Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Google AI tool Big Sleep finds zero-day vulnerability in SQLite database engine
Global Security

Google AI tool Big Sleep finds zero-day vulnerability in SQLite database engine

AdminBy AdminNovember 4, 2024No Comments3 Mins Read
Zero-Day Vulnerability
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


November 4, 2024Ravi LakshmananArtificial Intelligence / Vulnerability

A zero-day vulnerability

Google said it discovered a zero-day vulnerability in the open-source SQLite database engine using a Large Language Model (LLM)-enabled framework called Big dream (formerly Project Naptime).

The tech giant described the development as the “first real-world vulnerability” discovered using an artificial intelligence (AI) agent.

“We believe this is the first public example of an AI agent detecting a previously unknown memory security issue in widely used real-world software,” Big Sleep Team said in a blog post shared with The Hacker News.

Cyber ​​security

The vulnerability it’s about stack buffer underfilling in SQLite, which happens when a piece of software references a memory location before the memory buffer starts, causing it to crash or execute arbitrary code.

“This typically occurs when a pointer or its index is decremented to a position before the buffer, when pointer arithmetic results in a position before the beginning of a valid memory location, or when a negative index is used,” according to Common Weakness Enumeration. (CWE) description class of errors.

After responsible disclosure, the flaw was addressed as of early October 2024. It should be noted that the flaw was discovered in the library’s development branch, meaning it was flagged before the official release.

Project Naptime was first in detail Google in June 2024 as a technical framework for improving automated vulnerability detection approaches. It has since evolved into Big Sleep as part of a larger collaboration between Google Project Zero and Google DeepMind.

The idea behind Big Sleep is to use an artificial intelligence agent to simulate human behavior while detecting and demonstrating security vulnerabilities, taking advantage of LLM’s code comprehension and comprehension abilities.

Cyber ​​security

This entails using a set of specialized tools that allow the agent to navigate the target codebase, run Python scripts in a sandbox to generate the fuzzing input, debug the program, and observe the results.

“We believe that this work has enormous defensive potential. “Finding vulnerabilities in software before it’s released means that attackers have no way to compete: vulnerabilities are patched before attackers have a chance to exploit them,” Google said.

The company, however, also emphasized that these are still experimental results, adding that “the Big Sleep team’s position is that it is currently quite likely that the target fuzzer will be at least as effective (at finding vulnerabilities).”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025

Pragmatic approach to NHI stocks

June 30, 2025

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025

Pragmatic approach to NHI stocks

June 30, 2025

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.