WebSocket is a technology platform tracked across 15 threat clusters and 17 intelligence report mentions on ThreatCluster. First observed November 21, 2025; most recent activity July 7, 2026.
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…
A critical vulnerability (CVSS 9.7) in the Cline Kanban server allows any website a developer visits to silently exfiltrate workspace data and inject commands into the AI agent's terminal. This flaw affects version…
The FBI has issued a warning regarding the Kali365 phishing kit, which is actively stealing Microsoft OAuth tokens and bypassing multi-factor authentication (MFA) protocols. First identified in April 2026, Kali365 is…
Mirax, a newly identified Android Remote Access Trojan (RAT) and banking malware, has emerged as a significant threat, particularly in Spanish-speaking regions. It was first observed on underground forums in December…
A new malware named RoadK1ll has been identified, allowing attackers to pivot within compromised networks. Discovered by Blackpoint during an incident response, RoadK1ll is a Node.js implant that communicates via a…
OpenAI has integrated its ChatGPT subscriptions as the authentication layer for OpenClaw, an open-source AI agent framework with 3.2 million users. This move follows Anthropic's decision to block access to its Claude…
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
Agentic LLM browsers, which automate user tasks by reading and interacting with web content, have introduced significant security risks related to prompt injection and data theft. These browsers, including Perplexity…
On March 22, 2026, Peter, the founder of OpenClaw, confirmed that the OpenClaw Gateway WebSocket unauthenticated upgrade vulnerability was exclusively discovered by the 360 Security Cloud team. This vulnerability is…
The OpenClaw ecosystem, previously known as ClawdBot and Moltbot, is experiencing significant security vulnerabilities, including bot takeover and remote code execution (RCE) exploits. Security researchers, including…