AISLE(AI网络安全公司,自2025年中起运营自主漏洞发现与修复系统)报告
作者:Stanislav Fort(AISLE创始人兼首席科学家)
发布时间:2026年4月7日
报告标题:《AI Cybersecurity After Mythos: The Jagged Frontier》(《Mythos之后的AI网络安全:锯齿状前沿》)
核心看点
“The FreeBSD NFS vulnerability — described by Anthropic as a 17-year-old zero-day enabling unauthenticated root access — was detected by every single model AISLE tested. All eight, including a model with just 3.6 billion active parameters costing $0.11 per million tokens, correctly identified the stack buffer overflow, computed the available buffer space, and flagged it as critical with remote code execution potential.”
“The smallest model tested — GPT-OSS-20b with 3.6 billion active parameters — found the same overflow that Mythos found. So did Kimi K2, DeepSeek R1, Qwen3 32B, and Gemma 4 31B. Kimi K2 and DeepSeek R1 are fully open-weights models. The detection of this bug, AISLE concludes, is ‘commoditized.’”
“DeepSeek R1 identified the NULL dereference but dismissed the signed overflow” in the 27-year-old OpenBSD TCP SACK vulnerability test.
“On a basic security reasoning task, small open models outperformed most frontier models from every major lab. DeepSeek R1 correctly traced the data flow across all four trials in the false positive discrimination test, while only Opus 4.6 out of 13 Anthropic models passed cleanly.”
- AISLE原始报告:AI Cybersecurity After Mythos: The Jagged Frontier | AISLE
- AISLE后续更新报告(开源nano-analyzer工具):System Over Model: Zero-Day Discovery at the Jagged Frontier | AISLE
- OfficeChai权威报道:Smaller And Cheaper Models Also Managed To Discover The Same Security Bugs As Claude Mythos, Says AISLE Analysis
VIDOC Security Lab(专业网络安全研究机构)验证
发布时间:2026年4月12日
核心发现
“This is not a new capability. We have been using GPTs-4 and Opus, and we were able to find the same bugs, days, in some cases weeks, before Mythos was probably at the task of finding potential issues in code, but the ‘shock’ was in the way it was presented.”
“We were able to replicate the Mythos findings using existing models without any fine-tuning, no RBS, no prompts. It’s just a normal redaction.”
(表格中的参数规模指的是激活参数)
核心结论
本话题由我和豆包专家共同整理~ ![]()











