Apple struggles to keep pace with AI ‘bug’ hunters - FT中文网
登录×
电子邮件/用户名
密码
记住我
请输入邮箱和密码进行绑定操作:
请输入手机号码,通过短信验证(目前仅支持中国大陆地区的手机号):
请您阅读我们的用户注册协议隐私权保护政策,点击下方按钮即视为您接受。
FT商学院

Apple struggles to keep pace with AI ‘bug’ hunters

iPhone maker has limited the number of vulnerabilities researchers can submit to manage wave of reports
00:00

{"text":[[{"start":9.04,"text":"Apple has restricted the number of potentially dangerous software bugs researchers can submit to its internal security team, as it faces a deluge of reports from people using AI models to identify alleged risks."}],[{"start":21.3,"text":"The Cupertino-based tech giant told the FT it had moved in June to limit the high volume of requests it was receiving, with its review system coming under pressure from “AI slop” reports that can hallucinate security risks in its software."}],[{"start":35.12,"text":"Apple is grappling with an industry-wide phenomenon that has resulted in generative AI software tools transforming the cyber security arms race, with an increase in the detection of real security flaws and a wave of poor-quality submissions from amateur bug hunters using AI, the company said."}],[{"start":52.34,"text":"The change in Apple’s approach was highlighted by Italian cyber security start-up Bynario, which told the FT it had used OpenAI’s ChatGPT to identify more than 50 bugs in the latest version of the MacBook operating system in just three weeks."}],[{"start":67.04,"text":"Among them was one of the most serious types of vulnerability, a so-called privilege escalation exploit chain, which could allow an attacker to seize full control of an Apple computer by gaining unrestricted access to the system."}],[{"start":79.08,"text":"However, the start-up said it was unable to alert Apple to the vulnerability because the tech giant had limited the number of bug reports it could make."}],[{"start":86.84,"text":"“It is a very difficult time in the industry,” Bynario chief executive and co-founder Alfredo Pesoli said. “Maintainers and vendors have been flooded by the sheer amount of bugs [being found].”"}],[{"start":98.6,"text":"Apple told the FT that it was now in contact with Bynario and reviewing its submissions."}],[{"start":103.68,"text":"The company has introduced a cap and a 30-day cool-off period on submissions through its internal security portal, requiring users to submit requests for an increased quota. Each alleged security breach requires human review to confirm, although Apple is also using AI internally to help triage the massive upsurge."}],[{"start":121.16,"text":"“With the growing volume of AI-generated security submissions across the industry, we recently adjusted the number of new reports a researcher can have open at once,” Apple said in a statement."}],[{"start":131.68,"text":"Researchers “can easily request an increase to that limit at any time to ensure critical reports reach our security teams,” the company continued."}],[{"start":138.92,"text":"Bynario, a seven-person start-up founded in Milan last year, develops defensive cyber security software. Three of its other co-founders previously worked at Hacking Team, the Italian surveillance software company whose hacking tools were leaked in a 2015 cyber attack."}],[{"start":155.76,"text":"In 2025, Bynario reported eight vulnerabilities to Apple, one of which was patched in a software update in November. This year it said it had reported five more, before Apple’s system refused further submissions."}],[{"start":170.14,"text":"The privilege escalation exploit Bynario was unable to report is the latest example of AI exposing weaknesses in Apple’s security systems, despite the company’s longstanding emphasis on privacy and device security."}],[{"start":183.12,"text":"Last September Apple announced Memory Integrity Enforcement, a security feature designed to prevent memory corruption attacks, one of the most common ways hackers compromise software. The company described it as “the most significant upgrade to memory safety in the history of consumer operating systems”."}],[{"start":199.8,"text":"Eight months later, researchers at Palo Alto-based Calif said they had found a way past the new security, having used Anthropic’s Mythos to identify the first memory corruption exploit on the latest software."}],[{"start":211.2,"text":"Unlike that attack, Bynario’s exploit relied on so-called logic flaws, by manipulating trusted software into carrying out a sequence of otherwise legitimate actions in an unintended order. Pesoli estimated that an exploit of this type could fetch between $100,000 and $200,000 on the cybercriminal black market."}],[{"start":231.04,"text":"Apple last year introduced a new bug bounty award mechanism that could pay out as much as $5mn for identifying the most serious and sophisticated category of threats to its software."}],[{"start":241.52,"text":"Apple is also using AI to strengthen its software. In security updates released this week for its operating systems, the company credited tools from Anthropic and OpenAI with helping identify a number of vulnerabilities across its devices."}],[{"start":254.7,"text":"The updates included around five times as many security fixes as previous release cycles, underlining how rapidly AI is reshaping both attack and defence in cyber security."}],[{"start":265.44,"text":"The challenge for all software companies is that AI is having a “dual impact” on bug hunting, making it easier for amateur sleuths to submit speculative reports and for skilled researchers to find dangerous exploits, said Rafe Pilling, director of threat intelligence at cyber security firm Sophos."}],[{"start":281.88,"text":"“The result is that bug bounty programmes are shifting from a problem of finding vulnerabilities to a problem of validating, prioritising and responding to them at machine speed.”"}],[{"start":282.38,"text":"Additional reporting by Stephen Morris in Diablo"}],[{"start":296.9,"text":""}]],"url":"https://audio.ftcn.net.cn/album/a_1785648160_5448.mp3"}

版权声明:本文版权归FT中文网所有,未经允许任何单位或个人不得转载,复制或以任何其他方式使用本文全部或部分,侵权必究。

气候如何推动新的地缘战略?

环境变化正在重塑贸易、商业、物流和地缘政治。

“全民分担”的金融危机仍是危机

私募信贷与保险业的联姻热潮可能暗藏代价。

一周展望:美国通胀对债市的扰动有多大?

由于对美国40万亿美元的国家债务以及大量AI债券发行感到担忧,美国30年期借款利率已升至2007年以来的最高水平。

特朗普冷落韩国引发亚太地区诸多疑问

缩减军事演习削弱了人们对美国可靠性的信心。

穆罕默德与赫蒂彻:一段美满婚姻

一桩持续25年的阿拉伯商业联姻。

中国企业加大AI投资,阿里巴巴拟配股筹资102亿美元

在最新通义千问3.8-Max模型广受好评后,该公司发行新股融资。
设置字号×
最小
较小
默认
较大
最大
分享×