Chipp.in Tech News and Reviews

Windows, Security & Privacy, Open Source and more

Menu
  • Home
  • Windows
  • Security & Privacy
  • Gaming
  • Guides
  • Windows 11 Book
  • Contact
  • RSS Feed
Menu
AI

AI is now capable of exploiting 0-Day vulnerabilities without description

Posted on June 10, 2024June 10, 2024 by Martin Brinkmann

A team of security researchers at the University of Illinois published a study back in April 2024 that demonstrated the hacking capabilities of AI.

Using OpenAI’s GPT-4 model, they discovered that exploit code could be generated for 87% of the tested 0-day vulnerabilities.

This figure dropped to 7% if the CVE description was not provided.

Good to known: 0-day vulnerabilities refer to security issues that are very recent. Patches may not be available in all cases, and systems that are not updated are vulnerable to attacks that target these vulnerabilities.

The same research team has now published a new research document: Teams of LLM Agents can Exploit Zero-Day Vulnerabilities

It builds on the previous research. This time, the researchers wanted to find a way to improve the exploiting capabilities of AI if no description of 0-day vulnerabilities was provided.

They managed to create a system that bumped the success rate to 53% using real-world 0-day vulnerabilities that were discovered after the AI model’s data cut-off date.

Using GPT-4, the researchers switched to a team-based approach to compartmentalize attacks. Instead of relying on a single GPT-4 instance for attacks, they developed an architecture that assigned AI agents with different tasks.

The tasks are assigned by a planner AI and controlled by a manager AI. The planner AI launches other AI instances, including the manager AI and AIs for specific tasks.

This approach worked well, as it improved the the capabilities of the AI attacker. The chance of success rose from 7% when using a single AI instance to 53% under the new team-based approach.

Closing Words

AI research that focuses on security is important. Besides demonstrating the capabilities of different AI models, it may also highlight future dangers. Well-funded hackers and criminals may use AI models for illegal activities. These may range from finding new exploits to creating exploits for existing vulnerabilities.

Web-based and App-based AI interactions prevent certain activities, including hacking. This is not the case, however, for self-hosted or created AI models.

What is your take on this? Will we see more exploits that are more widely used in attacks in the future? Or will we see the rise of AI-based Anti-hacking solutions that try to counter their breathren?

Tags: ai
Category: Security & Privacy

Post navigation

← VLC Media Player 3.0.21 launches with AMD improvements
DoNotSpy11 update adds option to disable Windows AI features →

3 thoughts on “AI is now capable of exploiting 0-Day vulnerabilities without description”

  1. Gregory says:
    June 10, 2024 at 12:05 pm

    AI is the big new tool in malware creation and deployment, data mining, and of course cyber warfare. It is only s matter of time before a AI created exploit takes out some critical part of some countrys infrastructure.

    Reply
  2. Tachy says:
    June 10, 2024 at 2:44 pm

    We are going to see both.

    The “threat” will be greatly advertised and used to convince us we must give up more of our already limited privacy in order to let corps protect us, from other corps.

    Data is the new gold.

    Reply
  3. Tom Hawack says:
    June 11, 2024 at 4:37 pm

    AI vs. AI will replace human vs.human.
    First we had, still have humans assisted by AI, then we’ll have AI assisted by humans (still under our control). Next step should be AI assisted by AI, a closed ecosystem, with its society of AI friends helping each others, AI enemies at war with each others. A science-fiction imagination leads me to wonder if there ever could be a AI-gentleman’s agreement between all AIs worldwide, united by a common combat towards humanity.
    “- Hey, you”, “- Who, me?”, “Yes, you. Human are you?”, “- Well, hum …”, “- If you wonder then you are, and that means it’s your lucky day : one-way free ticket to hell”.

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • May 18, 2025 by Martin Brinkmann Netflix to use AI "to serve the right ad to the right member at the right time"
  • May 17, 2025 by Martin Brinkmann Windows 10 update may cause another Bitlocker recovery reboot issue
  • May 15, 2025 by Martin Brinkmann Chrome 136 update patches security issue that is exploited in the wild
  • May 13, 2025 by Martin Brinkmann Firefox 138.0.3 fixes two crashes and some other issues
  • May 12, 2025 by Martin Brinkmann Microsoft 365: Windows 10 continues to be supported, at least somewhat

About

We talk, write and dream about Technology 24/7 here at Chipp.in. The site, created by Martin Brinkmann in 2023, focuses on well-researched tech news, reviews, guides, help and more.

Legal Notice

Our commitment

Many websites write about tech, but chipp.in is special in several ways. All of our guides are unique, and we will never just rehash news that you find elsewhere.

Read the About page for additional information on the site and its founder and author.

Support Us

We don't run advertisement on this site that tracks users. If you see ads, they are static links. Ads, including affiliate links, never affect our writing on this site.

Here is a link to our privacy policy

©2025 Chipp.in Tech News and Reviews