back to article Today's LLMs craft exploits from patches at lightning speed

The time from vulnerability disclosure to proof-of-concept (PoC) exploit code can now be as short as a few hours, thanks to generative AI models. Matthew Keely, of Platform Security and penetration testing firm ProDefense, managed to cobble together a working exploit for a critical vulnerability in Erlang's SSH library (CVE- …

  1. Anonymous Coward
    Anonymous Coward

    Fast patching, and deployment anytime

    "your infrastructure should be built to allow safe and fast patching."

    This has become crucial: Your production system should be able to be patched and updated at any time.

    If not, you're a sitting duck.

    And you should make backups because you will be hacked.

    1. elDog

      Re: Fast patching, and deployment anytime

      So perhaps we should add in a "Patch Friday" every now and then. And require the system to be rebooted. And pray that the boot disk can still be read, etc.

      1. Anonymous Coward
        Anonymous Coward

        Re: Fast patching, and deployment anytime

        "So perhaps we should add in a "Patch Friday" every now and then."

        No, a Simian Army (like Netflix) of monkey programs that reboot, or patch, servers and services randomly. Netflix uses these to ensure robust services. If a server cannot reboot now, there is something wrong.

        If you want to be able to patch any time, you should simply patch and reboot randomly to test continuously.

        1. kmorwath

          Re: Fast patching, and deployment anytime

          Absolutely. System administrators needs to be replaced by monkeys. They can't do a worse job.

      2. I am the liquor

        Re: Fast patching, and deployment anytime

        Never on Friday. You don't want to be in at the weekend when it goes wrong, do you? Safest not to do anything of consequence on Friday. Except firing people, of course. Studies have statistically shown that there's less chance of an incident if you do it at the end of the week.

    2. This post has been deleted by its author

  2. Clausewitz4.1
    Devil

    AI bubble bursting

    And people still fall for that ?

    1. ecofeco Silver badge

      Re: AI bubble bursting

      Apparently at least 7 numpties here looking at your downvotes. Assuming you mean they still fall for the AI as savior bollocks

      They just mad about their cryptocoins.

  3. Anonymous Coward
    Anonymous Coward

    Exploiting development

    Exploiting development should be made on a tight, closed group task-force. With zero AI or mind reading.

    After all, it's cybernetic weapons stockpile of a country. And each one found is worth from thousands to millions.

  4. m4r35n357 Silver badge

    Generative my arse

    This word is increasingly added to the A1 bullshit, as if it is a done deal.

    There is no such thing, do you understand?

  5. steelpillow Silver badge
    Alert

    Patch Hour?

    Sod Patch Tuesday. Gonna have to be AI-automated Patch Hour until a certain shitty OS learns to patch itself without rebooting everything like the good ones do.

    1. ecofeco Silver badge

      Re: Patch Hour?

      Exactly. There is NO way to keep up with that.

      Hence my other post here.

  6. ecofeco Silver badge
    Mushroom

    Hahahahahahahahahahaha

    "Sergai you arrogant ass, you've killed US!"

    Well, it was fun while it lasted and now it's self destructed.

  7. frankyunderwood123

    At what point is attack and defence handed over to AI?

    This paints an interesting picture which could theoretically be the first place where LLMs or dare we say AI is pitted against itself / other models in real time.

    Bad actors use LLMs to quickly find exploits while systems are protected by LLMs real time constantly scanning for vulnerabilities, attacks etc. and self patching the system.

    Human interaction is simply to watch, check logs, occasionally prompt.

    At this point it really is AI against AI with all the hallucinations that could result.

    Bad actor AI tricks system protection AI into becoming a Bad actor too.

    It's a weird idea, always on 24/7 self learning LLM's "battling" each other at a speed humans can't match and perhaps even left unattended/unmonitored for hours end.

    What could possibly go wrong?

  8. herman Silver badge

    Private fight

    Can’t we just let the AIs fight things out without involving us?

    1. ecofeco Silver badge

      Re: Private fight

      We could have except for tech douche bros.

  9. theOtherJT Silver badge

    I wonder how long...

    ...before we look back on today's world with much the same misty eyed nostalgia as we get today looking at computing in the 80s and early 90s? "Oh, no, there's no password, there's only one user account, so why need one?" "Why would we need to segregate memory between processes? Who's running two processes at once?" "What do you mean 'firewall' why wouldn't I allow totally unrestricted data flow between this machine and that one? That's Ted's machine. We all know Ted!"

    I get the impression that a day will come when running code that hasn't been mathematically validated to do what it says it does will be looked at as some kind of age of innocence naiveite, and people will look back on speed of development and change in the decades before and wish for the days before everything got infested with hostile AI that has to be guarded against at every turn.

  10. johnmccash

    My question is whether this means that, in addition to generating exploits faster, AI can also assist with generating exploits for vulnerabilities that might not have had exploits created for them at all, previously. I'm thinking of vulnerabilities that MS categorizes as 'exploitation less likely', such as CVE-2024-35254.

    Thoughts?

    1. ecofeco Silver badge
      Mushroom

      Imagine generating endless exploits every hour of the day.

      THAT'S what this means.

      Now imagine what it takes to counter that. Yeah, nothing. We're screwed.

      The well has now been poisoned beyond fixing.

    2. heyrick Silver badge

      Rated 7.1 severity high? Sounds important...

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like