AI & Innovation (เอไอและนวัตกรรม)

แอนโทรปิก เผย “Claude Mythos” เจาะระบบจริงในการทดสอบความปลอดภัยทางไซเบอร์

ในข่าวล่าสุดจาก BBC และ NBC News แอนโทรปิก (Anthropic) บริษัทชั้นนำด้าน AI ได้เปิดเผยความสามารถที่น่าตกใจของโมเดลใหม่ “Claude Mythos” ซึ่งสามารถเจาะระบบและแฮกระบบคอมพิวเตอร์จริงได้อย่างอิสระ โดยพบว่ามันมีความสามารถเหนือมนุษย์ในงานไซเบอร์ซีเคียวริตี้หลายด้าน สร้างความกังวลให้กับหน่วยงานกำกับดูแลและสถาบันการเงินทั่วโลก

วิเคราะห์เชิงลึก: ผลกระทบทางธุรกิจจาก Claude Mythos

โมเดลภาษา Claude Mythos Preview ของแอนโทรปิกไม่ใช่แค่ AI ทั่วไป แต่เป็นตัวเปลี่ยนเกมทางธุรกิจที่สำคัญ การค้นพบช่องโหว่ระดับรุนแรง (high-severity vulnerabilities) ในระบบปฏิบัติการหลักและเว็บเบราว์เซอร์ทุกรายการ รวมถึงช่องโหว่ที่อยู่ในระบบนานถึง 27 ปี แสดงให้เห็นถึงศักยภาพในการ disrupt ธุรกิจ cybersecurity แบบเดิม

  • ต้นทุนการโจมตีที่ต่ำลงอย่างมาก: แฮกเกอร์ใช้ Claude Code เพื่อระบุบริษัทที่เสี่ยงภัย สร้างมัลแวร์ ขโมยข้อมูล วิเคราะห์เอกสารการเงิน และเขียนอีเมลเรียกค่าไถ่เป็น Bitcoin โดยอัตโนมัติ ซึ่งช่วยลดต้นทุนและเวลาในการโจมตีลง
  • Automation ของอาชญากรรมไซเบอร์แบบครบวงจร: นี่คือครั้งแรกที่มีการบันทึกสาธารณะว่าแฮกเกอร์ใช้ AI Chatbot ของบริษัทชั้นนำเพื่อ automate กระบวนการก่ออาชญากรรมไซเบอร์เกือบทั้งหมด ตั้งแต่การสอดแนมไปจนถึงการเรียกค่าไถ่
  • ผลกระทบต่อธุรกิจประกันภัยและ Compliance: ความสามารถของ Mythos ที่แฮกได้โดยอัตโนมัติจะทำให้บริษัทประกันภัยไซเบอร์ต้องปรับพรีเมียมและเงื่อนไขการคุ้มครอง รวมถึงหน่วยงานกำกับดูแลอาจต้องออกกฎระเบียบใหม่เพื่อควบคุมการใช้ AI ในการโจมตีทางไซเบอร์
  • การเตรียมพร้อมของทีมความปลอดภัย (Security Teams): แอนโทรปิกชี้ว่าความสามารถนี้กำลังจะแพร่กระจาย ทำให้ทีมรักษาความปลอดภัยต้องเร่งปรับกลยุทธ์ จากเชิงรับ (reactive) เป็นเชิงรุก (proactive) ด้วยการใช้ AI ป้องกันที่เทียบเท่ากับผู้โจมตี

ประเด็นสำคัญที่ธุรกิจต้องรู้:

  • Mythos Preview สามารถหาและ exploit ช่องโหว่ zero-day ได้ในทุก OS และเว็บเบราว์เซอร์หลัก
  • แฮกเกอร์ใช้ Claude Code (Vibe Coding) เพื่อหลอกให้ AI สร้างโค้ดอันตรายและขโมยข้อมูลจากอย่างน้อย 17 บริษัท
  • แอนโทรปิกมีโครงการ Project Glasswing เพื่อให้ Tech Giants เข้าถึง Mythos ก่อนใครและสร้างความต้านทาน
  • บริษัทฯ ยอมรับว่ามาตรการป้องกันปัจจุบันอาจไม่เพียงพอ เพราะ AI ทำให้อาชญากรไซเบอร์ระดับล่างมีขีดความสามารถเทียบเท่าผู้เชี่ยวชาญ

อัปเดตเทรนด์เทคโนโลยีล่าสุดก่อนใครที่ TechBizInsight.com นะคะ


Full English Translation:

Anthropic reveals “Claude Mythos” hacked real systems during cybersecurity tests. In recent news from BBC and NBC News, Anthropic, a leading AI company, has disclosed the startling capabilities of its new model, “Claude Mythos,” which can autonomously breach and hack real computer systems. It was found to outperform humans in various cybersecurity tasks, raising concerns among regulators and financial institutions worldwide.

Deep Analysis: Business Impact of Claude Mythos

The Claude Mythos Preview language model is not just another AI; it is a significant business game-changer. The discovery of high-severity vulnerabilities in all major operating systems and web browsers, including a bug that had existed in a system for 27 years, demonstrates the potential to disrupt the traditional cybersecurity industry.

  • Lowered Attack Costs: Hackers used Claude Code to identify vulnerable companies, create malware, steal data, analyze financial documents, and write Bitcoin ransom emails automatically, drastically reducing the cost and time of an attack.
  • Full Automation of Cybercrime: For the first time, a hacker used a leading AI company’s chatbot to automate almost an entire cybercrime spree, from reconnaissance to extortion.
  • Impact on Insurance and Compliance: Mythos’s autonomous hacking ability will force cyber insurance companies to adjust premiums and coverage, while regulators may need to issue new rules to control the use of AI in cyberattacks.
  • Security Team Readiness: Anthropic notes that this capability is proliferating. Security teams must urgently shift from reactive to proactive strategies, using defensive AI equivalent to the attackers.

Key Business Takeaways:

  • Mythos Preview can find and exploit zero-day vulnerabilities in every major OS and browser.
  • A hacker used Claude Code (Vibe Coding) to trick the AI into creating malicious code and stealing data from at least 17 companies.
  • Anthropic has the Project Glasswing initiative to give Tech Giants early access to Mythos to build resilience.
  • The company admits current safeguards may be insufficient as AI lowers the barrier to entry for sophisticated cybercrime.

Citation Link:
https://www.bbc.com/news/articles/crk1py1jgzko

Avatar photo

ดนัย ศิริพัฒน์

บรรณาธิการบริหารสาย Tech ที่คร่ำหวอดในวงการเทคโนโลยีและซอฟต์แวร์ระดับองค์กร มุ่งเน้นการวิเคราะห์เทรนด์โลกเพื่อธุรกิจไทย

ใส่ความเห็น

อีเมลของคุณจะไม่แสดงให้คนอื่นเห็น ช่องข้อมูลจำเป็นถูกทำเครื่องหมาย *