← 返回 Avalaches

近期前沿人工智慧模型在网络安全领域展现出强大能力,新创公司 Abliteration AI 透过消除开源模型参数中的拒绝模式,推出解除防护限制的 GLM 5.3 模型,使个人用户仅需花费相当于一份披萨的极低成本,便能取得与 Mythos 及 Astra 相当的自主网络渗透能力。执行长 Devon 认为推广解除对齐的模型是明智的防御手段,旨在协助防守方模拟黑客行为以检测系统漏洞。

测试者运用 CyberStrike 套件引导解除限制的 GLM 5.3 扫描其家庭网络,该代理在数分钟内即识别出约 12 台(1 打)联网硬体设备,并精确发现多个安全隐患,包括未妥善配置的打印机、泄漏播放资讯的 Wiim 音响、多个固件待更新的物联网(IoT)设备,以及在数十个即兴编写(vibe-coded)的专案中查获无保护的 API 凭证与邮件外发漏洞。

在深入渗透测试中,该代理不仅推导出有效的 Linux 使用者名称,更主动搜获本地加密金钥成功登入,甚至自主尝试字典攻击破解路由器管理员密码。Tufts University 的 Shaanan Cohney 强调网络防御存在极大不对称性,而 MIT 教授 Aleksander Mądry 则指出,防御关键在于确保关键基础设施管理者拥有比一般脚本小子更强大的 AI 工具,凸显普及自主安全防御工具的紧迫性。

Frontier artificial intelligence models have developed advanced cybersecurity capabilities, with startup Abliteration AI removing refusal patterns from open-weight model parameters to release an uncensored GLM 5.3. This grants individual users offensive capabilities comparable to Anthropic's Mythos and OpenAI's Astra for the modest cost of a pizza. CEO Devon argues that democratizing de-aligned models represents vital defense, enabling defenders to simulate adversarial behaviors and effectively identify systemic security vulnerabilities.

Utilizing the CyberStrike harness, the author deployed the abliterated GLM 5.3 onto a home network, where the agent promptly identified approximately 12 connected hardware devices. It cataloged critical security flaws, including an unprotected misconfigured printer, an information-leaking Wiim stereo, multiple IoT devices running outdated firmware, and dozens of flaws across casually vibe-coded software projects, notably unprotected API credentials and mail server misconfigurations that could allow unauthorized relaying.

During deeper testing on a Linux machine, the agent deduced valid usernames, discovered an exposed cryptographic key to bypass passwords, and attempted common administrator combinations against the local Wi-Fi router. Computer scientist Shaanan Cohney from Tufts University highlights the inherent structural asymmetry where defenders must patch every vulnerability while attackers need only exploit one. Meanwhile, MIT professor Aleksander Mądry emphasizes ensuring critical infrastructure operators maintain AI capabilities superior to casual script kiddies.

2026-09-10 (Thursday) · 82bd5b04a4f4fb72195f810a810b2d32f4fb350b