Dramatic illustration of a computer screen showing OpenClaw AI security warning from Chinese cybersecurity agency, with hacker threats and vulnerability symbols.
Dramatic illustration of a computer screen showing OpenClaw AI security warning from Chinese cybersecurity agency, with hacker threats and vulnerability symbols.
AI 生成的图像

中国网络安全机构警告OpenClaw AI代理软件风险

AI 生成的图像

中国国家网络安全机构警告OpenClaw AI代理软件存在安全漏洞,可能允许攻击者完全控制用户计算机系统。该软件最近下载量激增,主要云平台提供一键部署服务,但默认安全配置薄弱。

OpenClaw是一种通过自然语言指令直接执行计算机任务的AI代理软件,也被称为Clawdbot或Moltbot。由奥地利程序员Peter Steinberger开发,该软件在GitHub上迅速流行,用户昵称其为“龙虾”。它被设计为执行实际操作,如组织桌面和处理数据,但需要高系统权限,包括访问本地文件、环境变量和外部API。

中国国家计算机网络应急技术处理协调中心(CNCERT)在其官方社交媒体上发布通知,指出OpenClaw的默认安全配置薄弱,易受攻击者利用。潜在风险包括:攻击者可在网页中嵌入隐藏恶意指令,诱骗AI代理泄露敏感信息,如系统密钥;软件可能误解用户命令,意外删除重要数据,包括电子邮件或核心运营信息;某些插件被识别为恶意,可能窃取加密密钥、安装恶意软件或将设备转为网络攻击工具。

工业和信息化部(MIIT)管理的国家漏洞数据库(NVDB)发布了针对OpenClaw用户的六项“应做”和六项“勿做”指南。该指南与AI代理提供商、漏洞平台运营商和网络安全公司合作制定,旨在应对典型使用场景中的风险。“应做”包括使用官方最新版本、最小化互联网暴露、仅授予必要权限、谨慎使用第三方技能市场、防范浏览器劫持,并定期检查补丁漏洞。“勿做”包括使用过时或第三方镜像版本、将AI代理实例暴露于互联网、部署时启用管理员账户、安装需输入密码的技能包、浏览未验证网站,以及禁用详细日志审计功能。

NVDB还提供了限制互联网访问、扫描文件和卸载软件的说明。目前,已公开披露OpenClaw的中高严重性漏洞,如果被利用,可能导致系统被攻破和敏感数据被窃取,包括个人文件、支付信息和API密钥。该软件的快速采用反映了AI从对话向行动的转变,但专家强调需通过有限权限逐步扩展访问,以平衡便利性和安全。

(约250字)

相关文章

Illustration depicting Moltbook AI social platform's explosive growth, bot communities, parody religion, and flashing security warnings on a laptop screen amid expert debate.
AI 生成的图像

Moltbook AI social network sees rapid growth amid security concerns

由 AI 报道 AI 生成的图像

Launched in late January, Moltbook has quickly become a hub for AI agents to interact autonomously, attracting 1.5 million users by early February. While bots on the platform have developed communities and even a parody religion, experts highlight significant security risks including unsecured credentials. Observers debate whether these behaviors signal true AI emergence or mere mimicry of human patterns.

OpenClaw, an open-source AI project formerly known as Moltbot and Clawdbot, has surged to over 100,000 GitHub stars in less than a week. This execution engine enables AI agents to perform actions like sending emails and managing calendars on users' behalf within chat interfaces. Its rise highlights potential to simplify crypto usability while raising security concerns.

由 AI 报道

An open-source AI assistant originally called Clawdbot has rapidly gained popularity before undergoing two quick rebrands to OpenClaw due to trademark concerns and online disruptions. Created by developer Peter Steinberger, the tool integrates into messaging apps to automate tasks and remember conversations. Despite security issues and scams, it continues to attract enthusiasts.

Criminals have distributed fake AI extensions in the Google Chrome Web Store to target more than 300,000 users. These tools aim to steal emails, personal data, and other information. The issue highlights ongoing efforts to push surveillance software through legitimate channels.

由 AI 报道

Cybersecurity experts are increasingly alarmed by how artificial intelligence is reshaping cybercrime, with tools like deepfakes, AI phishing, and dark large language models enabling even novices to execute advanced scams. These developments pose significant risks to businesses in the coming year. Published insights from TechRadar underscore the scale and sophistication of these emerging threats.

Following IBM's recent findings on AI accelerating vulnerability exploits, a TechRadar report warns that hackers are turning to accessible AI solutions for faster attacks, often trading off quality or cost. Businesses must adapt defenses to these evolving threats.

由 AI 报道

The cURL project, a key open-source networking tool, is ending its vulnerability reward program after a flood of low-quality, AI-generated reports overwhelmed its small team. Founder Daniel Stenberg cited the need to protect maintainers' mental health amid the onslaught. The decision takes effect at the end of January 2026.

 

 

 

此网站使用 cookie

我们使用 cookie 进行分析以改进我们的网站。阅读我们的 隐私政策 以获取更多信息。
拒绝