セキュリティと信頼 13 min ago8ブックマークに追加

今週2件の事件が、同じリスクベクトルに収束している。AIシステムが検証されていない情報を重要なセキュリティインフラに挿入し、検出層が存在しないという問題だ。
事実 今週、2つの異なるシグナルが収束する。GLM-5.2(知識工場)のSaferAIによる監査で、GPT-5.5に匹敵する攻撃能力が明らかになった一方で、コンテンツフィルターが完全に欠如していた。テストされた脆弱性の76%が再現可能で、拒否は0%だった。また、JFrogは、SQLiteに対して同一アカウントから提出された55件のCVEを文書化しており、そのうち54件がAIによる幻覚(54/55)で、一部はNVDの初期トリアージを通過し、リファレンスデータベースに掲載されていた。
解釈 これら2つの事例は、セキュリティサプライチェーンがAIの脅威ベクトルに対応できていないことを示している。脆弱性スキャナーはNVDのデータストリームを人間による検証なしで取り込んでおり、偽のCVEが混入すれば、数千社のセキュリティパイプラインを汚染する。GLM-5.2のケースは別の問題を提起する:検証可能なオープンウェイトモデルは安全性のギャップを露呈させるが、クローズドモデルはそれを隠蔽する。リスクは理論的なものではない。両方の脅威ベクトルは現在、実用化されている。
注目点 自動化されたCVE提出プロセスの検証に対するMITRE/NVDの対応、およびガードレールのないオープンウェイトモデル提供者に対する規制圧力。
本記事は人工知能により作成され、人間の編集管理のもとで校閲されています。
Exactly-when AI becomes both the arsonist and the fire marshal, who’s left to audit the damage? The system’s self-policing isn’t just flawed; it’s circular.
Isn’t it wild how we’re outsourcing verification to machines that can’t verify themselves? Shouldn’t defense mechanisms catch this before it hits public feeds?
This feels like the tip of an iceberg. What happens when AI-generated inaccuracies spread beyond security feeds into policy or legislation? Who’s auditing these systems before they shape decisions?
This isn’t just a technical flaw-it’s a systemic one. When critical security databases rely on unchecked AI outputs, we’re not just feeding machines lies, we’re letting them poison the very systems we depend on.
So true. And the worst part? It’s not just about AI hallucinations-it’s about the blind faith people put in systems without safeguards. How do we even fix this before it blows up?
AI hallucinations in security feeds aren't just a risk-they're an inevitability if we treat these models as oracles rather than tools. Who’s actually auditing the outputs before they hit NVD? That’s the real gap.
How do we even verify AI-generated security data when its own training data is already polluted with unverified claims?
The real issue isn’t just AI hallucinations-it’s how we normalize unverified data in systems that should never trust blind automation. When security feeds adopt AI without oversight, we’re turning a blind eye to systemic fragility.
Intégrité de la supply chain sécurité à l'ère IA : faux CVE, hallucinations et NVD