Calif Research发布首个零点击微信蠕虫WeWorm
Quoting Calif Research
展示了AI在安全研究与漏洞利用中的实际工程能力,为安全从业者提供了关于AI辅助攻防效率的新视角与参考案例。
Today, we're releasing a demo of WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android. [...]
今天,我们发布了一个 WeWorm 的演示版本,这是首个通过 iOS 和 Android 上的微信通话传播的零点击蠕虫。[...]
The victim does not need to answer the call, or interact with their phone at all. Even if they do answer, they hear nothing, and the exploit still succeeds. [...]
受害者无需接听电话,也完全不需要与手机进行任何交互。即使他们接听了,也听不到任何声音,但漏洞利用依然成功。[...]
Working with AI, our team found the bug and wrote the first remote code execution (RCE) exploit in about two days. Building the worm took one more week.
借助 AI,我们的团队在大约两天内发现了该漏洞并编写了第一个远程代码执行(RCE)漏洞利用程序。构建蠕虫又花了一周时间。
A worm at this scale used to be the kind of thing that took a larger team months. AI can already do most of the work here. Our team provided the judgment about what to target and how to test it safely.
以往这种规模的蠕虫通常需要更大的团队花费数月时间才能完成。AI 已经能够在这里承担大部分工作。我们的团队提供了关于目标选择和安全测试方法的判断。
— Calif Research, WeWorm
—— Calif Research,WeWorm
Tags: ai-security-research, ai, llms, security, generative-ai
标签:ai-security-research、ai、llms、security、generative-ai
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力