Хиймэл оюун ухаан ашиглан Zoom-ийн аюулгүй байдлын цоорхойг илрүүлсэн нь кибер аюулгүй байдлын эрсдэлийг нэмэгдүүлж байна

Published:

Энэхүү мэдээ, нийтлэлийг хиймэл оюун боловсруулав.

Олон нийтэд нээлттэй хиймэл оюун ухааны загварууд нь нарийн төвөгтэй програм хангамжийн эмзэг байдлыг богино хугацаанд илрүүлэх чадвартай болсон нь салбарын мэргэжилтнүүдийн санааг зовоож байна.

“A Security” кибер аюулгүй байдлын компани Zoom платформ дээрх дэлгэц хуваалцах үед ашиглагддаг тэмдэглэгээний хэрэгсэлд суурилсан ноцтой цоорхойг илрүүлжээ. Энэхүү цоорхой нь халдагч этгээдэд тухайн хэрэглэгчийн төхөөрөмжийг “zero-click” буюу ямар нэгэн үйлдэл шаардахгүйгээр удирдах боломжийг олгож байсан юм. Халдагчид тусгайлан бэлтгэсэн мессежээр дамжуулан хэрэглэгчийн санах ойг гэмтээж, дур мэдэн код ажиллуулах замаар дуудлагад оролцогчдыг тус бүрээр нь онилох боломжтой байжээ.

Энэхүү эмзэг байдал нь Zoom-ийн бүх хувилбар болон үйлдлийн системүүд дээр, тэр дундаа төгсгөл хоорондын шифрлэлт (end-to-end encryption) идэвхтэй байсан ч илэрч байсныг тус компани онцолсон байна. Аюулгүй байдлын шинжээчид уг цоорхойг илрүүлэхийн тулд 20 хүрэхгүй удаагийн сануулга (prompt) өгч, 24 цагаас бага хугацаанд хиймэл оюун ухааны загваруудыг ашигласан нь анхаарал татаж байна. Одоогоор уг цоорхойг засварласан тул хэрэглэгчид програм хангамжаа шинэчлэх шаардлагатай байгаа юм.

Лас Вегас хотноо болсон “Black Hat” кибер аюулгүй байдлын хурлын үеэр АНУ болон Их Британийн албаны хүмүүс хиймэл оюун ухааны тусламжтайгаар эмзэг байдлыг илрүүлэх хурд нь түүнийг засварлах боломжоос хурдацтай давж байгааг анхааруулав. Дэвшилтэт хиймэл оюун ухааны лабораториуд өндөр хүчин чадалтай загваруудынхаа хандалтыг хязгаарлаж байгаа ч олон нийтэд нээлттэй хэрэгслүүд өөрөө кибер аюулгүй байдлын салбарыг эрс өөрчлөхөд хүргэж байна. Энэ нь аюулгүй байдлын баталгаа улам бүр бүдгэрч, хэрэглэгчид өөрсдөө ч мэдэлгүйгээр эрсдэлд орох магадлалыг нэмэгдүүлж байна.

Дэлгэрэнгүйг эх сурвалжаас харах

↓Эх сурвалжийг нээх ↓

There are few things more mortifying than the prospect of sharing something you didn’t intend to on a work Zoom call. Now imagine it’s entirely out of your control. That is the risk of a security flaw discovered and disclosed by a cybersecurity company called A Security, which found a vulnerability that allowed an attacker to hijack the device of any user involved in a call with screen sharing. Notably, the group claims to have found the issue with just a few AI prompts.

According to the firm, the vulnerability was about as bad as it gets: a zero-click remote code execution that takes advantage of the way Zoom’s annotation feature works. The company explained in a blog post that because Zoom’s client “automatically parses whatever it receives” while the annotation feature is in use, an attacker could send a “specially crafted message to corrupt the receiving client’s memory and run code on it.” And because the protocol within the app creates a direct channel between the viewer and sharer, each participant on the call could be targeted individually.

That’s pretty bad, made worse by the fact that the vulnerability was apparently present in every version of Zoom on every operating system, and was even exploitable in calls where end-to-end encryption was active. It has since been patched, but you’ll have to update to make sure you’re not subject to the hijacking technique.

What makes the flaw particularly worth mentioning is how it was discovered in the first place. According to A Security, the company was able to find the vulnerability using publicly available AI models, which were able to identify and exploit the issue in fewer than 20 prompts and in under 24 hours. Of course, the models were guided by security researchers with real know-how providing direction on what to look for, but it does speak to the ways that AI models are impacting the cybersecurity landscape.

All of the frontier AI labs have made hay about just how powerful their top-tier models are—so powerful, in fact, that access to them must be restricted so the power doesn’t fall into the wrong hands. But even the publicly available tools seem to be upending the cyber industry. Just last week, officials from the United States and the United Kingdom warned at the Black Hat cybersecurity conference in Las Vegas that the speed at which people are discovering vulnerabilities is quickly surpassing the ability to patch them.

Safety was never guaranteed, but it seems we’re all increasingly vulnerable without fully realizing it.

- Зар сурталчилгаа -

Та юу гэж бодож байна?

Сэтгэгдлээ оруулна уу!
Please enter your name here

MFC.mn сайтад сэтгэгдэл оруулахад анхаарах зүйлс

Холбоотой

spot_img

Шинэ

spot_img