Knowledge File / AI小生意项目库
一个价值20万美元的真实macOS漏洞未被报告,因为苹果的漏洞赏金邮箱被AI垃圾信息塞满
苹果限制安全研究人员提交漏洞报告的数量,并强制30天冷却期。低质量AI生成的漏洞报告堵塞了审核流程,导致意大利初创公司Bynario发现严重macOS漏洞却无法提交,该漏洞黑市价值高达20万美元。苹果已联系Bynario,同时自身也在使用AI寻找漏洞。
SOURCE / AI小生意项目库
MIN / 9
ACCESS / 会员
POST / 2026-08-02 20:42:49
原贴
查看原文原文
AI as a cybersecurity risk, but not the way you'd think. Apple is capping the number of bug reports security researchers can submit and enforcing a 30-day cooldown period. A flood of low-quality, AI-generated reports with hallucinated vulnerabilities is clogging the review pipeline, the Financial Times reports . Researchers can request a higher quota. The cap creates real security gaps: Italian startup Bynario used ChatGPT to find a serious macOS vulnerability that could give attackers full control over a machine but couldn't report it because Apple had blocked further submissions. CEO Alfredo Pesoli estimates the flaw's black-market value at $100,000 to $200,000. Apple has since reached out to Bynario. Meanwhile, Apple itself is using AI from Anthropic and OpenAI to hunt for vulnerabilities, and its latest updates included five times as many fixes as usual. That raises the question whether bug bounty programs can survive long-term or whether big tech companies will handle vulnerability discovery on their own. Rafe Pilling of Sophos told the FT that bug bounty programs have gone from finding vulnerabilities to validating them "at machine speed." Ad DEC_D_Incontent-1 Ad Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section.
中文翻译
AI是一种网络安全风险,但并非你想的那样。苹果正在限制安全研究人员可以提交的漏洞报告数量,并强制执行30天的冷却期。据《金融时报》报道,大量低质量的、由AI生成的、带有虚构漏洞的报告正在堵塞审核流程。研究人员可以申请更高的配额。这一限制造成了真实的安全漏洞:意大利初创公司Bynario使用ChatGPT发现了一个严重的macOS漏洞,该漏洞可能让攻击者完全控制机器,但由于苹果已阻止进一步提交,他们无法报告。CEO Alfredo Pesoli估计该漏洞在黑市上的价值为10万至20万美元。苹果随后已联系Bynario。与此同时,苹果自己也在使用Anthropic和OpenAI的AI来寻找漏洞,其最新更新包含的修复数量是平时的五倍。这引出一个问题:漏洞赏金项目能否长期存在,还是大型科技公司将自行处理漏洞发现。Sophos的Rafe Pilling告诉《金融时报》,漏洞赏金项目已经从寻找漏洞转变为“以机器速度”验证漏洞。
核心信息
苹果限制安全研究人员提交漏洞报告的数量,并强制30天冷却期。低质量AI生成的漏洞报告堵塞了审核流程,导致意大利初创公司Bynario发现严重macOS漏洞却无法提交,该漏洞黑市价值高达20万美元。苹果已联系Bynario,同时自身也在使用AI寻找漏洞。
- 苹果限制安全研究人员提交漏洞报告的数量,并强制30天冷却期。低质量AI生成的漏洞报告堵塞了审核流程,导致意大利初创公司Bynario发现严重macOS漏洞却无法提交,该漏洞黑市价值高达20万美元。苹果已联系Bynario,同时自身也在使用AI寻找漏洞。
- 原贴提到:AI as a cybersecurity risk, but not the way you'd think. Apple is cappin
- 来源:the-decoder.com
试看内容
成为会员查看完整内容
你已经看到了这篇内容的前置整理,剩余深度部分仅对会员开放。
详细解读
信息差价值
参考来源
成为会员查看完整内容