行业

Armadin 称今年已在客户环境中发现 90 多个零日漏洞

精选理由

Armadin 的 Mandia 讲他们用 AI 红队今年挖出 90 多个零日漏洞,全程黑盒不打源码,还能看 a16z 那 21 家公司漏洞量从 100 涨到 600 的数据。

a16z 发布的访谈中,Armadin 公司的 Kevin Mandia 表示自 2025 年 1 月以来已在客户生产环境中发现超过 90 个零日漏洞,涉及 Fortune 500 企业,通常在 48 小时内联系 CISO 通报远程代码执行问题。该公司用真实红队成员对模型做后训练,扫描网络时不依赖源代码,而是从外部黑盒方式进入。a16z 统计的 21 家大型软件公司(包括 Apple、AWS、Microsoft、Google)数据显示,过去四年每月报告的严重漏洞从未突破 100 个,今年春季以来跳涨到每月超过 600 个。Mandia 认为 AI 攻击会寻找自定义应用中的逻辑漏洞而非代码漏洞,并会穷尽所有攻击路径。

原文 · a16z

Cyber is having a moment Across 21 major software companies, including Apple, AWS, Microsoft, and Google: - Reported critical vulnerabilities never cleared 100 per month in four years - Since spring they've jumped to over 600 per month a16z @a16z Kevin Mandia on finding 90+ security holes at Fortune 500 companies that nobody knew existed: "When you have an AI-based attack, it'll find logic flaws rather than code flaws in custom applications. It'll exhaust all routes all the time." "Armadin, since January of this year, we have found over 90 zero-days at customer sites, all in production." "We've post-trained all our models with real red teamers, real folks that actually can develop exploits." "When we're scanning networks, we don't have source code to review. We're not finding these zero-days with source code. We're not finding these zero-days because we can log into an app and now we have access, and we can get to other things. We are black box coming from the internet." "Over 90 zero-days in major software companies, and they're thankful. We're coming from the outside, and then we're calling a CISO, usually within 48 hours, 'Hey, we've got remote code execution in your DMZ.' And usually from there we're getting in, and they agree with us." "That's not a pen test. That is like a real adversary coming at you." @ArmadinSecurity @DavidGeorge83 Your browser does not support the video tag. 🔗 View on Twitter 🔗 View Quoted Tweet 💬 9 🔄 0 ❤️ 20 👀 4244 📊 7 ⚡