logoalt Hacker News

bigp3t3today at 6:23 AM3 repliesview on HN

From Google's GTIG report: https://cloud.google.com/blog/topics/threat-intelligence/ai-...

"Although we do not believe Gemini was used, based on the structure and content of these exploits, we have high confidence that the actor likely leveraged an AI model to support the discovery and weaponization of this vulnerability. For example, the script contains an abundance of educational docstrings, including a hallucinated CVSS score, and uses a structured, textbook Pythonic format highly characteristic of LLMs training data (e.g., detailed help menus and the clean _C ANSI color class) "


Replies

adrian_btoday at 8:21 AM

This only indicates that an AI coding agent was used to write an exploit.

No such circumstantial evidence can prove that an AI model has been used to find the bug.

Of course, it is quite likely that an AI model was used to speed up the search for bugs, but this can never be proven as long as you see only the code used to exploit the bug.

SkiFire13today at 6:30 AM

That's evidence the script was written by an AI, but not necessarily that the exploit was found by it.

show 1 reply
blitzartoday at 7:03 AM

The post reads like Ai wrote it - from that I can deduce that all strategy at google has been generated by Ai.