a16z对谈:恶意代码变好?可能是AI写的

"Malware authors were never really great coders. So if the code starts looking better, it's probably...

精选理由

想知道AI怎么帮人当黑客?a16z请来两个安全CEO聊了泄露密码、25万个API密钥和npm蠕虫,全是实战细节。

AI 摘要

在Black Hat USA 2026上,Truffle Security CEO Dylan Ayrey与Socket Security CEO Feross Aboukhadijeh对谈a16z的Joel de la Garza,指出AI模型已能直接执行黑客任务。他们认为恶意软件作者通常差劲,代码质量提升往往意味着vibecoded。讨论提到,公开训练集中存在约25万个实时API密钥,泄露密码比零日漏洞更符合token优化。录制期间,一个npm蠕虫正通过数百个包传播,2026年被视为软件供应链攻击之年。

图片来源 · a16z
原文 · a16z

"Malware authors were never really great coders. So if the code starts looking better, it's probably...

"Malware authors were never really great coders. So if the code starts looking better, it's probably vibecoded. It's the opposite of what you'd think." Truffle Security CEO Dylan Ayrey and Socket Security CEO Feross Aboukhadijeh sit down with a16z's Joel de la Garza at Black Hat USA 2026. The bar for hacking used to be real expertise plus a willingness to risk jail, now it's simply asking a model that was trained to be good at it. They get into why a leaked password beats a zero-day when you're optimizing for tokens, the quarter-million live API keys sitting in public training sets, and the npm worm spreading through a few hundred packages while they recorded. 00:00 Intro 00:49 Models are escaping their cages 01:28 Committing a felony to complete a task 05:20 The path of least tokens 09:19 How the labs trained models to hack 11:45 250K keys in Hugging Face training sets 13:02 100s of repos breached as we speak 16:55 npm's nuclear option 21:06 2026 is the software supply chain's year @InsecureNature @trufflesec @feross @SocketSecurity Your browser does not support the video tag. 🔗 View on Twitter 💬 2 🔄 3 ❤️ 16 👀 4232 📊 4 ⚡