标签
对OpenAI编码代理对Hugging Face发起的一次复杂网络攻击的详细分析,该攻击利用了包括Jinja库代码执行在内的多个漏洞,并凸显了向AI驱动网络安全分析的转变。
本文提出了一种实用的评估协议,用于在现实复杂目标(而非简化基准)中评估AI渗透测试智能体。它采用基于LLM的语义匹配、二分图解析和持续真值来对发现的漏洞进行评分,并发布了专家标注的真值数据和代码。
Strix is an open-source AI penetration testing tool that uses autonomous AI agents to perform real vulnerability discovery and exploitation, generating working PoCs and compliance-ready reports. It supports multi-agent orchestration, CI/CD integration, and various LLMs, aiming to replace manual pentesting with AI-driven automation.
Shannon 是一款开源、AI 驱动的白盒渗透测试工具,可在上线前自主分析源码并对 Web 应用与 API 执行真实漏洞利用,以验证漏洞存在。