← Carolina Clear Tech

Cyber Threat Brief

2026-03-01

Listen to this brief (13:43)

Download MP3
Show Notes

Show Notes - 2026-03-01

Stories Covered

CVEs Referenced

CVE-2026-24763, CVE-2026-25157, CVE-2026-25475, CVE-2026-25593, CVE-2026-26319, CVE-2026-26322, CVE-2026-26329, CVE-2026-28417, CVE-2026-28418, CVE-2026-28421, CVE-2026-28422

Indicators of Compromise

Domains: extensionanalyticspro[.]top, drivers[.]solutions, google-update[.]icu, drivers[.]solutions.

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cyber Threat Brief - 2026-03-01

Today: OpenClaw's ClawJacked vulnerability (7 CVEs) lets any malicious website hijack a locally running AI agent via WebSocket password brute-force, with a patch available in version 2026.2.25 released February 26. SentinelOne issued a formal advisory assessing that Iranian state-aligned threat actors will intensify cyber operations against U.S., Israeli, and allied targets following recent kinetic escalation. A compromised Chrome extension (QuickLens) pushed ClickFix attacks and crypto-stealing malware to 7,000 users before removal from the Web Store.


Critical Alerts

ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket (CVE-2026-26319, CVE-2026-26322, CVE-2026-24763, CVE-2026-25593, CVE-2026-25157, CVE-2026-25475, CVE-2026-26329)

Oasis Security disclosed a high-severity flaw in OpenClaw's core gateway that allows any malicious website to connect to a developer's locally running AI agent via WebSocket, brute-force the gateway password due to missing rate limiting, and silently register as a trusted device without user confirmation. Browsers do not block cross-origin WebSocket connections to localhost, so the attack fires from any page the developer visits. EPSS scores across all seven CVEs are currently low (highest: CVE-2026-25475 at 26th percentile, CVE-2026-24763 at 24th percentile), reflecting the vulnerability's novelty, not its exploitability. A separate log poisoning flaw, addressed in version 2026.2.13 (February 14), allowed attackers to inject content into OpenClaw's log files via WebSocket, which the agent then read back as operational input, enabling indirect prompt injection and potential data disclosure.


Business & Infrastructure Threats

SentinelOne Intelligence Brief: Iranian Cyber Activity Outlook

SentinelOne issued a partner and customer advisory on February 28, 2026 assessing with high confidence that Iranian state-aligned cyber operations are likely to intensify in the near-term following recent U.S. and Israeli kinetic strikes against Iranian targets. Iran's established groups, including APT34 (OilRig), APT42 (TA453), APT39, and MuddyWater, conduct precision espionage, credential theft, and spearphishing against defense, government, critical infrastructure, financial services, and academic targets. Iran has also deployed wiper malware, fake hacktivist personas (DarkBit, Cyber Av3ngers), coordinated disinformation across Telegram and X, and criminal proxy ransomware fronts to obscure attribution. Priority targets identified in the advisory include U.S. military and government organizations, Israeli defense entities, diplomatic infrastructure, and defense contractors and their supply chains.

QuickLens Chrome Extension Steals Crypto, Shows ClickFix Attack

The QuickLens Chrome extension (7,000 users, formerly Google-featured) was transferred to a new owner on February 1, 2026, and a malicious version 5.8 was pushed February 17. The extension stripped CSP, X-Frame-Options, and X-XSS-Protection headers from all browsed pages, enabling inline JavaScript execution across every site visited. A C2 at api.extensionanalyticspro[.]top was polled every five minutes for payloads delivered via a 1x1 GIF pixel onload trick. Payloads included: a fake Google Update ClickFix prompt delivering "googleupdate.exe" (signed with a Chinese food company certificate), which spawned hidden PowerShell connecting to drivers[.]solutions/META-INF/xuoa.sys; and a second agent targeting MetaMask, Phantom, Coinbase Wallet, Trust Wallet, Solflare, Backpack, Brave Wallet, and Exodus credentials. Google has removed the extension from the Chrome Web Store.

