Breaking
April 30, 2025

Vulnerability exploitation: The dangers of the open LLM model boom | usagoldmines.com

For a software vendor, telling the world about the latest security vulnerability is always a delicate balancing act. Customers need information quickly, starting with the flaw’s severity rating and whether it is severe enough to allow for remote exploitation. But they are not the only people listening, which is why care needs to be taken with the information disclosed. Criminals, too, pay close attention to public alerts, looking for any clue that might help them create a successful exploit for a vulnerability before it is patched.

This is cybersecurity’s quiet war, fought every day across dozens of vulnerability disclosures. Attackers want to understand and write exploits for flaws as quickly as possible while defenders want to prioritize, mitigate and patch them just as fast. If the attackers triumph every now and again, it remains the case that good patching routines and threat detection keep the bad guys out most of the time.

The dangers of local models

The bad news is that thanks to developments in AI this is changing. We’re still in the early days of offensive AI techniques and tools, but already it is having a disruptive effect across multiple threat types. Unfortunately, that includes using local or offline generative pre-trained transformer (GPT) models as a way of accelerating and automating exploit creation.

Since DeepSeek released its open and resource friendly, but very competitive and capable model, we are now standing at the advent of a potential open model boom. This movement brings new and evolving risks, where criminals can adapt open pre-trained models, easily downloadable across the Internet, and run them locally on modest PCs with GPUs.

Operating without the guardrails typically found in their commercial online counterparts, local spinoffs can then be created and fine-tuned using data collected from malicious software research and underground forums. What you end up with are specialized crime AI platforms that can be offered as a subscription service or the backend of AI agent system for automating attack campaigns. The weaponized platforms can be specifically designed to make writing malware – or creating exploits based on vulnerability disclosures – a more automated and therefore much faster process.

The modus operandi won’t succeed every time, but for criminals, success is always a percentages game. Across possibly hundreds of threat actors, successful exploits could be written on a scale that will dramatically increase the likelihood of eventually uncovering a working exploit.

The threat here isn’t theoretical. The proof of concept is that black hat AI models, such as FraudGPT and WolfGPT, have been around since 2023. Moreover, researchers demonstrated the ability of a single LLM agent backed by GPT-4 to exploit one-day vulnerabilities in April 2024. Today, an organization might still assume it has 24-48 hours to mitigate or patch a significant vulnerability before the risk of exploits in the wild begins to rise. The advent of local pre-trained models coupled to AI agents for automation are transforming this. Instead of days to patch, organizations are looking at minutes.

Fighting AI with AI

This much is certain: no organization can patch their systems in minutes, at least not using today’s processes based on manual decision making. But let’s not panic. Vulnerability exploits written by AI are just the latest incarnation of an unceasing threat evolution. The answer is the same as it always has been – the defenders must evolve, too.

Just as attackers can use AI agents to create exploits quickly, so defenders can deploy the same technology to process new vulnerability alerts in real time, rapidly implementing security mitigations that might be required. In many ways, this is the perfect example of how today’s defenses could soon become a battle of our AI versus their AI.

If attackers have the advantage of time and the volume, defenders have the benefit of knowledge. Agentic AI tuned to understand the environment it is defending will always know more about the network it is protecting than the AI probing it. Meanwhile, attacks targeting exploits are not necessarily getting more sophisticated, but merely faster and more frequent. It is the speed attackers can throw exploits at defenders that is dangerous, not the quality of those exploits. If defenders can match them on this metric, all is not lost.

What we shouldn’t do is become alarmed. The fact that attackers look for vulnerabilities is not new. AI is just the latest technology in a long line that can be put to malicious use. But this capability cuts both ways. Defending against AI-developed exploits will be challenging but developments such as agentic AI automation will also be our friend.

We’ve featured the best malware removal software.

This article was produced as part of TechRadarPro’s Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Best laptops: Our experts pick the top 12 models | usagoldmines.com

Best gaming monitors 2025: Level up your display | usagoldmines.com

Android 16 Teases Secret UI Update That Should Bring Fresh Beauty, Tons of Blur Kellen | usagoldmine...

Samsung Mentions New Foldables, Galaxy Watch With ‘Innovative Design’ During Earnings Call Tim | usa...

Update Your Apple Devices Now to Keep Them Safe From New AirPlay Vulnerability Khamosh Pathak | usag...

The Samsung M8 Is a Smart Monitor and TV in One, and It’s $300 Off Right Now Daniel Oropeza | usagol...

I Started Customizing My Steam Deck Controls, and It Was a Literal Game Changer Eric Ravenscraft | u...

