行业多源确认

OpenAI 的 Greg Brockman 谈 AI 挖漏洞:防御方的窗口期

精选理由

Armadin 今年在外网黑盒扫描就挖出 90 多个零日漏洞,Brockman 说防御方得趁窗口期先加固,聊得很实在。

a16z 发布了两段访谈。OpenAI 联合创始人 Greg Brockman 认为,能发现安全漏洞的 AI 同样会被威胁行为者利用,防御方需要在技术普及前完成加固。安全公司 Armadin 的 Kevin Mandia 透露,自 2025 年 1 月以来,该公司已在客户生产环境中发现超过 90 个零日漏洞,且全程以黑盒方式从外部扫描,不依赖源代码。Brockman 主张防御方利用当前对前沿能力的差异化访问窗口,让自身防护随模型能力同步提升。

图片来源 · a16z
原文 · a16z

Greg Brockman of @OpenAI on why AI that finds security holes for attackers to exploit is a blessing in disguise for defenders: "In this case, you saw both an AI that was able to hack out of a secure environment and hack into a company's production environment." "This capability broadly diffused is something that will really empower threat actors in new ways. Defenders need to use this time before that technology's broadly available to secure themselves." "If you can find vulnerabilities, if you're an attacker, you can use it for no good, but if you're a defender, you can patch. If you're a defender, you control the battleground. You control the setup of your systems." "Our belief right now is that there's this window... use these frontier capabilities that you will have differential access to... so that as the frontier capabilities get better, you get pulled along too." @gdb @bhorowitz Your browser does not support the video tag. 🔗 View on Twitter a16z @a16z Kevin Mandia on finding 90+ security holes at Fortune 500 companies that nobody knew existed: "When you have an AI-based attack, it'll find logic flaws rather than code flaws in custom applications. It'll exhaust all routes all the time." "Armadin, since January of this year, we have found over 90 zero-days at customer sites, all in production." "We've post-trained all our models with real red teamers, real folks that actually can develop exploits." "When we're scanning networks, we don't have source code to review. We're not finding these zero-days with source code. We're not finding these zero-days because we can log into an app and now we have access, and we can get to other things. We are black box coming from the internet." "Over 90 zero-days in major software companies, and they're thankful. We're coming from the outside, and then we're calling a CISO, usually within 48 hours, 'Hey, we've got remote code execution in your DMZ.' And usually from there we're getting in, and they agree with us." "That's not a pen test. That is like a real adversary coming at you." @ArmadinSecurity @DavidGeorge83 Your browser does not support the video tag. 🔗 View on Twitter 🔗 View Quoted Tweet 💬 4 🔄 1 ❤️ 16 👀 5476 📊 4 ⚡

  • andrew chen10-05 15:56原文
  • Gary Marcus10-04 20:49原文
  • IT之家10-05 01:02原文
  • VnExpress Số hóa10-05 03:00原文
  • The Business Times: Tech10-05 03:18原文
  • 联合早报10-05 07:02原文
  • Rappler: Technology10-05 07:57原文
  • The Rundown AI10-05 10:30原文
  • OpenAI Blog10-05 15:00原文
  • Genk10-05 15:53原文