티스토리 뷰
AI is Finding the Holes in Your Apps and Websites First? The Security Vulnerabilities Even Google and Firefox Didn't Know About
실더 2026. 5. 27. 21:00
The Apps I Use Actually Have Tons of Security Holes
Imagine getting a text from your bank app one day saying "A transfer of 1.5 million dollars has been made from your account." I'm serious. This isn't a movie plot. There was actually a real case recently where a bank partner company caught this exact scam thanks to AI.
You'd think companies like Firefox, Cloudflare (basically the massive infrastructure service that keeps the internet running fast and secure behind the scenes), and Microsoft would have airtight security, right? Well, that wasn't the case at all.
Firefox alone had 271 security vulnerabilities discovered all at once, and Cloudflare had a whopping 2,000 bugs. Think of a vulnerability like an "open window that hackers can sneak through." I got the chills when I first heard there were that many windows. No joke.
Wait, AI Finds Security Holes Before Hackers?
An AI company called Anthropic started something called 'Project Glasswing.' Sounds unfamiliar, right? Glasswing is actually a type of butterfly with transparent wings, and the name seems to mean "invisible on the surface but completely see-through inside." Here's the key point: instead of waiting for bad actors (hackers) to find vulnerabilities, AI discovers and patches those holes first.
The AI model used in this project is called 'Claude Mythos Preview.' This AI doesn't just read code—it actually simulates multi-stage attacks like a real hacker would. It went through testing in what's called a "cyber range," a simulated hacking training ground. This is actually the first time an AI has passed multi-stage simulations like this.
Want to see how much it found in just one month?
| Target | Vulnerabilities Found | Notable Points |
|---|---|---|
| Cloudflare | 2,000 (400 high-risk) | Bug discovery speed increased 10x or more |
| Firefox | 271 | 10x better performance than existing AI |
| 1,000+ Open-Source Projects | 6,202 (high-risk) | Discovered through automated scanning |
| All Partners (about 50 companies) | 10,000+ | Achieved within 1 month |
A really dangerous vulnerability was also found in something called wolfSSL, an encryption library (the component used by banks and financial apps to encrypt communication). If hackers exploited this, they could create fake authentication certificates to make a phishing website look like the real thing. In other words, that website you thought was your real bank could actually be a fake site made by hackers. Pretty creepy, right?
But What Does This Have to Do With Me?
You might be thinking, "I'm not a developer and I don't know anything about code—how is this my problem?" But here's the thing: it really is your problem. Every app you open daily, every site you log into, every banking app you use to transfer money, even your kid's school notification app—they all run on top of these security components.
There's one really good thing that comes out of this project: security holes can be blocked before hackers discover them. Usually when a vulnerability is found, the developer releases a "patch" (security update), but thanks to AI, this process is now 10 times faster or more. We all know how annoying app update notifications are and put them off, right? But you should know that those updates might contain fixes for these serious security holes.
There is one unfortunate downside, though. AI is finding holes so fast that developers can't keep up with reviewing and fixing them all. Especially since most open-source project managers are volunteers running things on limited resources. That's definitely something we need to tackle going forward.
What I Can Do Right Now
You might think "Well, that's all about what the developers do. There's nothing I can do, right?" Wrong. There absolutely is something you can do. And honestly, this is the most important part. I'm not talking about anything fancy—just everyday habits.
Frequently Asked Questions
A. By the time news breaks about a vulnerability, a patch is usually already out or coming very soon. When you see the news, update to the latest version of the app. If there's no update available yet, it's safer to avoid using it for a bit. Projects like Glasswing follow a principle of disclosing vulnerabilities within 90 days while also releasing patches, so you're protected on both ends.
A. That's a really important point, and you're absolutely right. Honestly, AI is a double-edged sword. It can be misused. That's actually the core goal of the Glasswing project: "Let the good AI find it first before the bad AI can exploit it." Think of it like a race where the good side has to stay ahead. It's not a perfect solution, but it's the most realistic response we have right now.
Today's topic might have felt a bit heavy. Honestly though, reading about this actually made me feel a little reassured. It feels like someone is already working hard to find and patch the holes in the apps I use before I even know about them. It won't be perfect, of course. There's only one thing we need to do: don't put off updates, watch out for suspicious links, and change your passwords once in a while. It might not seem like much, but that's really where security starts. 🦋
#securitynews #AIsecurity #cybersecurity #glasswingproject #appupdate #hackingprevention #privacyprotection #Anthropic
'Security News(Eng)' 카테고리의 다른 글
- Total
- Today
- Yesterday
- HackingAlert
- 랜섬웨어
- infosecurity
- 해킹예방
- 취약점
- Malware
- 해킹주의
- 보안뉴스
- 사이버보안
- 전자금융기반시설취약점분석평가
- securitynews
- 전자금융기반시설
- PrivacyProtection
- 정보보안
- HackingPrevention
- 샤이니헌터스
- DataPrivacy
- 공급망공격
- 2단계인증
- SecurityTips
- 금취분평
- 악성코드
- 보안꿀팁
- 개인정보유출
- supplychainattack
- cve
- 스마트폰보안
- 보안상식
- 개인정보보호
- cybersecurity
| 일 | 월 | 화 | 수 | 목 | 금 | 토 |
|---|---|---|---|---|---|---|
| 1 | 2 | 3 | 4 | 5 | 6 | |
| 7 | 8 | 9 | 10 | 11 | 12 | 13 |
| 14 | 15 | 16 | 17 | 18 | 19 | 20 |
| 21 | 22 | 23 | 24 | 25 | 26 | 27 |
| 28 | 29 | 30 |