压制AI武器化:我们对A Security的投资

Lightspeed · Stories ·

作者讨论了AI驱动的攻击如何挑战现有安全实践。他们描述了A Security对已验证攻击路径的关注,并将团队的产品工作与其在企业安全和事件响应方面的经验联系起来。 阅读 4 条观点,查看支持证据与原始来源。

Guru Chahal, Tal Morgenstern

理解这篇

4 个要点

综合解读

  1. AI攻击挑战旧有安全模型

    作者认为,旧的安全模型并非为应对持续检查环境、将漏洞组合成攻击路径并自动化利用的恶意智能体而构建。

    支持这项说法 1

    当前沿模型一发布,对手便在防御者尚未反应过来时将其武器化——此时,这层玻璃便碎裂了。如今,恶意智能体持续爬取各类环境,不仅发现高危漏洞,更将多种漏洞串联为现实世界的攻击路径,并实现自动化利用。这代表一种旧安全模型无法应对的新现实。

    Guru Chahal, Tal Morgenstern · 段落 1

    原始摘录
    When frontier models emerged and adversaries weaponized them before defenders could react the glass shattered. Malicious agents are crawling environments at all times today, not only finding the high-severity vulnerabilities but chaining vulns of all kinds into real-world attack paths and automating exploitation. This represents a new reality that the old security model was not built for.
    上下文

    你的安全体系是为这一刻而构建的吗?可能不是。我们不仅需要一种新方法。我们相信我们需要一项新的基础技术。

    原始上下文

    Was your security stack built for this moment? Probably not. We don’t just need a new approach. We believe we need a new foundational technology.

    回到原文语境 →
  2. 作者质疑渗透测试与态势评估的局限性

    作者表示,包括渗透测试和态势评估在内的传统方法往往存在局限,因为它们主要识别理论风险或无法扩展。他们指出,恶意智能体几乎可以瞬间将风险转化为攻击,而渗透测试“在交付的那一刻就已过时”。

    支持这项说法 1

    如今这种局面,已不能靠改造旧办法来应对。传统方法,比如渗透测试和安全态势评估,往往存在局限:它们要么主要识别理论上的风险,要么难以扩大规模。但风险只停留在理论层面的日子已经过去。如今,恶意智能体几乎可以瞬间把风险热点变成现实中的攻击。渗透测试交付之时,就已经过时。

    Guru Chahal, Tal Morgenstern · 段落 3

    原始摘录
    You can’t retrofit this moment. Legacy approaches – pentests and posture assessments for example – are often limited because they either primarily identify areas of theoretical risk, or because they cannot scale. But the days of theoretical risk are over. Today malicious agents can turn a risk hot-spot into a real-world attack almost instantly. That pentest is out of date the moment it ships.
    上下文

    如今的防御者需要一个速度能超过武器化 AI 的平台,在恶意智能体真正利用漏洞利用路径之前,发现、演示、验证并修复这些路径。

    原始上下文

    Defenders today need a platform that can outpace weaponized AI, finding, demonstrating, validating, and remediating exploit paths before a malicious agent can actually exploit them.

    回到原文语境 →
  3. 该平台专注于已验证的攻击路径

    作者表示,该平台专注于经验证的可利用性而非理论风险,并能准确展示AI驱动的攻击者如何入侵并利用某个环境。他们称,这有助于组织防御AI赋能的对手正在大规模发起的攻击。

    支持这项说法 1

    该平台聚焦于已验证的可利用性,而非理论风险,并准确展示 AI 驱动的攻击者如何侵入并利用某个环境,帮助组织加强防御,抵御如今具备 AI 能力的对手发动的大规模攻击。

    Guru Chahal, Tal Morgenstern · 段落 7

    原始摘录
    By focusing on validated exploitability rather than theoretical risk, and demonstrating exactly how an AI-powered attacker could infiltrate and exploit an environment, the platform helps organizations to fortify themselves against the attacks that AI-enabled adversaries are launching en masse today.
    上下文

    A Security 是面向现代防御者的平台。我们认为,其方法——利用攻击型和防御型智能体,持续发现、验证并消除现实中的漏洞利用路径,赶在攻击者利用这些路径之前采取行动——很快将成为行业必备要求。

    原始上下文

    A Security is the platform for the modern defender. Their approach – utilizing offensive and defensive agents to continuously discover, validate, and eliminate real-world exploit paths before attackers can use them – will soon be an industry requirement in our opinion.

