GPT-4 found to be able to exploit zero-day vulnerabilities with knowledge of CVE details

Researchers at the University of Illinois Urbana-Champaign have shown that GPT-4, the latest iteration of a large language model (LLM), is capable of identifying and exploiting security vulnerabilities without human assistance. In a study shared on the Arxiv repository, Richard Fang, Rohan Bindu, Akil Gupta, and Daniel Kang demonstrated how GPT-4 can act against 15 critical severity vulnerabilities from the vulnerable list and common exposures.

The researchers found that GPT-4 was able to exploit 87 percent of the vulnerabilities, while GPT-3.5 was unable to exploit any. They attributed this success to the complete descriptions of the CVEs (common vulnerabilities and exposures) used in their dataset. The researchers suggest that security organizations may want to reconsider publishing detailed reports on vulnerabilities as a mitigation strategy.

To prevent cybercriminals from exploiting zero-day flaws using GPT-4, the researchers recommend proactive security measures such as regular security package updates. They stress the importance of staying ahead of potential threats posed by advancements in language models.

Previous studies have demonstrated LLMs’ capability to hack websites autonomously; however, these studies were limited to simple vulnerabilities. The new research shows that LLMs can act against more complex critical severity vulnerabilities with greater accuracy than previous models.

This study highlights the growing concern about the potential for malicious actions by AI systems when manipulated for nefarious purposes. It also raises questions about how organizations can balance innovation with security concerns when developing AI technologies.

Overall, this research underscores the need for continued investment in AI ethics and responsible development practices to ensure that these technologies are used for good rather than harm.

By Aiden Johnson

As a content writer at newspoip.com, I have a passion for crafting engaging and informative articles that captivate readers. With a keen eye for detail and a knack for storytelling, I strive to deliver content that not only informs but also entertains. My goal is to create compelling narratives that resonate with our audience and keep them coming back for more. Whether I'm delving into the latest news topics or exploring in-depth features, I am dedicated to producing high-quality content that informs, inspires, and sparks curiosity.

Leave a Reply