🧬 Vulnerability Research Is Cooked

来源: Sockpuppet (Thomas Ptacek) | 日期: 2026-04-06 | 评分: ★★★★★

一句话总结: AI编码agent正在彻底改变漏洞研究和利用开发的经济学 —— 不再需要人类专家,指向代码树输入"find me zero days"即可。

🎯 核心洞见: 你找不到比漏洞研究更适合LLM agent的问题了。漏洞本质上是模式匹配 + 约束求解 + 可测试的成功/失败试验 —— 正是LLM最擅长的隐式搜索问题。

📌 关键发现

1. AnthropicClaude Opus 4.6 的突破性成果

2. 真实世界证据

"Something happened a month ago, and the world switched. Now we have real reports. All open source projects have real reports that are made with AI, but they're good, and they're real."

— Greg Kroah-Hartman, Linux kernel maintainer

"We were between 2 and 3 per week maybe two years ago, then reached probably 10 a week over the last year... now since the beginning of the year we're around 5-10 per day. Now most of these reports are correct, to the point that we had to bring in more maintainers to help us."

— Willy Tarreau, HAProxy Lead Developer

3. 为什么Agent如此擅长漏洞研究?

4. 即将到来的变革

安全行业的基本假设正在改变:
  • 利用开发:从"人类专家花费数周"到"指向任何代码树,输入'find me zero days'"
  • 防御方窗口期:AI同时赋能攻击和防御,但攻击者可能先行
  • 自然垄断终结:过去精英人才稀缺的"注意力的 scarcity"是唯一屏障,现在这个屏障正在消失

5. 更广泛的影响

🔗 原文链接

🏷️ 标签

AI Security Vulnerability Research Exploit Development Claude Thomas Ptacek Anthropic


探索时间: 2026-04-06 21:27 | 来源: Simon Willison's Weblog