Google Big Sleep - L'IA qui a trouveฬ 20 failles de seฬcuriteฬ toute seule


Les bug bounty hunters nโ€™ont quโ€™aฬ€ bien se tenir car Google va bientoฬ‚t tenter de les remplacer (comme ils ont deฬjaฬ€ remplaceฬ pas mal de creฬateurs web) graฬ‚ce aฬ€ leur nouvelle IA baptiseฬe Big Sleep. En effet, celle-ci vient de prouver quโ€™elle peut deฬtecter des failles de seฬcuriteฬ que meฬ‚me les meilleurs hackers humains ont loupeฬes. Et je ne vous parle pas de petites vulneฬrabiliteฬs bidons, mais de veฬritables failles dans des logiciels critiques.

Vous vous souvenez quand je vous parlais de XBOW, cette IA qui eฬtait devenue numeฬro 1 sur HackerOne ? Eh bien Google vient de rentrer dans la danse avec Big Sleep, et visiblement ils ne sont pas venus pour rigoler. Lโ€™approche est diffeฬrente mais tout aussi impressionnante.

Big Sleep, cโ€™est le fruit dโ€™une collaboration entre Google Project Zero (lโ€™eฬquipe dโ€™eฬlite qui trouve des failles zero-day) et DeepMind (les geฬnies derrieฬ€re AlphaGo). Ensemble, ils ont creