リーディングビュー

「権限の低いエージェントをハックして上位権限でコードを実行する」というGoogle ADKのハッキング手法が発見される

🤖 AI Summary

タイトル:Google ADKの脆弱性が発見され、権限の低いエージェントをハックして上位権限でコード実行可能

要約:
セキュリティ企業Pillarによって、Googleが公開している企業向け開発支援ツール「Agent Development Kit(ADK)」に新たな脆弱性が見つかったことが明らかになりました。この脆弱性は、「権限の低いエージェントをハックして上位権限でコードを実行する」という攻撃手法に対応しています。

具体的な内容としては、セキュリティ企業Pillarは、ADKに存在する「プロンプトインジェクション」の脆弱性を利用して、エージェントに任意のフレーズを出力させることが可能としました。さらに、悪意のあるプロンプトを用いて、通常は人間にしか許可されていないメンテナー専用のワークフローを呼び出すことも確認されました。

Googleはこの問題を受け、既に軽減策が導入されているとのことですが、Pillarは、今回の発見が新たな攻撃対象領域を示唆していると指摘しています。セキュリティ担当者は、エージェントを使用した攻撃シナリオも考慮に入れて脅威モデルを作成する必要があるとしています。

この脆弱性は、悪意のあるハッカーが権限の低いエージェントをハックすることで、上位権限でコードを実行し、システムに深刻な影響を与える可能性があります。
Googleはエンタープライズ規模の開発をサポートするエージェント開発フレームワーク「Agent Development Kit(ADK)」を公開しています。このADKに「権限の低いエージェントをハックして上位権限でコードを実行する」という攻撃を実行可能な脆弱(ぜいじゃく)性が存在することが、セキュリティ企業のPillarによって発見されました。

続きを読む...

  •  

OpenAI's Astra Solved Decades-Old Math Problems For $2,000

✇Slashdot
著者: BeauHD
An anonymous reader quotes a report from Forbes: The cost of producing new results on ten longstanding mathematical problems just fell to $2,000, according to OpenAI, which says its Astra model generated machine-checkable proofs for questions that had resisted human progress for decades. OpenAI published the work on August 1 and used it to give its next major model family a name: Astra. The results run across group theory, high-dimensional geometry, coding theory, quantum complexity, lattice cryptography and extremal combinatorics. They arrived as a 249-page manuscript collection and, alongside it, something the field has not seen attached to an AI claim before at this scale: a machine-checkable certificate for every single result. The problems were not textbook exercises dressed up as discoveries. Each had been open for at least ten years, most of them far longer, and several sit at the center of their subfields: - A construction establishing the existence of non-sofic groups, a question that has occupied group theorists for years. - A disproof of Connes's rigidity conjecture, a long-standing problem in the theory of von Neumann algebras. - An improvement to the general upper bound on sphere-packing density in high dimensions, a bound that had stood since 1978. - Three problems come from the catalogue of open questions left behind by Paul Erdos. The announcement follows another result from May, when OpenAI used a similar reasoning model to produce an original mathematical proof disproving a famous unsolved conjecture in geometry, which was first posed by Paul Erdos in 1946.

Read more of this story at Slashdot.

  •  

Microsoft CEO Touts His Own DIY AI Project To Wall Street and His 20 Million Followers

