來源較早收集於 0m

OpenClaw 達50萬實例,無企業殺手開關

OpenClaw 達50萬實例,無企業殺手開關
PostLinkedIn
💼閱讀原文: VentureBeat
#ai-agents#security-exposure#rce-vuln#malicious-skillsopenclawopenclawcato-networksbreachforumsclawhub

💡50萬 OpenClaw 實例暴露,無殺手開關—立即檢查你的是否易受攻擊。(38字)

⚡ 30 秒速覽

有什麼變化

3月24日偵測到50萬個網際網路面向實例

為什麼重要

企業面臨無集中控制的 OpenClaw 流氓實例資料外洩風險。供應商須優先開發殺手開關,以因應快速採用。AI 自主性放大超出人類權限的威脅。

下一步行動

使用 Censys 掃描網路中的 OpenClaw 實例,並立即部署網路分段。

誰應關注:Enterprise & Security Teams

關鍵要點

  • 3月24日偵測到50萬個網際網路面向實例
  • CEO 實例在 BreachForums 售出,含即時 AI 存取與敏感資料
  • 無原生殺手開關;資料以純文字 Markdown 檔案儲存
  • 30,000+ 暴露實例有風險;15,200 個可經 RCE 利用
  • ClawHub 市場發現 341 個惡意技能

🧠 深度解析

本篇為 AI 生成分析,非原文內容。

🔑 增強重點摘要

  • The UK National Cyber Security Centre (NCSC) issued an emergency advisory on March 27, 2026, specifically warning organizations to isolate OpenClaw instances from public-facing networks due to the lack of authentication protocols.
  • Forensic analysis of the BreachForums incident indicates the threat actor utilized a zero-day vulnerability in the OpenClaw 'Local-Sync' plugin, which bypasses the default file-system permission checks.
  • OpenClaw's developer community has initiated a fork of the project, dubbed 'SecureClaw,' aiming to implement mandatory OAuth2 integration and encrypted storage, following the original maintainers' refusal to issue a centralized patch.
📊 競品分析▸ Show
FeatureOpenClawEnterprise-Grade AI (e.g., MS Copilot)Local-LLM (e.g., Ollama/LM Studio)
DeploymentPublic-facing by defaultManaged/Private CloudLocal/Air-gapped
AuthenticationNone (Plain-text)SSO/MFA/RBACUser-defined
Kill SwitchAbsentNative/CentralizedManual Process
MarketplaceUnverified (ClawHub)Curated/EnterpriseCommunity-driven

🛠️ 技術深入

  • Architecture: OpenClaw utilizes a lightweight Node.js backend that serves a local REST API on port 8080 by default, with no internal firewall or request validation.
  • Data Storage: Conversations and API keys are stored in unencrypted .md files within the ~/.openclaw/data directory, accessible to any process with user-level permissions.
  • RCE Vector: The Remote Code Execution vulnerability stems from the 'Plugin-Loader' module, which executes arbitrary JavaScript files placed in the /plugins directory without signature verification.
  • Network Exposure: Instances are discoverable via Shodan/Censys due to a hardcoded 'OpenClaw-Instance' header in the HTTP response, which broadcasts the version number and active plugin list.

🔮 前景展望基於引用來源的 AI 分析

Regulatory bodies will mandate security audits for open-source AI agents.
The scale of the OpenClaw breach has triggered legislative discussions in the EU and UK regarding the liability of developers for insecure default configurations in AI software.
OpenClaw will face a mass migration to the 'SecureClaw' fork.
Enterprise users are actively abandoning the original repository in favor of the community-led fork that prioritizes authentication and encrypted storage.

時間線

2025-09
OpenClaw project launched on GitHub as an open-source productivity assistant.
2026-01
ClawHub marketplace introduced, allowing third-party developers to upload custom AI skills.
2026-03
Security researchers identify the RCE vulnerability in the Plugin-Loader module.
2026-03
BreachForums incident involving the compromised UK CEO instance reported.
📰

AI 週報

閱讀本週精選 AI 大事摘要 →

👉相關動態

AI 策展新聞聚合。所有內容版權歸原始發布者所有。
原始來源: VentureBeat

這是摘要,不是原文。去看原站,或訂閱每週簡報。

每週電子報

每週一封,可隨時退訂。