A Real WebSocket Hijack Hit an AI Agent Framework. Here's What We Learned About Defense-in-Depth.
A critical WebSocket brute-force vulnerability was disclosed in OpenClaw, one of the leading open-source AI agent frameworks. The fix was straightforward — but the incident exposed a deeper problem: most AI agent deployments have zero defense-in-depth.