一项针对互联网基础设施的广泛扫描活动被发现正在冒充知名AI数据爬虫进行漏洞探测。[1] 根据Agent Analytics的监测数据,这些恶意扫描主要针对AI编码工具使用的凭证和配置路径,包括/.config/anthropic/credentials/default.json、/.claude/settings.json和/.aws/credentials等敏感位置。[1]
在被冒充的AI机器人中,ClaudeBot、GPTBot和CCBot是最常见的伪装身份。[1] 监测覆盖5000多个网站的流量数据显示,ClaudeBot在AI数据爬虫中的活动占比最高,达到27.0%,但其Robots.txt遵守率仅为21.7%。[1] Googlebot的冒充率最高,达到0.5%。[1]
An ongoing campaign has been discovered in which unknown attackers are impersonating artificial intelligence bots to conduct widespread vulnerability scans across thousands of websites.[1] The attackers are specifically targeting credentials and configuration file paths used by AI coding tools.[1] According to monitoring by Agent Analytics, the most frequently spoofed AI data crawlers are ClaudeBot, GPTBot, and CCBot.[1]
Among these impersonated bots, ClaudeBot shows the highest activity level, accounting for 27.0% of all AI data crawler traffic, though it has the lowest robots.txt compliance rate at 21.7%.[1] Googlebot, by comparison, is impersonated at a rate of 0.5%.[1] The scanning campaign targets credential and configuration paths including /.config/anthropic/credentials/default.json, /.claude/settings.json, and /.aws/credentials, among others.[1] The monitoring data encompasses traffic patterns across more than 5,000 websites globally.[1]