Anthropic is finding bugs faster than Microsoft can fix them

Anthropic is finding bugs faster than Microsoft can fix them

Anthropic 发现漏洞的速度快于微软的修复速度

On an afternoon in mid-May, dozens of Microsoft engineers and their managers gathered online and in a conference room at the company’s Redmond, Washington, headquarters to discuss Project Glasswing. The tech giant was racing to fix weaknesses in its code that a new AI model known as Mythos was uncovering at an unprecedented clip.

五月中旬的一个下午,数十名微软工程师及其经理通过线上和线下方式,聚集在位于华盛顿州雷德蒙德的公司总部,讨论“玻璃翼计划”(Project Glasswing)。这家科技巨头正争分夺秒地修复其代码中的漏洞,而一款名为“Mythos”的新型人工智能模型正以史无前例的速度挖掘出这些漏洞。

The AI behemoth Anthropic, which developed Mythos, had given access to select organizations that make software used by regular people, companies, and governments across the world. The goal was to find and fix the vulnerabilities before hackers and adversarial governments like China began using similar tools to find and exploit them for espionage and sabotage.

开发 Mythos 的人工智能巨头 Anthropic 已向部分机构开放了访问权限,这些机构所开发的软件被全球各地的普通用户、企业和政府所使用。其目标是在黑客和中国等敌对国家的政府开始利用类似工具进行间谍活动和破坏之前,发现并修复这些漏洞。

As the group settled in, one engineer asked the question that loomed over the meeting: Did Mythos “live up to the hype that Anthropic claimed it would have had?” “Yes,” a manager responded, according to a recording of the meeting viewed by ProPublica. The version being used by Microsoft, Claude Mythos Preview, was surfacing bugs faster than the tech giant could patch them, and engineers, the manager said, were now in “a mad dash” to close the gap.

会议开始后,一名工程师提出了笼罩在整个会议之上的核心问题:Mythos 是否“达到了 Anthropic 所宣称的那种炒作效果?”据 ProPublica 查看的会议录音显示,一位经理回答道:“是的。”微软所使用的版本——Claude Mythos Preview——发现漏洞的速度超过了这家科技巨头修复漏洞的速度,该经理表示,工程师们现在正处于“疯狂冲刺”状态,试图缩小这一差距。

One slide in that day’s presentation showed that in April alone, Mythos had uncovered 90 “critical” bugs and 141 “important” ones in SharePoint, Microsoft’s widely used collaboration software. In the first half of May it found even more. “Please, please, please if your org has any April bugs, drive those down,” engineering manager Hans Andersen implored the group. They had roughly two weeks “to find as many things and do as much good as we can with this access.”

当天演示文稿中的一张幻灯片显示,仅在四月份,Mythos 就在微软广泛使用的协作软件 SharePoint 中发现了 90 个“严重”漏洞和 141 个“重要”漏洞。在五月上半月,它发现的漏洞数量更多。工程经理汉斯·安德森(Hans Andersen)恳求团队:“拜托,拜托,如果你们的部门还有四月份遗留的漏洞,请务必尽快解决。”他们大约有两周的时间,“利用这次访问权限尽可能多地发现问题,并尽可能多地做出贡献。”

May 31, he explained, “is considered the day when the rest of the world will have caught up.” The engineers on the call poked at that assertion, with one of them summing up the predicament: “So basically you’re saying if it’s released on June 1, then on June 2 the adversaries will have our bugs?” Yep, one person responded. Yep, another echoed.

他解释说,5 月 31 日“被认为是世界其他地区赶上来的日子”。参会的工程师们对这一说法提出了质疑,其中一人总结了这种困境:“所以你基本上是说,如果它在 6 月 1 日发布,那么 6 月 2 日敌对势力就会掌握我们的漏洞?”“是的,”一人回答道。“没错,”另一人附和道。

Ever since Anthropic kick-started a national conversation about the bug-hunting power of AI in April, when Project Glasswing was made public, national security experts predicted that the US would have a window of opportunity to fix flaws before adversaries would have similar models capable of discovering the same weaknesses. In late June, the international alliance of intelligence agencies known as the Five Eyes—whose members are the US, Australia, Canada, New Zealand and the UK—warned in an unusual joint statement that in a matter of months, that window would be closing.

自四月份“玻璃翼计划”公开,Anthropic 引发了关于人工智能漏洞挖掘能力的全国性讨论以来,国家安全专家就预测,美国将有一个机会窗口期来修复漏洞,在此之前,敌对势力尚无法拥有能够发现同样弱点的类似模型。六月下旬,被称为“五眼联盟”的国际情报机构联盟(成员包括美国、澳大利亚、加拿大、新西兰和英国)在一份罕见的联合声明中警告称,这个窗口期将在几个月内关闭。

But the recording of the Microsoft meeting, along with internal documents reviewed by ProPublica, suggest the day of cyber reckoning may already be here. Given the deluge of flaws Mythos has identified, Microsoft so far has focused on patching those it considers most dangerous, which are classified critical or important, according to the presentation as well as the company’s own public patch updates.

