Automatically translated.View original post

Use AI to help find bugs. 🚨

Mozilla revealed a major breakthrough in Firefox's security after partnering with Anthropic, bringing the AI "Claude Mythos" model to help detect vulnerabilities in the software. In Firefox version 150, up to 271 vulnerabilities can be discovered and fixed before leaving them to real users.

.

That number is considered unusually high. Compared to the past, a single vulnerability could already be classified as a critical-level catastrophe. Mozilla had previously used the AI version of Opus 4.6 in Firefox 148, and only 22 were found. It clearly shows that Mythos has the potential to find a leap in vulnerability.

.

Mozilla explains that vulnerability detection normally uses both fuzzing automation and expert in-depth analysis, which, while effective, still has limitations, especially some of the code that is difficult and time-consuming, but AI like Mythos can perform this function so quickly and comprehensively that it can hardly find any type of vulnerability that humans can find but AI can't.

.

Although the number of bugs found seems worrying, Mozilla sees this as a positive sign because all vulnerabilities are discovered and fixed before they are deployed. It also reduces the advantage of hackers in the long run.

.

However, this kind of AI is also a double-edged sword, as it can also be deployed by non-hopefuls, forcing Anthropic to strictly restrict access to Mythos, allowing only certain organizations to use it.

.

Mozilla has realized that the world is entering an era in which software vulnerabilities can be discovered more comprehensively, with the power of AI truly changing the game of cybersecurity.

.

Source: cybernews, Mozilla

# IT should know # IT News # Includes IT matters # IT

4/29 Edited to

... Read moreในยุคที่ซอฟต์แวร์และเทคโนโลยีเข้ามามีบทบาทในชีวิตประจำวัน การตรวจจับช่องโหว่และบั๊กในโปรแกรมจึงเป็นเรื่องจำเป็นอย่างยิ่ง การนำ AI มาใช้ในการสแกนหาช่องโหว่จึงเป็นก้าวที่สำคัญและน่าตื่นเต้นสำหรับวงการความปลอดภัยไซเบอร์ จากกรณีของ Mozilla ที่ใช้โมเดล AI ชื่อ Claude Mythos ของ Anthropic มาช่วยตรวจสอบช่องโหว่ใน Firefox เวอร์ชัน 150 และสามารถค้นพบช่องโหว่มากถึง 271 จุดนั้น แสดงให้เห็นว่าพลังของ AI สามารถทำงานได้รวดเร็วและละเอียดกว่ากระบวนการแบบเดิมอย่าง fuzzing และการวิเคราะห์โดยผู้เชี่ยวชาญที่มักใช้เวลานาน รวมถึงยังลดข้อจำกัดของการตรวจสอบโค้ดยาก ๆ ด้วย โดยส่วนตัว ผมเห็นว่าในอนาคตจะมีการใช้ AI ในการพัฒนาความปลอดภัยของซอฟต์แวร์เพิ่มขึ้นอย่างแน่นอน เพราะ AI สามารถเรียนรู้รูปแบบช่องโหว่และเทคนิคการโจมตีที่แฮกเกอร์ใช้ได้อย่างรวดเร็วและครอบคลุมกว่าเดิม นอกจากนี้ AI ยังสามารถช่วยในการตรวจสอบโค้ดที่ซับซ้อนมากกว่าคนทั่วไปทำได้ ซึ่งช่วยลดความเสี่ยงในการปล่อยซอฟต์แวร์ที่มีช่องโหว่เข้าสู่ตลาด อย่างไรก็ตาม AI ในด้านนี้ก็มีความเสี่ยงที่จะถูกนำไปใช้ในทางที่ไม่ถูกต้อง โดยแฮกเกอร์อาจใช้เทคโนโลยี AI ในการค้นหาช่องโหว่ให้เร็วขึ้น เช่นเดียวกับที่ Anthropic ต้องจำกัดการเข้าถึง Claude Mythos ด้วยเหตุผลด้านความปลอดภัย สำหรับนักพัฒนาหรือผู้ที่สนใจเรื่องความปลอดภัยไซเบอร์ การเข้าใจและติดตามความก้าวหน้าของ AI ในการตรวจสอบซอฟต์แวร์จะช่วยให้สามารถเตรียมความพร้อมและปรับกระบวนการทำงานให้ทันสมัยและมีประสิทธิภาพมากขึ้น รวมทั้งช่วยเพิ่มความมั่นใจในการใช้งานซอฟต์แวร์ปลอดภัยมากขึ้นด้วย สุดท้ายนี้ เหตุการณ์ที่ Mozilla สามารถปิดช่องโหว่ได้มากมายก่อนปล่อย Firefox เวอร์ชันใหม่ เป็นตัวอย่างให้เห็นว่าการผสมผสานเทคโนโลยี AI กับการวิเคราะห์เชิงลึกของมนุษย์ จะเป็นอนาคตของการรักษาความปลอดภัยที่สำคัญและมีประสิทธิผลสูงสุดในยุคดิจิทัลนี้