预警:OpenClaw Gateway现高危漏洞,请立即升级至2026.2.25或更高版本

PANews 3月2日消息,GoPlus中文社区发布预警,OpenClaw Gateway现高危漏洞,请立即升级至2026.2.25或更高版本,审计并撤销授予Agent实例的不必要凭证、API密钥和节点权限。其分析称,OpenClaw通过绑定到本地主机的WebSocket Gateway运行,该Gateway作为Agent的核心协调层,是OpenClaw的重要组成部分。此次攻击针对的就是Gateway层的弱点,只需满足一个条件:用户在浏览器中访问被黑客控制的恶意网站。 完整攻击链如下:

1.受害者在其浏览器中访问攻击者控制的恶意网站; 2.页面中的JavaScript向本地主机上的OpenClaw网关发起WebSocket连接; 3.之后,攻击脚本以每秒数百次尝试暴力破解网关密码; 4.破解成功后,攻击脚本静默注册为受信任设备; 5.攻击者获得Agent的管理员级控制权;

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Articoli correlati

日本首相高市早苗澄清与同名 Meme 币无关,代币应声跌超 85%

日本首相高市早苗澄清称,自己对名为SANAE TOKEN的加密货币毫不知情,未对此项目给予任何批准,旨在消除公众误解。该代币由企业家Mizoguchi Yūji发行,曾短暂暴涨后因声明迅速下跌。

GateNews1h fa

Ex-LAPD Officer Found Guilty of $350K ‘Wrench Attack’ Bitcoin Robbery

In brief A former LAPD officer has been found guilty of kidnapping and robbery after a home invasion in which he held a teenage crypto owner at gunpoint. Eric Halem and his alleged associates stole a hard drive containing $350.000 worth of Bitcoin from the victim. The crime is the

Decrypt7h fa

私募投資 SpaceX、OpenAI 要注意什麼?拆解 Pre-IPO 的私募風險

代幣化 Pre-IPO 在幣圈受熱捧,但投資者需警惕潛在風險,因為所購買的可能只是承諾而非實際股份。SPV 是常見的合規工具,須遵循監管要求,特別是在法律與投資者資格方面。Phyrex 指出,一些產品或僅是衍生品敞口,投資人需謹慎,避免陷入非法募資的風險。

ChainNewsAbmedia11h fa

韩国出现加密货币资助的复仇攻击,嫌犯收取 300-600 美元报酬

韩国警方正在调查一系列由加密货币资助的复仇攻击案件,嫌犯通过Telegram接受雇主支付进行破坏和诽谤。警方怀疑一个自称私人复仇组织的团体在活动,这一现象在俄罗斯也有出现。

GateNews12h fa

Lido:ZKsync wstETH桥接端点合约存在潜在漏洞

Lido官方透露,ZKsync wstETH桥接合约存在潜在漏洞,但尚未被利用,持有者不受影响。Lido已暂停对该合约的新资金存入,计划在下次治理投票后修复并恢复功能。

GateNews14h fa

sDOLA LlamaLend 遭闪电贷价格操纵攻击,损失约 24 万美元

ChainCatcher 消息指 sDOLA LlamaLend 遭遇闪电贷价格操纵攻击,损失约 24 万美元。攻击者通过调整 sDOLA 价格,导致多个账户健康因子低于 0,触发清算条件,实现获利。

GateNews15h fa
Commento
0/400
Nessun commento
Trading di criptovalute ovunque e in qualsiasi momento
qrCode
Scansiona per scaricare Gate app
Notizie
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)