AI Found Twelve New Vulnerabilities in OpenSSL
嗯,用户让我总结一下这篇文章的内容,控制在100字以内,而且不需要特定的开头。我得先仔细阅读文章,抓住关键点。 文章主要讲的是OpenSSL在2026年1月27日发布的一个安全更新,发现了12个零日漏洞。这些漏洞都是由AI系统发现的,其中有10个被分配了CVE-2025的编号,另外两个是CVE-2026的。AI不仅发现了这些漏洞,还在五个案例中直接提出了被接受的补丁。 文章还提到这些漏洞有些存在了超过25年,甚至有一个可以追溯到SSLeay时代。其中一个漏洞CVE-2025-15467被评定为高危,CVSS评分9.8分,非常严重。 最后,文章指出AI在漏洞发现上的应用正在改变网络安全格局,并且这种能力会被用于攻击和防御双方。 总结的时候要包括时间、发现的漏洞数量、AI的作用、漏洞的严重性和历史背景,以及AI对网络安全的影响。控制在100字以内的话,需要简洁明了地表达这些要点。 </think> OpenSSL于2026年1月发布安全更新,披露12个零日漏洞,均由AI系统发现并负责任地报告。其中10个获CVE-2025编号,另两个为CVE-2026。部分漏洞存在超25年,甚至可追溯至SSLeay时代。AI还直接提出5个补丁方案。此成果凸显AI在网络安全中的变革性作用。 2026-2-18 12:3:10 Author: www.schneier.com(查看原文) 阅读量:1 收藏

The title of the post is”What AI Security Research Looks Like When It Works,” and I agree:

In the latest OpenSSL security release> on January 27, 2026, twelve new zero-day vulnerabilities (meaning unknown to the maintainers at time of disclosure) were announced. Our AI system is responsible for the original discovery of all twelve, each found and responsibly disclosed to the OpenSSL team during the fall and winter of 2025. Of those, 10 were assigned CVE-2025 identifiers and 2 received CVE-2026 identifiers. Adding the 10 to the three we already found in the Fall 2025 release, AISLE is credited for surfacing 13 of 14 OpenSSL CVEs assigned in 2025, and 15 total across both releases. This is a historically unusual concentration for any single research team, let alone an AI-driven one.

These weren’t trivial findings either. They included CVE-2025-15467, a stack buffer overflow in CMS message parsing that’s potentially remotely exploitable without valid key material, and exploits for which have been quickly developed online. OpenSSL rated it HIGH severity; NIST‘s CVSS v3 score is 9.8 out of 10 (CRITICAL, an extremely rare severity rating for such projects). Three of the bugs had been present since 1998-2000, for over a quarter century having been missed by intense machine and human effort alike. One predated OpenSSL itself, inherited from Eric Young’s original SSLeay implementation in the 1990s. All of this in a codebase that has been fuzzed for millions of CPU-hours and audited extensively for over two decades by teams including Google’s.

In five of the twelve cases, our AI system directly proposed the patches that were accepted into the official release.

AI vulnerability finding is changing cybersecurity, faster than expected. This capability will be used by both offense and defense.

More.

Tags: , , , ,

Posted on February 18, 2026 at 7:03 AM0 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.


文章来源: https://www.schneier.com/blog/archives/2026/02/ai-found-twelve-new-vulnerabilities-in-openssl.html
如有侵权请联系:admin#unsafe.sh