标签: AI

‘Generative AI is already changing what malicious software packages look like and how threat actors are beginning to probe AI-based code systems’: Amazon flags North Korean hacker group as being behind the surge in open source supply chain attacks

'Generative AI is already changing what malicious software packages look like and how threat actors are beginning to probe AI-based code systems': Amazon flags North Korean hacker group as being behind the surge in open source supply chain attacks

Amazon 威胁情报团队将 NPM 生态中 axios、debug、chalk、typo-crypto 等多个流行库被入侵的事件,归因于同一个朝鲜黑客组织。生成式 AI 正在让这类恶意软件包看起来更“正常”,也让传统安全检测更加被动。