• chicken@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    4
    ·
    7 days ago

    Instead, the data suggests that AI is currently better at increasing the volume of vulnerabilities researchers can uncover than at increasing the proportion that attackers actually exploit.

    Makes sense, if AI can find an exploit, then everyone is going to know about it pretty soon.

  • BussyGyatt@feddit.org
    link
    fedilink
    English
    arrow-up
    3
    ·
    edit-2
    6 days ago

    Huh? The claim is that it will find volumes more vulnerabilities than a human with the same amount of time, not that the vulnerabilities it finds will be somehow more exploitable? big “I knew we had lost the war when the generals’ reports of glorious victories came nearer and nearer the capitol” energy. And really, since AI produces so many false positives (hallucinations) we really ought to expect a lower-than-competent-human rate of finding exploits. The real question is “can we patch vulnerabilities faster than ai can find them?” and the answer, for now, is apparently yes.

    edit: capital

  • Multiplexer@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    7
    ·
    7 days ago

    Some good news today, at last.

    Although one might want to insert the WWII airplane hit distribution picture here, especially with regard to exploits used by governments, as those are not part of the disclosed sets and targeted attacks are also in general much less likely to show up using simple attack monitoring.