Apple Warns More Users About Mercenary Spyware Attacks Juli Clover | usagoldmines.com

Google is working on a Gemini AI app for kids erichs211@gmail.com (Eric Hal Schwartz) | usagoldmines...

Windows RDP lets you log in using revoked passwords. Microsoft is OK with that. Dan Goodin | usagold...

Sundar Pichai says DOJ demands are a “de facto” spin-off of Google search Ryan Whitwam | usagoldmine...

Research roundup: Tattooed tardigrades and splash-free urinals Jennifer Ouellette | usagoldmines.com

Raspberry Pi cuts product returns by 50% by changing up its pin soldering Kevin Purdy | usagoldmines...

Windows RDP lets you log in using revoked passwords. Microsoft is OK with that. Dan Goodin | usagold...

You Can Get the Nix Mini 3 Color Sensor on Sale for Just $80 Right Now Pradershika Sharma | usagoldm...

Six Signs Your Bank Is About to Fail (and What to Do About It) Jeff Somers | usagoldmines.com

Here's What's New in the Latest Nintendo Switch Update Jake Peterson | usagoldmines.com

Google CEO Says Antitrust Remedies Would Cripple Google Search Juli Clover | usagoldmines.com

Samsung confirms 2025 release for its first Android XR device – here are 3 things I want to see from...

Data centers in China are dumping rare 48GB Nvidia RTX 4090D GPUs for nearly $6,000, but the exact r...

First Slate Auto and now Isuzu – why electric pick-up trucks could be the next big EV battleground ...

SK Telecom offers free SIM cards to customers after data breach | usagoldmines.com

YouTube just got a big TV app upgrade – here are 9 new time-saving improvements mark.wilson@futurene...

NASA just swapped a 10-year-old Artemis II engine with one nearly twice its age Stephen Clark | usag...

Millions of Apple Airplay-enabled devices can be hacked via Wi-Fi Lily Hay Newman and Andy Greenberg...

RFK Jr.’s anti-vaccine stance is rooted in a disbelief in germ theory Beth Mole | usagoldmines.com

Intel ‘Lunar Lake’ handhelds, laptops are getting a free gaming boost | usagoldmines.com

Android Users Can Now Edit Photos, Videos in Shared Albums Tim | usagoldmines.com

My Favorite Amazon Deal of the Day: The New M3 iPad Air Daniel Oropeza | usagoldmines.com

After convincing senators he supports Artemis, Isaacman nomination advances Eric Berger | usagoldmin...

Nintendo imposes new limits on sharing for digital Switch games Kyle Orland | usagoldmines.com

CBS owner ready to settle Trump lawsuit in apparent bid to get merger approved Jon Brodkin | usagold...

Get the latest Surface Laptop with Snapdragon for $599 | usagoldmines.com

Beyond Speedtest: Orb gives you a holistic look at Internet performance | usagoldmines.com

Wednesday Poll: You Can Bring Back an ‘Old Phone’ Feature, What’s It Gonna Be? Tim | usagoldmines.co...

Samsung Slaps $230 Off Galaxy S25 Ultra Without Trade-in Kellen | usagoldmines.com

The Best Running Shoes for Every Type of Runner Meredith Dietz | usagoldmines.com

Five Unexpected Ways Your Home Renovation Can Backfire Jeff Somers | usagoldmines.com

You Can Get a Three-Year License for Photoshop Elements 2025 for $100 Right Now Pradershika Sharma |...

Mother's Day Deals: Save on AirPods, Apple Watch Bands, Travel Chargers, iPhones, and More Mitchel B...

Bookmark Multiple Tabs in Safari on iPhone Tim Hardwick | usagoldmines.com

Google CEO Suggests iOS 19 Will Feature Built-In Gemini Integration Joe Rossignol | usagoldmines.com

Third US Plant Set to Make Apple Chips Breaks Ground Hartley Charlton | usagoldmines.com

Shark goes for broke and straps a water tank onto its latest fan so it can blast you with cool mist ...

Co-op fending off hackers by shutting down IT systems | usagoldmines.com

Intel’s latest boasts about its integrated graphics makes me less excited for the Nintendo Switch 2 ...

Google CEO hopeful Gemini will be integrated into Apple Intelligence in time for iPhone 17 launch jo...

Proton Mail hit with blocking order in India - here's everything we know so far chiara.castro@future...

'You see the sparkle in her eye again': Andor star Adria Arjona on Bix's cathartic tale of revenge i...

Trump admin accuses Amazon of partnering with 'a Chinese propaganda arm' over tariff listing talk |...

