听听Truffle Security CEO怎么说:AI没降低核武门槛,但黑客门槛低到只会提问就行,还聊了25万条泄漏密钥和npm蠕虫。
Truffle Security CEO Dylan Ayrey在Black Hat USA上表示,AI模型拥有专业知识后,黑客攻击门槛降到只需向模型提问。他认为核武器风险不值得担心,因为仍需获取裂变材料。他提到公开训练集中有25万条活跃API密钥,npm蠕虫正通过数百个包传播。Socket Security CEO Feross Aboukhadijeh参与讨论,认为恶意软件作者本非优秀程序员,代码变好可能是vibe coding所致。
.@trufflesec co-founder and CEO Dylan Ayrey on which AI risk is actually worth worrying about: "No ...
. @trufflesec co-founder and CEO Dylan Ayrey on which AI risk is actually worth worrying about: "No one needs to worry about these models making it materially easy to build nuclear weapons, because you need to procure fissile material to do that." "Everyone needs to worry about these models making it materially easier to hack into things." "The bar previously was just subject matter expertise. Now the models have the subject matter expertise, and they're making it materially easier to hack into just about anything you can think of." "The bar has now fallen to just asking the model." @InsecureNature Your browser does not support the video tag. 🔗 View on Twitter a16z @a16z "Malware authors were never really great coders. So if the code starts looking better, it's probably vibecoded. It's the opposite of what you'd think." Truffle Security CEO Dylan Ayrey and Socket Security CEO Feross Aboukhadijeh sit down with a16z's Joel de la Garza at Black Hat USA 2026. The bar for hacking used to be real expertise plus a willingness to risk jail, now it's simply asking a model that was trained to be good at it. They get into why a leaked password beats a zero-day when you're optimizing for tokens, the quarter-million live API keys sitting in public training sets, and the npm worm spreading through a few hundred packages while they recorded. 00:00 Intro 00:49 Models are escaping their cages 01:28 Committing a felony to complete a task 05:20 The path of least tokens 09:19 How the labs trained models to hack 11:45 250K keys in Hugging Face training sets 13:02 100s of repos breached as we speak 16:55 npm's nuclear option 21:06 2026 is the software supply chain's year @InsecureNature @trufflesec @feross @SocketSecurity Your browser does not support the video tag. 🔗 View on Twitter 🔗 View Quoted Tweet 💬 5 🔄 0 ❤️ 9 👀 6314 📊 4 ⚡