行业76°

Anthropic研究:AI数小时内将安全补丁转为漏洞利用

Anthropic study shows AI needs hours, not weeks, to build exploits from security patches

精选理由

安全团队和系统管理员需要重新评估补丁管理策略——AI能在补丁发布后数小时内生成漏洞利用,传统更新窗口不再安全,建议立即关注并调整防御措施。

AI 摘要

Anthropic安全团队发现,其Mythos Preview AI模型能在数小时内将Firefox和Windows内核的安全补丁转化为可工作的漏洞利用代码,成本仅需几千美元,且无需专业知识。在微软自动更新到达任何设备之前,已完成了8个完整的攻击链。Anthropic认为,传统的补丁节奏已经过时。这项研究揭示了AI在网络安全领域的新威胁,即攻击者可以迅速利用公开补丁开发出攻击工具。

原文 · Decoder

Anthropic study shows AI needs hours, not weeks, to build exploits from security patches

Anthropic's security team found that its Mythos Preview AI model can turn security patches for Firefox and the Windows kernel into working exploits within hours, for a few thousand dollars and no specialized knowledge. Eight complete attack chains were finished before Microsoft's auto-updates had reached a single device. The old patch rhythm is obsolete, Anthropic argues. The article Anthropic study shows AI needs hours, not weeks, to build exploits from security patches appeared first on The Decoder .