Desk/2024-W47

Week of Nov 18–24, 2024

2 records0 status changes on new evidence0 new findings

Defense & research

Nov 20, 2024
OSS-Fuzz AI-generated fuzz targets find 26 vulnerabilities, including OpenSSL CVE-2024-9143
DefenseTool releaseGoogle Open Source Security Team, OpenSSL

Google reports that AI-generated and AI-enhanced fuzz targets in OSS-Fuzz found 26 new vulnerabilities in projects that already had extensive fuzzing, including CVE-2024-9143 in OpenSSL. The LLM workflow drafts targets, fixes compilation errors, fixes runtime issues and triages crashes, and gained coverage in 272 C/C++ projects.

Policy & standards

Nov 22, 2024
Frontier Model Forum issue brief maps defensive uses of frontier AI in cybersecurity
PolicyGuidanceFrontier Model Forum

The Frontier Model Forum, an industry body of frontier labs, published an issue brief on using frontier AI for cyber defense. It lists use cases including process automation for incident response, natural-language querying and analysis, vulnerability discovery and fixing, open-source intelligence and training, and recommends designing for human-AI collaboration rather than full automation.