Google 披露 AI 安全代理 PageBreak,已发现逾 500 个漏洞

链捕手
Yesterday

ChainCatcher 消息,Google 产品安全团队披露内部 AI 代理 PageBreak,用于测试其第一方 Web 应用的安全性。该代理基于 Google 的 Gemini 模型构建,于 2025 年 11 月启动试点,2026 年 1 月转为正式项目,目标是自主扩大漏洞发现规模并减少人工投入。

与常见的 AI 扫描工具不同,PageBreak 在发现可疑缺陷后,会将假设交给专门的验证器,在实时运行的应用副本中尝试实际利用,只有确认可利用后才上报,误报率接近零。Google 称,PageBreak 已在其第一方 Web 应用中找出超过 500 个 XSS 漏洞,此类漏洞可被用于劫持登录会话、窃取数据或冒充用户。

Google 表示,安全团队近年来被大量由 AI 生成、看似合理却并不成立的漏洞报告淹没,分辨真实缺陷与幻觉已成为主要难题。在针对采用新一代高保障框架构建的应用进行测试时,PageBreak 仅发现两个漏洞。下一步 Google 计划将 PageBreak 与自动修复代理 CodeMender 对接,使已确认的漏洞附带修复方案。

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10