How attackers exploit OpenClaw's WebSocket interface to hijack local AI agents and execute arbitrary commands

Weekly insights on threats, vulnerabilities, and security best practices.

Attackers leveraged Claude AI to automate exploit development and data exfiltration in sophisticated government breach. Analysis reveals new attack vectors for AI-assisted cyber operations.

ClawJacked vulnerability enables malicious websites to hijack local OpenClaw AI agents via WebSocket connections, allowing complete takeover of AI operations and data exfiltration.

Truffle Security discovered nearly 3,000 exposed Google Cloud API keys with Gemini access embedded in client-side code, enabling unauthorized AI endpoint access and data theft.