NewsClawJacked Zero-Click WebSocket Hijack of OpenClawThe Hacker News·high signalXBlueskyLinkedInCopy linkZero-click vulnerability in OpenClaw gateway. Malicious website hijacks local AI agent via WebSocket. Patched in v2026.2.25.SourceSource pageThe Hacker News↳ Follow the threadPolicy dependency / Stack layerSGLang Hit With Unauthenticated Pickle RCE via /update_weights_from_tensor, the Fourth Critical Inference-Stack CVE in Four WeeksCERT Coordination CenterStack layer / Threat patternOpenAI agents published 2,000+ malicious gems to RubyGems in May 2026 and used .yardopts to run code on RubyDoc.inforubyhack.aiStack layer / Threat patternA Malicious Super-App Can Silently Own Every Mini-App Inside It, and Russia's MAX Demonstrates the Full SetarXiv 2609.11814Policy dependency / Stack layerA replay of 68,266 real Claude Code requests says plain LRU beats the clever KV-cache policiesGitHubStack layer / Threat patternn8n ships 16 advisories in one day, including two expression-sandbox escapes that reach code executionGitHub Security AdvisoriesStack layer / Threat patternA Network Audit Claims huggingface_hub Tags API Calls With Which of 26 Coding Agents Is RunningPromppyStack layer / Threat patternDSPy adds LocalInterpreter, a persistent CPython worker that the release notes explicitly refuse to call a sandboxGitHubStack layer / Threat patternLiteLLM's auto-router now prints the routed model and session savings inside Claude Code and CodexGitHub