13/04/2026
100,000 stars in a few weeks. Sounds like a great tool. Until you realise can browse your site, call your APIs, read emails — and when hijacked, do all of that for an attacker instead. This is the grey-zone bot problem most security teams haven't caught up with yet. Not a botnet. Not malware. Just a legitimate AI agent that sits right on the edge — and your WAF has no idea how to handle it. We broke down what's actually happening and why 2026 is the year this becomes everyone's problem.
OpenClaw 在 GitHub 幾週內突破 10 萬顆星。 聽起來是個很強的工具——直到你知道它能瀏覽你的網站、 呼叫 API、讀取郵件,而一旦被劫持,攻擊者可以用它做 完全相同的事。 這就是「灰色地帶機器人」。 不是惡意程式、不是傳統機器人網路, 卻是 WAF、IP 黑名單和 CAPTCHA 都擋不住的威脅。 大多數資安團隊還沒意識到這個問題的存在。 我們寫了一篇文章,拆解這個 2026 年最值得關注的新型攻擊面。
In early 2026, OpenClaw (previously known as Clawdbot and Moltbot) exploded across GitHub, quickly amassing over 100,000 stars. What started as an open-source personal AI assistant—capable of browsing the web, executing commands, calling APIs, reading emails, and integrating with messaging apps—...