VulnCheck says fewer than 2% of AI-assisted vulnerability discoveries have been weaponized, casting doubt on claims frontier models are handing attackers a major advantage

  • frongt@lemmy.zip
    link
    fedilink
    English
    arrow-up
    3
    ·
    3 days ago

    Fewer than 2% of AI-assisted vulnerability discoveries have been weaponized so far. Also, that we know of.

    Though it’s really a script kiddie thing. Any teenager can point an LLM at a codebase and start picking out vulns. Writing an exploit is a level harder. And actually using it offensively in the wild is even harder. So, it makes sense that right now we just see people reporting vulns.

  • WhoIzDisIz@lemmy.today
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 days ago

    AI-found bugs aren’t proving any easier to exploit despite the hype

    Yeah, that’s what the state-sponsored hackers want you to believe…

    /s

  • Canaconda@lemmy.ca
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 days ago

    AI discovering new zero-days isn’t the real issue though.

    AI’s ability to seamlessly implement every single known vulnerability is the problem that can attack us at scale.

    An AI trained on devices, software versions, and vulnerabilities could literally identify targets just by the hardware. It would passively identify and attack anything with out of date security software.

    It’s inevitable and we won’t know it exists until one day some crazy number of the network routers in the world all stop working more or less at the same time.

    • Rimu@piefed.socialOPM
      link
      fedilink
      English
      arrow-up
      0
      arrow-down
      1
      ·
      3 days ago

      That sounds plausible but is in direct contradiction to the contents of the article.