NewsClawJacked OpenClaw WebSocket Hijack 7 CVEs PatchedThe Hacker News·high signalXBlueskyLinkedInCopy linkCritical vulnerability allows malicious websites to hijack locally running OpenClaw agents via localhost WebSocket brute-force. 7 additional CVEs found. Patched in v2026.2.26+.SourceSource pageThe Hacker News↳ Follow the threadPolicy dependency / Stack layerSGLang Hit With Unauthenticated Pickle RCE via /update_weights_from_tensor, the Fourth Critical Inference-Stack CVE in Four WeeksCERT Coordination CenterStack layer / Threat patternGreyNoise Traced One Attacker Running OpenAI's Codex Harness With a DeepSeek Model Through 395 Organizations in 48 CountriesHelp Net SecurityStack layer / Threat patternA Malicious Super-App Can Silently Own Every Mini-App Inside It, and Russia's MAX Demonstrates the Full SetarXiv 2609.11814Policy dependency / Stack layerA replay of 68,266 real Claude Code requests says plain LRU beats the clever KV-cache policiesGitHubStack layer / Threat patternn8n ships 16 advisories in one day, including two expression-sandbox escapes that reach code executionGitHub Security AdvisoriesPolicy dependency / Threat patternFrontMCP's OpenAPI SSRF fix is bypassed in the latest release via DNS resolution and IPv4-mapped IPv6GitHub Security AdvisoriesStack layer / Threat patternA Network Audit Claims huggingface_hub Tags API Calls With Which of 26 Coding Agents Is RunningPromppyStack layer / Threat patternGemini CLI now demands confirmation before running a build command after a build file changedGitHub