← 返回 Avalaches

近期随著主流与开源人工智慧工具的普及,利用人工智慧挖掘软体漏洞的速度出现了前所未有的激增。包含微软、甲骨文、Google Chrome 和 Mozilla 等各大科技巨头近期释出的漏洞修补程式数量均创下历史新高,资料显示今年记录的 CVE 总数已呈现翻倍成长,给资源有限的人力资安团队与开源软体维护者带来沉重负担。

资安专家对于这波漏洞爆发的影响看法不一,部分学者认为这仅是揭露了更多已知问题,代表安全系统正在发挥作用;然而多数人担忧的是修补的速度远远跟不上漏洞发现的脚步,且攻击者同样能借由人工智慧加速挖掘新型漏洞,进而引发更加频繁与升级的网路攻击行动。

目前资安攻防双方在人工智慧的应用上维持著脆弱的平衡,但核心瓶颈在于漏洞挖掘能借由算力无限扩展,而修补与应对却始终受限于人力规模。即使未来针对前沿模型实施开发减速或监管措施,也无法遏止现有 AI 工具已然带来的软体漏洞海啸。

The widespread availability of mainstream and open-source AI tools has led to an unprecedented surge in AI-driven software vulnerability discoveries. Major tech companies including Microsoft, Oracle, Google Chrome, and Mozilla have recently set records for released patches, while tracked CVE totals have nearly doubled compared to previous periods, placing immense strain on under-resourced security teams and open-source maintainers.

Cybersecurity experts remain divided on the ramifications of this spike: some argue that a higher CVE count simply reflects better detection rather than inherent harm, while others caution that remediation cannot keep pace with automated discovery and that malicious actors are equally empowered to uncover novel flaws using AI.

Although a tenuous balance currently persists between offense and defense utilizing AI, the fundamental dilemma lies in the fact that vulnerability discovery scales with computing power, whereas remediation relies on finite human labor. Even if future AI model development slows through regulation or industry agreements, it cannot halt the ongoing wave of vulnerabilities unleashed by existing tools.

2026-09-20 (Sunday) · a0beafe48f78a752987bde70607450555cd1c4ac