Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Google AI tool Big Sleep finds zero-day vulnerability in SQLite database engine
Global Security

Google AI tool Big Sleep finds zero-day vulnerability in SQLite database engine

AdminBy AdminNovember 4, 2024No Comments3 Mins Read
Zero-Day Vulnerability
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


November 4, 2024Ravi LakshmananArtificial Intelligence / Vulnerability

A zero-day vulnerability

Google said it discovered a zero-day vulnerability in the open-source SQLite database engine using a Large Language Model (LLM)-enabled framework called Big dream (formerly Project Naptime).

The tech giant described the development as the “first real-world vulnerability” discovered using an artificial intelligence (AI) agent.

“We believe this is the first public example of an AI agent detecting a previously unknown memory security issue in widely used real-world software,” Big Sleep Team said in a blog post shared with The Hacker News.

Cyber ​​security

The vulnerability it’s about stack buffer underfilling in SQLite, which happens when a piece of software references a memory location before the memory buffer starts, causing it to crash or execute arbitrary code.

“This typically occurs when a pointer or its index is decremented to a position before the buffer, when pointer arithmetic results in a position before the beginning of a valid memory location, or when a negative index is used,” according to Common Weakness Enumeration. (CWE) description class of errors.

After responsible disclosure, the flaw was addressed as of early October 2024. It should be noted that the flaw was discovered in the library’s development branch, meaning it was flagged before the official release.

Project Naptime was first in detail Google in June 2024 as a technical framework for improving automated vulnerability detection approaches. It has since evolved into Big Sleep as part of a larger collaboration between Google Project Zero and Google DeepMind.

The idea behind Big Sleep is to use an artificial intelligence agent to simulate human behavior while detecting and demonstrating security vulnerabilities, taking advantage of LLM’s code comprehension and comprehension abilities.

Cyber ​​security

This entails using a set of specialized tools that allow the agent to navigate the target codebase, run Python scripts in a sandbox to generate the fuzzing input, debug the program, and observe the results.

“We believe that this work has enormous defensive potential. “Finding vulnerabilities in software before it’s released means that attackers have no way to compete: vulnerabilities are patched before attackers have a chance to exploit them,” Google said.

The company, however, also emphasized that these are still experimental results, adding that “the Big Sleep team’s position is that it is currently quite likely that the target fuzzer will be at least as effective (at finding vulnerabilities).”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025

Google warns about scattered spider attacks focused on IT -commander by US insurance firms

June 17, 2025

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025

Google warns about scattered spider attacks focused on IT -commander by US insurance firms

June 17, 2025

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025

New Flodrix Botnet Option Operates Langflow Ai Server RCE BUG to launch DDOS ATTACKS

June 17, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.