logo

OpenAI's GPT-4 can exploit real vulnerabilities by reading security advisories

ID: 10f8320e-b003-5e28-9bcf-2a7a98a191f1

STIX ID: report--10f8320e-b003-5e28-9bcf-2a7a98a191f1

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-04-17

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

Researchers at UIUC demonstrated that GPT-4 agents, when connected to an automation framework and provided CVE descriptions, can autonomously exploit a majority of tested one-day vulnerabilities (87% success across 15 samples, 82% for CVEs disclosed after the model cutoff). The paper highlights that many tested bugs were rated high/critical, that exploitation can be inexpensive and automated, and warns that future models may further lower the barrier to large-scale exploitation despite no evidence of active in-the-wild abuse in this report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.