当前位置:首页 >英文主页 >中英对照 > 中译版报告详情

KELA:2026 OpenClaw or OpenFlaw:OpenClaw 生态威胁评估报告(中译版)(29页).pdf

上传人: 小*** 编号:1267009 2026-06-12 29页 2.48MB

下载:

1、 OpenClaw or OpenFlaw:Threat Assessment of the OpenClaw Ecosystem February 11,2026 Table of contents Executive Summary.3 The Genesis of Agentic Risk:Evolution,Identity,and the Vibe Coding Crisis.5 The Clawdbot Era:Functionality Over Security.5 The Moltbot Transition and the Security Vacuum.5 The Eme

2、rgence of OpenClaw and Vibe Coding.6 Critical Design Flaws:The Lethal Trifecta.8 The Local-First Runtime Risks.8 The Lethal Trifecta Realized.8 Persistent Memory and Time-Shifted Attacks.9 The OpenClaw Paradox.9 The Shadow AI Enterprise Infiltration.10 Vulnerabilities and Exploitation Analysis.11 Th

3、e WebSocket Hijack(One-Click RCE)-CVE-2026-25253.11 Remote Command Injection in Docker Container-CVE-2026-24763.11 The Exposed Instance Epidemic.12 The Supply Chain Vector:ClawHub and ClawHavoc.13 The Anatomy of a Malicious Skill.13 Case Study:The ClawHavoc Campaign.13 The VirusTotal Integration Par

4、adox.14 The Moltbook Deception:A Simulated Civilization.15 Security Failure leads to Massive Data Leakage.15 The Yellow Pages for Threat Actors.16 The Church of Molt.16 Encrypted Channels and Covert Ops.16 Economic and Physical Threats:MoltRoad and Rentahuman.ai.17 MoltRoad:The Decentralized Darknet

5、.17 Rentahuman.ai:The Reverse Gig Economy Risks.18 The Broader OpenClaw Ecosystem.19 MoltBunker:The Persistence Layer.19 ClawCity and ClawLove.19 Underground Chatter Related to OpenClaw within KELAs Cybercrime Sources.20 Vulnerabilities Exploitation.20 Scanning for OpenClaw.22 OpenClaw and its Ecosy

6、stem as a Supply Chain Threat.24 Conclusion.25 Enterprise Impact&Remediation Strategy.26 OpenClaw or OpenFlaw:Threat Assessment of the OpenClaw Ecosystem-2026|2 Executive Summary The rapid emergence of the OpenClaw ecosystem-encompassing the core OpenClaw agent(formerly ClawdBot and MoltBot),the Cla

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
1. **OpenClaw生态风险**:OpenClaw是本地化AI代理系统,因系统级权限和架构缺陷(如CVE-2026-25253 WebSocket劫持、CVE-2026-24763命令注入)成为高危安全威胁,29,000个暴露实例遭攻击者扫描利用。 2. **供应链攻击**:ClawHub技能市场超10%含恶意代码(如ClawHavoc campaign),通过“Markdown即代码”绕过传统安全扫描,窃取API密钥或植入RAT。 3. **数据泄露与滥用**:Moltbook平台因配置漏洞泄露150万API令牌,成为威胁目标“黄页”;MoltRoad暗网市场交易武器化技能,理论“勒索软件5.0”实际多为诈骗。 4. **企业渗透**:22%企业环境存在未授权OpenClaw实例,Mac Mini等设备成跳板,结合“影子AI”和持久化攻击(如MoltBunker)威胁核心系统。
OpenClaw是什么? 如何防范OpenClaw? OpenClaw风险何在?
客服
商务合作
小程序
服务号
折叠