Hackers Weaponize Claude Code in Mexican Government Cyberattack

Threat actors used Claude Code, an AI coding assistant, to write exploits, build attack tooling, and automate data exfiltration against a Mexican government target, resulting in over 150 GB of data stolen. This is a documented case of AI-assisted attack automation used at operational scale against a government network.


General Security News

Who is the Kimwolf Botmaster "Dort"?

KrebsOnSecurity published an open-source intelligence profile on "Dort," operator of the Kimwolf botnet, identified as Jacob Butler of Ottawa, Canada (DOB August 2003). Butler began as a Minecraft cheater (Dortware), escalated to selling disposable email services and CAPTCHA bypass tools, and was active in LAPSUS$ channels in 2022. Butler and a partner ("Qoft") stole over $250,000 in Xbox Game Pass accounts via automated card fraud. Since a researcher disclosed the Kimwolf vulnerability, Dort has coordinated DDoS, doxing, email flooding, and a SWAT attack against the researcher and against Krebs. This is a named threat actor profile, not a direct SMB action item, but relevant for situational awareness on botnet operations and retaliation patterns against security researchers.

OpenClaw, but in Containers: Meet NanoClaw

In response to OpenClaw's growing security incident history, software engineer Gavriel Cohen built NanoClaw, a container-isolated AI agent platform with approximately 4,000 lines of code. Each agent runs in a dedicated container with access scoped strictly to the integration it requires, preventing one compromised agent from reaching all connected services. The codebase is small enough for a single reviewer to audit fully, a notable contrast to OpenClaw's 400,000 lines. Andrej Karpathy highlighted the project publicly. For teams evaluating AI agent deployment, NanoClaw's container isolation model is a relevant reference architecture against the blast-radius risks demonstrated by the ClawJacked disclosure.

Canadian Tire Data Breach Impacts 38 Million Accounts

Names, addresses, email addresses, phone numbers, and encrypted passwords for 38 million Canadian Tire accounts were compromised in a breach. No additional technical details are available in current reporting.

$4.8M in Crypto Stolen After Korean Tax Agency Exposes Wallet Seed

South Korea's National Tax Service published a press release about a tax enforcement operation that included unredacted photos of a handwritten 24-word Ledger seed phrase for a seized cold wallet holding 8.1 billion won (~$5.6M). Within hours, an attacker deposited ETH for gas fees and transferred 4 million PRTG tokens ($4.8M) out in three transactions. The press release has been removed. This incident illustrates how physical key material in photos or documents creates immediate and total compromise of any associated wallet. The same concept applies to any secret photographed or published, including server passwords, API keys, and recovery codes.


Patch Priority


Vulnerability Disclosures

Vim: OS Command Injection and Memory Corruption (CVE-2026-28417, CVE-2026-28418, CVE-2026-28421, CVE-2026-28422)

MSRC published four Vim vulnerabilities on March 1, 2026. CVE-2026-28417 is an OS command injection in Vim's netrw plugin (EPSS 23rd percentile, 0.001 score), the most actionable of the four as command injection via file handling is a known vector for attack when users open untrusted content. CVE-2026-28418 is a heap-based buffer overflow in Emacs tags parsing (EPSS 0). CVE-2026-28421 covers a heap-buffer overflow and segmentation fault (EPSS 0). CVE-2026-28422 is a stack-buffer overflow in build_stl_str_hl() (EPSS 0). All four carry minimal exploitation probability at this time, but the netrw command injection is worth prioritizing for any environment where Vim is used on shared or multi-user systems.


Trends & Context

AI agent platforms are emerging as a high-value attack surface with a compressed timeline: OpenClaw accumulated a log poisoning flaw, the ClawJacked WebSocket takeover, and documented public internet exposure incidents all within weeks, while separate reporting shows threat actors actively using AI coding tools to accelerate attack operations. Browser extension supply chain attacks continue following a consistent playbook: acquire an established extension with an existing user base, change ownership silently, push a malicious update that strips security headers, and deliver ClickFix for initial access. Iranian state-aligned groups present a credible escalation threat during the current geopolitical period, with historical precedent for pairing cyber operations with kinetic events, using wiper malware, and deploying hacktivist fronts for deniability. Organizations supporting U.S. and Israeli government or defense clients should treat the next several weeks as a heightened risk window.