然而,微软会议的录音以及 ProPublica 查看的内部文件表明,网络清算之日可能已经到来。鉴于 Mythos 识别出的漏洞如潮水般涌现,根据演示文稿及公司公开的补丁更新,微软目前主要专注于修复其认为最危险的漏洞,即被归类为“严重”或“重要”的漏洞。

The internal records indicate that Microsoft plans to eventually address “moderate”-severity flaws uncovered by Mythos. The documents made no mention of “low”-severity bugs. The company’s approach reflects the triage system that is typical in the industry. Just as the sickest patients are the first to be treated in the emergency room, vulnerability triage prioritizes issues that are likely to cause the most damage if exploited by hackers.

内部记录显示,微软计划最终处理 Mythos 发现的“中等”严重程度的漏洞。文件中未提及“低”严重程度的漏洞。该公司的做法反映了行业内典型的分类(Triage)系统。正如急诊室会优先救治病情最重的病人一样,漏洞分类优先处理那些一旦被黑客利用就可能造成最大损害的问题。

But that strategy carries its own risk in this AI-powered bug-finding era, in which new tools are unearthing a record-breaking volume of weaknesses in the products we use every day. Mythos, for example, is able to chain together a string of bugs that build on one another, meaning that the low- and moderate-severity vulnerabilities that remain unpatched could create an opening to carry out devastating attacks.

但在人工智能驱动的漏洞挖掘时代,这种策略本身也存在风险,因为新工具正在我们日常使用的产品中挖掘出创纪录数量的弱点。例如,Mythos 能够将一系列相互关联的漏洞串联起来,这意味着那些未修复的低严重程度和中等严重程度的漏洞,可能会为实施毁灭性攻击创造机会。

“The problem now is that you can chain four low-level flaws, and that can equal a high severity,” said Vinh Nguyen, a senior technical adviser to Anthropic and a senior fellow for AI at the Council on Foreign Relations who formerly served as chief AI officer and chief data scientist at the National Security Agency. “If you’re Microsoft, the current triage strategy may be underpricing risks.”

“现在的问题是,你可以将四个低级别漏洞串联起来,其危害程度可能等同于一个高级别漏洞,”Anthropic 高级技术顾问、外交关系委员会人工智能高级研究员、曾任美国国家安全局首席人工智能官和首席数据科学家的 Vinh Nguyen 表示。“如果你是微软,当前的分类策略可能低估了风险。”

In emailed responses to ProPublica’s questions, Microsoft stood by its approach, saying its triaging decisions are based on a number of factors, including exploitability and the impact on customers. The company presentation did not mention chaining, but a spokesperson told ProPublica that the technique “has long been considered as part of vulnerability assessment and risk analysis.”

在回复 ProPublica 提问的电子邮件中,微软坚持其做法,称其分类决策基于多种因素,包括可利用性和对客户的影响。公司演示文稿中未提及“串联”技术,但一位发言人告诉 ProPublica,该技术“长期以来一直被视为漏洞评估和风险分析的一部分”。

Asked about the internal presentation and the then-looming May 31 deadline, the spokesperson downplayed its significance, saying that “accelerated targeting and exploitation of new vulnerabilities is not a new phenomenon.” That said, he added, the comments made during the meeting reflect how the company “feels a sense of urgency to help our customers at this time.”

当被问及内部演示文稿和当时临近的 5 月 31 日截止日期时,该发言人淡化了其重要性,称“针对新漏洞的加速定位和利用并不是什么新鲜事”。但他补充说,会议期间的评论反映了公司“在当前时刻帮助客户的紧迫感”。

“What was heard on that call and is true today is that security is Microsoft’s most important priority and teams across the company are prioritizing using AI to discover and remediate vulnerabilities as quickly as possible.” Microsoft declined to answer questions about how many bugs engineers had patched since the presentation. Anthropic declined to comment.

“在那次通话中听到的内容,以及今天的事实是,安全是微软最重要的优先事项,公司各团队正优先利用人工智能尽可能快地发现和修复漏洞。”微软拒绝回答自演示以来工程师修复了多少漏洞的问题。Anthropic 拒绝置评。

The internal Microsoft presentation and accompanying slides predicted that the group of staffers working on SharePoint, which is used by governments and businesses worldwide to manage data and documents, “will be busy for months,” first working through the highest-priority critical bugs, then tackling the important ones in August. Microsoft says vulnerabilities it categorizes as critical include so-called worms that can crash systems and spread malware as they race across computer networks. Important ones could result in “compromise of the confi…”

微软的内部演示文稿及随附幻灯片预测,负责 SharePoint(全球政府和企业用于管理数据和文档的软件)的员工团队“将在未来几个月内非常忙碌”,首先要解决优先级最高的严重漏洞,然后在八月份处理重要漏洞。微软表示,其归类为“严重”的漏洞包括所谓的“蠕虫”,它们可以在计算机网络中传播时导致系统崩溃并扩散恶意软件。而“重要”漏洞则可能导致“机密信息的泄露……”