    回到原文语境 →
  4. 事件响应经验指导了团队的工作

    作者表示,该团队凭借多年企业安全与事件响应经验,基于对攻击者运作方式以及现有安全工作流程通常失效环节的第一手认知来构建产品。

    支持这项说法 1

    团队的经验无可匹敌,源于多年在企业安全和事件响应一线的实战。这确保他们在开发时,依据的是对攻击者行动方式及现有安全工作流程常见失效环节的第一手了解。

    Guru Chahal, Tal Morgenstern · 段落 16

    原始摘录
    The team’s unmatched experience comes from years of being “in the trenches” of enterprise security and incident response, ensuring they are building from first-hand knowledge of attacker operations and where existing security workflows typically fail.
    上下文

    一线经验:

    原始上下文

    Front-Line Experience:

    回到原文语境 →

关键段落4

带明确归属与语境的原文片段。打开原始文本核查出处。

AI安全范式转变

AI攻击挑战旧有安全模型

当前沿模型一发布,对手便在防御者尚未反应过来时将其武器化——此时,这层玻璃便碎裂了。如今,恶意智能体持续爬取各类环境,不仅发现高危漏洞,更将多种漏洞串联为现实世界的攻击路径,并实现自动化利用。这代表一种旧安全模型无法应对的新现实。

原始摘录
When frontier models emerged and adversaries weaponized them before defenders could react the glass shattered. Malicious agents are crawling environments at all times today, not only finding the high-severity vulnerabilities but chaining vulns of all kinds into real-world attack paths and automating exploitation. This represents a new reality that the old security model was not built for.
上下文

你的安全体系是为这一刻而构建的吗?可能不是。我们不仅需要一种新方法。我们相信我们需要一项新的基础技术。

原始上下文

Was your security stack built for this moment? Probably not. We don’t just need a new approach. We believe we need a new foundational technology.

经验证的可利用性关注点

该平台专注于已验证的攻击路径

该平台聚焦于已验证的可利用性,而非理论风险,并准确展示 AI 驱动的攻击者如何侵入并利用某个环境,帮助组织加强防御,抵御如今具备 AI 能力的对手发动的大规模攻击。

原始摘录
By focusing on validated exploitability rather than theoretical risk, and demonstrating exactly how an AI-powered attacker could infiltrate and exploit an environment, the platform helps organizations to fortify themselves against the attacks that AI-enabled adversaries are launching en masse today.
上下文

A Security 是面向现代防御者的平台。我们认为,其方法——利用攻击型和防御型智能体,持续发现、验证并消除现实中的漏洞利用路径,赶在攻击者利用这些路径之前采取行动——很快将成为行业必备要求。

原始上下文

A Security is the platform for the modern defender. Their approach – utilizing offensive and defensive agents to continuously discover, validate, and eliminate real-world exploit paths before attackers can use them – will soon be an industry requirement in our opinion.

创始人专业能力作为差异化因素

事件响应经验指导了团队的工作

团队的经验无可匹敌,源于多年在企业安全和事件响应一线的实战。这确保他们在开发时,依据的是对攻击者行动方式及现有安全工作流程常见失效环节的第一手了解。

原始摘录
The team’s unmatched experience comes from years of being “in the trenches” of enterprise security and incident response, ensuring they are building from first-hand knowledge of attacker operations and where existing security workflows typically fail.
上下文

一线经验:

原始上下文

Front-Line Experience:

安全测试的局限性

作者质疑渗透测试与态势评估的局限性

如今这种局面,已不能靠改造旧办法来应对。传统方法,比如渗透测试和安全态势评估,往往存在局限:它们要么主要识别理论上的风险,要么难以扩大规模。但风险只停留在理论层面的日子已经过去。如今,恶意智能体几乎可以瞬间把风险热点变成现实中的攻击。渗透测试交付之时,就已经过时。

原始摘录
You can’t retrofit this moment. Legacy approaches – pentests and posture assessments for example – are often limited because they either primarily identify areas of theoretical risk, or because they cannot scale. But the days of theoretical risk are over. Today malicious agents can turn a risk hot-spot into a real-world attack almost instantly. That pentest is out of date the moment it ships.
上下文

如今的防御者需要一个速度能超过武器化 AI 的平台,在恶意智能体真正利用漏洞利用路径之前,发现、演示、验证并修复这些路径。

原始上下文

Defenders today need a platform that can outpace weaponized AI, finding, demonstrating, validating, and remediating exploit paths before a malicious agent can actually exploit them.

来源与研究方法

这些观点均关联原始来源。转述已明确标注,不作为逐字原话展示。

打开转录或来源材料 (在新标签页中打开)报告问题