Google's OSS-Fuzz with AI Finds Critical OpenSSL Bug After Two Decades

 Google's AI-powered OSS-Fuzz tool has uncovered 26 previously unknown vulnerabilities in open-source software, including a critical flaw in OpenSSL (CVE-2024-9143) that existed undetected for 20 years. Leveraging large language models (LLMs) like Vertex AI Codey and OpenAI's models, OSS-Fuzz automates the creation and improvement of fuzz targets, significantly enhancing its bug-finding capabilities.

The AI-driven enhancements have improved code coverage for 272 C/C++ projects, identifying vulnerabilities such as out-of-bound reads and writes. Google plans to further automate this system, aiming to autonomously identify, report, and triage bugs in open-source projects

https://thehackernews.com/2024/11/googles-ai-powered-oss-fuzz-tool-finds.html

Comments

Popular posts from this blog

Endor Labs Announces Integrated SAST Offerings

OWASP Releases Enhanced Dependency-Check Tool with Advanced Tagging and Policy Management Features

The Hidden Cost of DevSecOps: Time and Financial Burden of Security on Developers