable items include a maximum-severity Cisco SD‑WAN zero-day (CVE-2026-20127) actively exploited in the wild, and CISA-confirmed active exploitation of FileZen (CVE-2026-25108). Multiple critical product fixes were released (e.g., SolarWinds Serv-U CVE-2025-40538), while widespread supply-chain and repository abuse was observed — malicious NuGet/npm/Go modules, a trojanized StripeApi package, and developer-targeting fake Next.js repos. AI/ML‑s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- c2cbfb72b746b0052d9906971871be3b76dc1e2d78a8bee7730e101f5191110b
- Enrichment time
- 2026-03-04T22:41:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.