Sicurezza AI · Attacco ad app web
OpenClaw ha corretto la falla 'ClawJacked' che permetteva a siti web malevoli di connettersi al gateway locale via WebSocket e prendere il controllo degli agent AI.
5 fonti · 6 mar
BleepingComputer
Bing AI promoted fake OpenClaw GitHub repo pushing info-stealing malware
Fake OpenClaw installers hosted in GitHub repositories and promoted by Microsoft Bing's AI-enhanced search feature instructed users to run commands that deployed information stealers and proxy malware.
originaleDark Reading
Critical OpenClaw Vulnerability Exposes AI Agent Risks
The now-patched flaw is the latest in a growing string of security issues with the viral AI tool, which has seen rapid adoption among developers.
originaleSecurityWeek
OpenClaw Vulnerability Allowed Websites to Hijack AI Agents
Malicious websites could open a WebSocket connection to localhost on the OpenClaw gateway port, brute force passwords, and take control of the agent.
originalePart of the PlainSec briefing for 2026-03-01
Every edition of this story: Falla OpenClaw consente a siti web di dirottare agent AI locali