ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket

2026-03-04T22:41:04Zc2cbfb72b746b0052d9906971871be3b76dc1e2d78a8bee7730e101f5191110b
CVE-2025-40538CVE-2026-20127CVE-2026-25108C2active-exploitationai-securitybackdoorbotnetcloud-credentialscredential-exposuredevsecopsmalicious-packagesransomwaresupply-chaintelecomvulnerability-managementwebshellszero-day

What happened

A large cluster of high-impact security incidents and vulnerabilities was reported across AI, cloud, networking, and software supply-chain ecosystems. Notable items include a maximum-severity Cisco SD‑WAN zero-day (CVE-2026-20127) actively exploited in the wild, and CISA-confirmed active exploitation of FileZen (CVE-2026-25108). Multiple critical product fixes were released (e.g., SolarWinds Serv-U CVE-2025-40538), while widespread supply-chain and repository abuse was observed — malicious NuGet/npm/Go modules, a trojanized StripeApi package, and developer-targeting fake Next.js repos. AI/ML‑s

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
c2cbfb72b746b0052d9906971871be3b76dc1e2d78a8bee7730e101f5191110b
Enrichment time
2026-03-04T22:41:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.