버그 소문으로 공격 코드가 빠르게 생성되는 현상에 대한 기사.
OCaml cohttp 6.3.0의 경로 순회 취약점에 대한 수정 PR이 공개된 후, 불과 10분 만에 실제 서버에서 유사한 공격 시도가 발생했다. AI 에이전트는 이 취약점의 대략적인 유형만으로도 1분 내에 공격 코드를 생성해 내는 능력을 보여 주었다. 이는 보안 분야에 있어 무차별적인 공격 리스크가 증가하고 있음을 시사한다.
The article discusses the rapid generation of exploit code based on bug rumors.
After the release of the path traversal vulnerability fix PR for OCaml cohttp 6.3.0, a similar attack was attempted on an actual server within just 10 minutes. An AI agent was able to generate exploit code in under a minute, based solely on a rough understanding of the vulnerability type. This highlights the increasing risk of indiscriminate attacks in the security field.