AIs, MCPs, and the Acutal Work that LLMs Are Generating - ASW #333
文章讨论了MCPs的流行及其安全设计缺陷,重点分析了LLMs在生成代码和应用安全中的价值与挑战,并探讨了LLMs在开源开发和漏洞奖励平台中的潜在影响。同时提及了GitLab和GitHub的提示注入攻击、代码重写的价值与权衡、iOS安全历史教训及NIST对漏洞测量的方法。 2025-6-3 09:0:0 Author: sites.libsyn.com(查看原文) 阅读量:8 收藏

Jun 3, 2025

The recent popularity of MCPs is surpassed only by the recent examples deficiencies of their secure design. The most obvious challenge is how MCPs, and many more general LLM use cases, have erased two decades of security principles behind separating code and data. We take a look at how developers are using LLMs to generate code and continue our search for where LLMs are providing value to appsec. We also consider what indicators we'd look for as signs of success. For example, are LLMs driving useful commits to overburdened open source developers? Are LLMs climbing the ranks of bug bounty platforms?

In the news, more examples of prompt injection techniques against LLM features in GitLab and GitHub, the value (and tradeoffs) in rewriting code, secure design lessons from a history of iOS exploitation, checking for all the ways to root, and NIST's approach to (maybe) measuring likely exploited vulns.

Visit https://www.securityweekly.com/asw for all the latest episodes!

Show Notes: https://securityweekly.com/asw-333


文章来源: http://sites.libsyn.com/18678/ais-mcps-and-the-acutal-work-that-llms-are-generating-asw-333
如有侵权请联系:admin#unsafe.sh