AI News AI资讯 4h ago Updated 1h ago 更新于 1小时前 50

Anthropic is finding bugs faster than Microsoft can fix them Anthropic 发现漏洞的速度比微软修复的速度还快

Anthropic's AI model Mythos has demonstrated unprecedented speed in identifying critical and important software vulnerabilities, outpacing Microsoft's ability to patch them. The technology is being used by select organizations to find and fix security flaws before adversarial nations or hackers can exploit them. A "window of opportunity" for the US and its allies to secure systems before adversaries gain access to similar AI tools is rapidly closing, with internal documents suggesting this recko Anthropic开发的AI模型Mythos被用于微软的Project Glasswing,以极快的速度发现代码漏洞。 Mythos在短短几周内发现了大量关键和重要级别的漏洞,远超传统安全测试的效率。 微软面临紧迫的时间窗口,需在竞争对手或敌对势力利用类似工具前修复这些漏洞。 低级别漏洞可能通过链式攻击组合成高风险威胁,传统漏洞分级策略可能低估风险。 Five Eyes联盟警告称,全球范围内AI辅助漏洞挖掘的能力正在迅速普及,安全窗口期即将关闭。

75
Hot 热度
68
Quality 质量
72
Impact 影响力

Analysis 深度分析

TL;DR

  • Anthropic's AI model Mythos has demonstrated unprecedented speed in identifying critical and important software vulnerabilities, outpacing Microsoft's ability to patch them.
  • The technology is being used by select organizations to find and fix security flaws before adversarial nations or hackers can exploit them.
  • A "window of opportunity" for the US and its allies to secure systems before adversaries gain access to similar AI tools is rapidly closing, with internal documents suggesting this reckoning may already be occurring.
  • Traditional vulnerability triage strategies (prioritizing only high-severity bugs) are becoming risky as AI models like Mythos can chain multiple low-severity flaws together to create devastating attack vectors.
  • Microsoft confirmed it is prioritizing the most dangerous bugs but declined to comment on specific numbers or the urgency of the May 31 deadline mentioned in internal meetings.

Why It Matters

This article highlights a pivotal shift in cybersecurity where AI-driven vulnerability discovery is accelerating faster than human defenders can respond. For practitioners and researchers, it underscores the urgent need to adapt security frameworks to account for AI's ability to chain vulnerabilities, moving beyond traditional severity ratings that may underestimate systemic risk. The narrowing window between defensive AI capabilities and potential adversary access suggests a critical inflection point in national and corporate digital security strategy.

Technical Details

  • Model Capability: Anthropic's Claude Mythos Preview identified 90 "critical" and 141 "important" bugs in Microsoft SharePoint during April alone, with even higher rates in early May.
  • Vulnerability Chaining: The AI can combine multiple low-severity vulnerabilities to achieve high-severity exploits, challenging conventional risk assessment methods.
  • Triage Strategy: Microsoft focuses initially on critical and important bugs, deferring moderate-severity issues, though this approach risks overlooking chained vulnerabilities.
  • Timeline Pressure: Internal discussions referenced a May 31 deadline after which broader public access to similar AI tools was expected, potentially allowing adversaries to exploit unpatched flaws.
  • Scope of Impact: The affected software (SharePoint) is widely used by governments and businesses globally, amplifying the strategic importance of rapid remediation.

Industry Insight

Security teams must reevaluate vulnerability management processes to incorporate AI-driven chaining risks, potentially lowering thresholds for addressing moderate-sequence flaws when advanced threat actors are likely to possess similar tools. Organizations should consider preemptive hardening of systems against multi-step attack chains rather than relying solely on reactive patching based on individual bug severity. The competitive landscape for AI-powered security tools will intensify, creating an arms race where early adopters of defensive AI gain significant advantages in protecting critical infrastructure before adversaries catch up.

TL;DR

  • Anthropic开发的AI模型Mythos被用于微软的Project Glasswing,以极快的速度发现代码漏洞。
  • Mythos在短短几周内发现了大量关键和重要级别的漏洞,远超传统安全测试的效率。
  • 微软面临紧迫的时间窗口,需在竞争对手或敌对势力利用类似工具前修复这些漏洞。
  • 低级别漏洞可能通过链式攻击组合成高风险威胁,传统漏洞分级策略可能低估风险。
  • Five Eyes联盟警告称,全球范围内AI辅助漏洞挖掘的能力正在迅速普及,安全窗口期即将关闭。

为什么值得看

这篇文章揭示了AI如何彻底改变软件安全领域——从被动防御转向主动、自动化、规模化的漏洞发现。对于AI从业者和安全工程师而言,它展示了大模型在现实世界中的强大应用能力,也警示了技术扩散带来的地缘政治与国家安全风险。

技术解析

  • Mythos是Anthropic开发的一款专门用于自动识别软件漏洞的AI模型,具备理解复杂代码逻辑并发现潜在缺陷的能力。
  • 在微软内部测试中,Mythos仅用一个月就在SharePoint系统中发现90个“严重”和141个“重要”级漏洞,效率远超人工审计。
  • 模型可识别单个漏洞之间的关联关系,将多个低危漏洞串联为高危攻击路径(chaining),这是传统静态分析难以做到的。
  • 微软采用基于CVSS标准的漏洞分级体系优先处理Critical和Important级别问题,但内部专家质疑该体系未充分考虑链式攻击风险。
  • Project Glasswing是一个限时访问计划,允许受信任组织提前使用Mythos进行安全审查,截止日期为5月31日,之后其他方可能获得同等能力。

行业启示

  • AI驱动的漏洞挖掘将成为未来网络安全的核心竞争点,企业需重新评估其依赖的传统安全流程是否足以应对自动化攻击面扩展。
  • 国家层面的技术差距可能转化为实际安全劣势,各国应加速布局自主可控的AI安全工具,避免陷入“技术代差陷阱”。
  • 安全团队必须升级风险评估框架,引入动态上下文感知机制,尤其要重视多步攻击链建模,而非孤立看待单一漏洞。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 LLM 大模型 Evaluation 评测