Researchers: when given 15 CVE descriptions, GPT-4 autonomously exploited 87% of the “one-day” vulnerabilities, compared to 0% for every other model tested
The Register Thomas Claburn
Related Coverage
- GPT-4 Can Exploit Most Vulns Just by Reading Threat Advisories Dark Reading
- LLM Agents can Autonomously Exploit One-day Vulnerabilities arXiv
- LLM Agents can Autonomously Exploit One-day Vulnerabilities [PDF] arXiv
- LLM Agents can Autonomously Exploit One-day Vulnerabilities Daniel Kang
- ChatGPT can craft attacks based on chip vulnerabilities — GPT-4 model tested by UIUC computer scientists Tom's Hardware
- @chetwisniewski @Techmeme I read the research earlier and they didn't present the actual evidence, it was weird @GossiTheDog@cyberplace.social
- So, about this claim that GPT-4 can exploit 1-day vulnerabilities. — I smell BS. — As always, I read the source paper. — Firstly, almost every vulnerability that was tested was on extremely well-discussed open source software, and each vuln was of a class with extensive prior work. … @mttaggart@infosec.town
- This is a wake-up call for all of us in the cybersecurity field. It highlights the growing sophistication of AI-powered attacks and the need for us to adapt our defenses accordingly. … Stanley Tsang
- In a newly released paper, four University of Illinois Urbana-Champaign (UIUC) computer scientists - Richard Fang, Rohan Bindu, Akul Gupta … Michael Tchuindjang
- Reactionary security/media FUD at its absolute worst. There's no such thing as a critical #vulnerability, generically. … Ben Hanson
- This will drastically decrease the level of skill to be a beginner hacker, while also increasing the capability of novice who might not typically be able to use a proof of concept. … Christopher Peacock
- Recent revelations that AI models like GPT-4 can exploit cybersecurity vulnerabilities are a stark reminder: the cyber landscape is transforming, and so must we. … Andrew Bandeira
- GPT-4 can exploit vulnerabilities by reading CVEs Hacker News
- GPT-4 Can Exploit Real Vulnerabilities By Reading Security Advisories Slashdot
Discussion
-
@soundboy
Ian Hogarth
on x
Early research into AI agents & their ability to autonomously exploit one-day vulnerabilities: https://arxiv.org/.... Feels important to prepare for a world where cyber attacks get easier by investing now in enhanced cybersecurity.
-
@daniel_d_kang
Daniel Kang
on x
We showed that LLM agents can autonomously hack mock websites, but can they exploit real-world vulnerabilities? We show that GPT-4 is capable of real-world exploits, where other models and open-source vulnerability scanners fail. Paper: https://arxiv.org/... 1/7