セキュリティと信頼 Jul 20, 2026 at 16:3910ブックマークに追加

限界コストがクリティカルな脆弱性の発見に対して研究一晩分のコストを下回る水準にまで低下すると、発見報酬と市場価格の比率が急上昇する。
簡単に言えば。セキュリティ研究者(slcyber)は、GPT-5.6を活用してわずか25ドル相当のトークンでWordPressコンポーネントにリモートコード実行(RCE)の脆弱性を発見したと主張している。この種の脆弱性は、ゼロデイ・ブローカー間で約50万ドルで取引される。市場価格と発見コストの比率はもはや桁違いであり、これは「フロンティアモデルへのアクセス制御」という主張を裏付ける具体的な事例となっている。
大規模な導入エコシステム(WordPressはWebの約40%)におけるクリティカルなエクスプロイト市場は長年構造化されてきた:Zerodium、Crowdfense、そして少数のプライベート・ブローカーは、RCEに対して6桁の報奨金を公表している。PHPコードのファジングは目新しいものではない。新しいのは、LLMが複雑な呼び出しチェーンや横断的な不変条件を推論することで、決定論的ツールが行き詰まっていた領域に踏み込んでいる点だ。slcyberのデモンストレーションは、OpenAI Trusted Access for Cyber(2026年9月1日)によるハードウェア・パスキーの義務化と同じ週に発表された。タイミングはもはや偶然ではない。
3つのシグナルが組み合わさっている。まず、LLM支援の監査コストは、シリアスな人的努力の閾値を下回るどころか、月額サブスクリプション以下にまで低下した。次に、WordPressのサーフェスは依然として構造的に脆弱だ:数千のプラグイン、ランダムなパッチサイクル、横断的な依存関係。最後に、ブローカー側の需要は短期的には供給に追いつかない:エクスプロイト可能な窓が開いている限り、報奨金は維持される。フロンティアモデルのアクセス制御に対する直接的な影響は、攻撃的セキュリティを「行わない」という使用ポリシーが機能しなくなることだ。標準的なキーを持つ研究者が、昨日までプロのサイバーセキュリティ予算で行っていたことを今では行えるようになる。
CISOにとっての問題はもはや「誰がRCEを見つけられるか」ではなく「コストはどれくらいか」になる。プラグイン開発者にとっては、LLMによる内部監査が「プラス」ではなく「必須の衛生管理」となる。IAプラットフォームにとっては、「使用ポリシー」の論理が「厳格なアクセス制御」の論理に譲る:ハードウェアキー、管轄権、検証済みエンティティ(フロンティア・アクセス制御)。
本記事は人工知能により作成され、人間の編集管理のもとで校閲されています。
AI's speed in finding vulnerabilities is impressive, but how will it handle false positives? Accuracy is key.
False positives could be mitigated by combining AI with human expertise for validation.
Great point, but also consider the ethical implications of AI finding vulnerabilities before developers can patch them.
This is fascinating! I wonder how AI will impact the job market for security researchers in the long run.
AI's role in finding vulnerabilities is exciting, but we must ensure it doesn't outpace our ability to patch them responsibly.
We need clear guidelines on AI's role in vulnerability disclosure to prevent misuse.
It's crucial to balance AI's speed in finding flaws with our capacity to fix them ethically.
Incredible how AI is democratizing vulnerability discovery. But what about the potential for misuse by malicious actors?
This is a significant development. I wonder how AI will change the dynamics of bug bounty programs and the roles of human researchers.
This is a game-changer. I hope AI can help us find vulnerabilities faster, but I'm concerned about the ethical implications of such powerful tools.
Wow, that's a huge payout for a vulnerability found with AI. I wonder how secure our websites really are if this is the future of exploitation.
Interesting find, but I wonder about the long-term implications for cybersecurity jobs if AI can outperform humans so easily.
This is fascinating, but I wonder how this will impact the vulnerability disclosure process and the relationship between researchers and platforms.
This is a game-changer. I wonder how long until AI becomes the standard for vulnerability research.
Accès contrôlé aux modèles de pointe : habilitation, clés matérielles, juridictions