Sicurezza AI · Attacco ad app web
OpenClaw presentava una falla ‘ClawJacked’ che consentiva a siti web maligni di aprire WebSocket al gateway locale e brute-force la password di gestione.
5 fonti · 6 mar
BleepingComputer
Bing AI promoted fake OpenClaw GitHub repo pushing info-stealing malware
Fake OpenClaw installers hosted in GitHub repositories and promoted by Microsoft Bing's AI-enhanced search feature instructed users to run commands that deployed information stealers and proxy malware.
originaleDark Reading
Critical OpenClaw Vulnerability Exposes AI Agent Risks
The now-patched flaw is the latest in a growing string of security issues with the viral AI tool, which has seen rapid adoption among developers.
originaleSecurityWeek
OpenClaw Vulnerability Allowed Websites to Hijack AI Agents
Malicious websites could open a WebSocket connection to localhost on the OpenClaw gateway port, brute force passwords, and take control of the agent.
originalePart of the PlainSec briefing for 2026-03-02
Every edition of this story: Vulnerabilità OpenClaw permette a siti web dirottare agenti AI locali