Are chatbot outputs protected speech? Court pressured to clarify. Ashley Belanger | usagoldmines.com

Companies don’t call anymore—only scammers. Stop picking up! | usagoldmines.com

Microsoft targets pesky bugs plaguing the classic Outlook app | usagoldmines.com

Declutter your work space with this mighty mini PC for $150 off | usagoldmines.com

Windows 7 took forever to load if you had a solid background. Now we know why | usagoldmines.com

Fast, sleek, and just $60: The SK Hynix Tube is practically an external SSD | usagoldmines.com

Microsoft CEO claims 30% of its new code is written by AI | usagoldmines.com

This slim 100W laptop power bank is just $40 right now | usagoldmines.com

MSP360 Backup review: Very effective local backup — and free file backup! | usagoldmines.com

Acer’s new esports gaming monitor hits a blistering 600Hz | usagoldmines.com

Rejoice! WhatsApp users will finally be able to make calls from the web | usagoldmines.com

Samsung Sends One UI 7 Update to Galaxy Tab S8, Tab S9, and Tab S10 in US Kellen | usagoldmines.com

This One-Year Subscription to Adobe Lightroom Is on Sale for $120 Right Now Pradershika Sharma | usa...

Meta, Spotify, and Match Launch Coalition Against Apple and Google Hartley Charlton | usagoldmines.c...

Microsoft developing fixes for multiple Outlook and SharePoint Online bugs and outage | usagoldmine...

SentinelOne targeted by Chinese espionage campaign probing customers and infrastructure | usagoldmi...

I loved LG phones because they were affordable, risky, and weird – and the smartphone world could us...

Cronos: The New Dawn developers reveal that it will take around 18 hours to beat dash.wood@futurenet...

These Pixel Earbuds Are $60 Right Now Pradershika Sharma | usagoldmines.com

Mango Languages Is an Alternative to 'AI-First' Duolingo, and It's Free at Libraries David Nield | u...

TSMC committed to Arizona chip plant ahead of potential tariff impact | usagoldmines.com

I'm excited for two very different school-themed horrors after seeing the trailers for Weapons and F...

Exposed Git tokens and secrets are being hoovered up by hacker scans | usagoldmines.com

Quordle hints and answers for Thursday, May 1 (game #1193) | usagoldmines.com

NYT Strands hints and answers for Thursday, May 1 (game #424) | usagoldmines.com

NYT Connections hints and answers for Thursday, May 1 (game #690) | usagoldmines.com

Samsung says a 'dimmer' OLED TV appears just as bright as a 'brighter' LED model, but that misses th...

Uncovering common CDN myths | usagoldmines.com

Samsung Galaxy Z Fold 7 rumored specs: predictions for every key spec | usagoldmines.com

The biggest PC builder regrets: 6 fatal mistakes to avoid! | usagoldmines.com

USB flash drives are going extinct. Use these alternatives instead | usagoldmines.com

ADT and Yale partner on Z-Wave lock with fingerprint recognition | usagoldmines.com

Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com

The 60 Best 2000s Movies You Can Stream Right Now Ross Johnson | usagoldmines.com

Android’s Default Keyboard Is Hiding a Secret Superpower Eric Ravenscraft | usagoldmines.com

iPhone 17 Air USB-C Port May Have This Unusual Design Quirk Tim Hardwick | usagoldmines.com

Case dismissed – Windscribe wins landmark no-log VPN lawsuit in Greece chiara.castro@futurenet.com (...

'Our existing subscriptions are plenty enough for us': Spotify CEO seems to pour water on mooted 'Su...

'Nothing else to live for': Andor season 2 star Faye Marsay breaks down episode 6's soul-crushing mo...

Rushed AI deployments and skills shortages are putting businesses at risk | usagoldmines.com

Republicans want to tax EV drivers $200/year in new transport bill Jonathan M. Gitlin | usagoldmines...

Millions of Apple AirPlay devices susceptible to 'AirBorne' zero-click RCE attacks, so patch now | ...

Reddit users give their verdicts on new ChatGPT shopping features: ‘the enshittification has arrived...

The Star Wars: Tales of the Underworld TV show premiere will take place in Fortnite, and you're invi...

Marvel Rivals patch notes: the latest balance changes and updates | usagoldmines.com

A24's The Smashing Machine trailer is a knockout but you can't stream the original documentary anywh...

Experts warn of heatwave danger to routers, so act now before summer kicks in and temperatures could...

75 zero-day exploitations spotted by Google, governments increasingly responsible for attacks | usa...

The end of an AI that shocked the world: OpenAI retires GPT-4 Benj Edwards | usagoldmines.com

Google Pixel 10 likely to get a display upgrade that makes it kinder on your eyes | usagoldmines.co...

Leave a Reply