Artículos Relacionados con Bug Bounty

El Centro de Noticias de HTX ofrece los artículos más recientes y un análisis profundo sobre "Bug Bounty", cubriendo tendencias del mercado, actualizaciones de proyectos, desarrollos tecnológicos y políticas regulatorias en la industria de cripto.

AI Bulk Bombards Apple Bug Bounty Program, Review Team Has Gone Offline

Apple has temporarily suspended and limited submissions to its Bug Bounty Program due to a flood of AI-generated vulnerability reports. The program, launched in 2016 and offering rewards up to $5 million, has been overwhelmed by reports from amateur researchers using tools like ChatGPT, many containing false positives or "AI hallucinations." This AI-driven surge in bug reports is straining Apple's security review team, leading the company to impose a 30-day "cooling-off" period and submission caps. The trend highlights a broader industry challenge, with other major firms like Google and GitHub also adjusting their vulnerability disclosure programs. Paradoxically, while AI is creating a reporting bottleneck, it's also accelerating defense. Apple's recent macOS Tahoe 26.6 security update, which patched 194 vulnerabilities, included its first-ever acknowledgments to AI tools (Claude, Codex Security, etc.) for helping discover flaws. This forces Apple into faster, more frequent security updates, a departure from its traditionally controlled release cadence. A key example involves Apple's advanced "Memory Integrity Enforcement" (MIE) security feature, touted as a major breakthrough. However, researchers using an AI model bypassed its protections in just five days, demonstrating both the power and disruptive pace of AI in cybersecurity. The incident underscores a critical shift: as AI compresses the vulnerability discovery cycle to days, traditional monthly security update cycles may become dangerously long exposure windows.

marsbitHace 18 hora(s)

AI Bulk Bombards Apple Bug Bounty Program, Review Team Has Gone Offline

marsbitHace 18 hora(s)

Claude Opus 4.8 Finds a $4.5 Billion Bug: The AI Era is Mass-Producing Hackers

A researcher discovered a critical "infinite mint" vulnerability in the Zcash cryptocurrency's Orchard protocol using Claude Opus 4.8, leading to a swift fix but also a 50% market drop, erasing billions in value. This incident highlights a new era where powerful, accessible AI models are dramatically lowering the barrier to finding software vulnerabilities. Previously, the security community feared specialized models like Claude Mythos Preview, capable of finding decades-old zero-day exploits. The Zcash case, however, involved a publicly available, general-purpose model. This shift makes advanced security auditing—and attack capabilities—accessible to far more people, not just experts. The mass democratization of vulnerability discovery brings a dual challenge: a flood of low-quality, AI-generated false reports that overwhelm maintainers, and the real, rapid uncovering of deep, dangerous bugs. Open-source projects, often understaffed and unfunded, are particularly vulnerable to this "attention DDoS." The article cites examples like curl shutting down its bug bounty program due to the unsustainable workload. Our perceived digital safety has often been luck, relying on the high cost and effort required to find deeply hidden flaws in complex systems, as seen with historical vulnerabilities like Heartbleed or Baron Samedit. AI changes this cost structure, effectively "mass-producing flashlights" to illuminate every corner of our codebase. While large companies operate extensive security chains involving external white-hat hackers and massive defensive operations, the global cybersecurity workforce faces a severe shortage, especially of experienced personnel capable of analyzing complex threats and coordinating fixes. The core dilemma emerges: AI makes *finding* bugs cheap and scalable, but *fixing* them remains a slow, expensive, and human-intensive process. The article concludes that AI won't destroy the internet but acts as a bright light, revealing that our digital existence is not inherently secure but is precariously maintained by ongoing human effort. The true cost in the AI era may not be discovery, but whether there will be enough people left willing and able to do the hard work of repair.

marsbit06/06 09:22

Claude Opus 4.8 Finds a $4.5 Billion Bug: The AI Era is Mass-Producing Hackers

marsbit06/06 09:22

活动图片