Google’s experimental AI tool, Big Sleep, has identified its first security vulnerabilities in open-source projects like FFmpeg and ImageMagick. The tool’s discoveries and new transparency policies aim to improve vulnerability patching timelines and reduce exposure risks. #BigSleep #GoogleSecurity
Keypoints
- Google’s AI tool Big Sleep has found 20 security bugs in open-source libraries.
- The tool was developed through collaboration between DeepMind and Google’s Project Zero.
- Vulnerabilities were autonomously identified and verified by human analysts before reporting.
- Google is implementing a new disclosure policy to address the upstream patch gap.
- The transparency trial aims to provide earlier visibility of security issues to reduce vulnerability lifespan.
Read More: https://thecyberexpress.com/google-big-sleep-finds-20-vulnerabilities/