✇Slashdot
著者: BeauHD
theodp writes: During Microsoft's 2026Q4 earnings call, CEO Microsoft Satya Nadella took time to tout a dashboard he personally created using AI from a Morgan Stanley analyst's PDF research report, which suggested a rosy payback for the so-called MAG7's ('Magnificent 7' companies) massive capital expenditures on AI (to which Nadella later added a "not financial advice" disclaimer). "It would be fun for you, Adam. I think one of your colleagues put out an ROIC [Return on Invested Capital] document. I took that document to Copilot, which is a PDF, and I said, 'Build me a new Power BI dashboard, essentially.' But here is the thing. It built a rich semantic model that went into my Fabric with OneLake that brought all the data in from the external sources. In fact, it was current with all the SEC filings of all the MAG7. And then on top of that, the repo itself is in GitHub, but the artifact is sitting in my Copilot as a site. That, to me, is a classic example of an enterprise-wide workflow. I, as a knowledge worker, could go create a dashboard. The data engineer can go to Fabric and find the artifact. The professional developer can go to the repo and find it in GitHub. And by the way, it's all registered with Agent 365. That's a little bit of what Amy is describing as the coming together of a new way to work, even while at the same time, bringing IT, security and manageability of it." After Nadella's show-and-tell drew an underwhelming response during the call ("That's very helpful. Thank you." said the Morgan Stanley analyst whose team's work Nadella scraped with AI), Nadella turned to social media with posts on LinkedIn (12M followers) and Twitter/X (8M followers) to make the case for why his DIY project was such a brilliant demonstration of how AI enables governance, controls, security, development, testing, deployment, maintenance, data analysis/modeling, visualization, usability, and value. "Some more detail on the ROIC Intelligence App I built yesterday and mentioned on today's earnings call," Nadella wrote on LinkedIn. "I took the PDF that Brian Nowak at Morgan Stanley put together for Hyperscale ROIC this week and used Copilot code (coming in our new superapp) with a single prompt + skill (/drill-me) to create the plan, then used autopilot in auto to create the full app (with history, lookups, scenarios, what-ifs, etc). And /rubber-duck to test. And the best part is that all the artifacts are in my enterprise environment. My app is in Copilot, my code is in GitHub Enterprise; all my data pipelines/lake/semantic models are in Fabric. And everything is under Agent 365 IT/Sec/FinOps control! So this is not about Tokenmaxxing or vibe coding. Every step of the way the rails are engineered to create value, making everything a long-term reusable asset, with governance/security, and cost controls. This is the full system to drive business value. Disclosures: This is all pulled from public sources, and for illustrative purposes only...not financial advice! :) Here is the app and architecture..." Not unexpectedly, the accompanying screenshot of a splash page for the BI app and a buzzword-laden complicated architecture diagram drew universal praise from LinkedIn fans, but also a few barbs from less-than-impressed commenters on Nadella's Twitter/X post, some of whom suggested Nadella's project might even represent a jump-the-shark moment for AI mania. "That he doesn't see whats wrong with saying 'My app is in Copilot, my code is in GitHub Enterprise; all my data pipelines/lake/semantic models are in Fabric' is exactly why MS is failing at AI,'" replied @PassingPixels on X/Twitter. "Dude is having to run 5 different systems to emulate babies first vibe code." @zigmund_ignatov added, "Why do we call glorified slide show an app?" @Mathupiriyan quipped, "Looks like Copilot just turned a PDF into a profit crystal ball." Unimpressed, @Markusndnb remarked, "So you created a web page using tons of proprietary MS tools." And @FishyAccounting called on Nadella to show-his-work, saying "Post the prompt or it didn't happen." (btw, Microsoft President Brad Smith similarly declined to provide the prompt for his own self-described amazing AI DIY reporting project that he touted at Microsoft's Shareholder Meeting last December). So, does Nadella's self-promoted AI reworking of someone else's PDF research report strike you as an amazing example of everything that's good about AI, or does it conjure up memories of The Emperor's New Clothes?

Read more of this story at Slashdot.

  •  

Company Offering Printed Books To Train AI Stops After 404 Media Coverage

✇Slashdot
著者: BeauHD
An anonymous reader quotes a report from 404 Media: Following 404 Media's reporting that book database company ISBNdb claimed to source printed books to then sell to AI companies for AI training, the company deleted the part of its website offering the service and walked back claims that it would train AI models, and instead called it "a test of market interest." On July 30, nine days after 404 Media's reporting, ISBNdb added a note to its homepage and an update on its news page about the change. "We've seen the recent coverage about a marketing landing page on our site, and we understand the concern it raised. The facts: ISBNdb has never purchased, scanned, or sold a book -- for AI training or anything else," ISBNdb wrote. "We don't train AI models, and we never have. The page was a test of market interest; no such service was ever brought to life. We've taken the page down. Our job is helping people find books. For more than two decades, ISBNdb has been the card catalog of the book world -- the data behind how bookstores, libraries, and reading apps connect readers with titles. Data about books, not the books themselves. That hasn't changed." ISBNdb removed the landing page for "Printed Books Sourcing for Your AI LLMs Dataset Needs" on July 28. "It was part of exploring demand, and we've chosen to pivot away from that direction. Our main ISBNdb (book metadata API) services are unaffected and running as usual," the site says. According to 404 Media's previous report, ISBNdb had pitched pre-2022 printed books as premium AI training material because they contained curated human knowledge without contamination from AI-generated text or modern data-poisoning techniques. "The world's best AI training data is sitting on a shelf," the company had argued, while offering discreet bulk book acquisition under NDAs and acknowledging the potential backlash if AI firms were seen destroying millions of books for scanning.

Read more of this story at Slashdot.

  •  
❌