ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocketThe Hacker News·Mar 2, 06:01 UTC · Mar 2, 2026VulnerabilityCVE-2026-25593CVE-2026-24763CVE-2026-25157+4 CVEs47
OpenClaw gives users yet another reason to be freaked out about securityArs Technica · Security·Apr 3, 20:30 UTC · Apr 3, 2026VulnerabilityCVE-2026-3357947
Researchers Find 40,000+ Exposed OpenClaw InstancesInfosecurity Magazine·Feb 9, 09:30 UTC · Feb 9, 2026Vulnerability42
OpenClaw Bug Enables One-Click Remote Code Execution via Malicious LinkThe Hacker News·Feb 3, 05:27 UTC · Feb 3, 2026VulnerabilityCVE-2026-2525347
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw FlawsThe Hacker News·Jul 10, 14:19 UTC · Jul 10, 2026Vulnerability42
Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and PersistenceThe Hacker News·May 15, 00:00 UTC · May 15, 2026VulnerabilityCVE-2026-44112CVE-2026-44113CVE-2026-44115+1 CVEs47
ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing SurfaceThe Hacker News·May 29, 18:07 UTC · May 29, 2026VulnerabilityCVE-2026-25592CVE-2026-2603047
ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New StoriesThe Hacker News·Jun 12, 05:36 UTC · Jun 12, 2026Vulnerability142
Docker CVE-2026-34040 Lets Attackers Bypass Authorization and Gain Host AccessThe Hacker News·Apr 7, 15:15 UTC · Apr 7, 2026VulnerabilityCVE-2026-34040CVE-2024-4111047