NewsClawJacked OpenClaw WebSocket Hijack 7 CVEs PatchedThe Hacker News·high signalXBlueskyLinkedInCopy linkCritical vulnerability allows malicious websites to hijack locally running OpenClaw agents via localhost WebSocket brute-force. 7 additional CVEs found. Patched in v2026.2.26+.SourceSource pageThe Hacker News↳ Follow the threadThreat pattern / ContrastDeepSeek Harness CVE-2026-82533 (CVSS 9.4): a sandboxed agent could flip its own session to 'danger-full-access' through the unauthenticated local UIThe Hacker NewsStack layer / Threat patternGreyNoise Traced One Attacker Running OpenAI's Codex Harness With a DeepSeek Model Through 395 Organizations in 48 CountriesHelp Net SecurityStack layer / Threat patternn8n ships 16 advisories in one day, including two expression-sandbox escapes that reach code executionGitHub Security AdvisoriesPolicy dependency / Threat patternFrontMCP's OpenAPI SSRF fix is bypassed in the latest release via DNS resolution and IPv4-mapped IPv6GitHub Security AdvisoriesStack layer / Threat patternGemini CLI now demands confirmation before running a build command after a build file changedGitHubStack layer / Threat patternTip: a plugin eval suite that grants Bash needs bubblewrap and socat on Linux, or WSL2 on WindowsClaude Code DocsStack layer / Threat patternClaude Code 2.1.269 fixes plugin archives being extracted world-readable on shared machinesClaude Code ChangelogPolicy dependency / Stack layerHolding Back Ready Agent Turns Instead of Releasing Them Eagerly Cuts P95 Workflow Latency up to 3.50xarXiv 2609.10964