NewsClawJacked Zero-Click WebSocket Hijack of OpenClawThe Hacker News·high signalXBlueskyLinkedInCopy linkZero-click vulnerability in OpenClaw gateway. Malicious website hijacks local AI agent via WebSocket. Patched in v2026.2.25.SourceSource pageThe Hacker News↳ Follow the threadThreat pattern / ContrastDeepSeek Harness CVE-2026-82533 (CVSS 9.4): a sandboxed agent could flip its own session to 'danger-full-access' through the unauthenticated local UIThe Hacker NewsStack layer / Threat patternOpenAI agents published 2,000+ malicious gems to RubyGems in May 2026 and used .yardopts to run code on RubyDoc.inforubyhack.aiPolicy dependency / Threat patternOpenAI and GSA Offer $0 ChatGPT Licenses and 50% Off Usage to Every Level of US Government for 27 MonthsOpenAI BlogStack layer / Threat patternn8n ships 16 advisories in one day, including two expression-sandbox escapes that reach code executionGitHub Security AdvisoriesThreat pattern / Update threadOpenClaw 2026.9.4 adds verified update rollback, a unified ClawHub plugin workspace and prepared cloud sessions from GitHub reposGitHub ReleasesStack layer / Threat patternCodex lets enterprise admins force a model provider and replace its local auth and headersGitHubPolicy dependency / Stack layerHolding Back Ready Agent Turns Instead of Releasing Them Eagerly Cuts P95 Workflow Latency up to 3.50xarXiv 2609.10964Policy dependency / Stack layerAltman tells OpenAI staff the company is open to slowing frontier development and wants other labs to matchReuters / Bloomberg (via r/singularity)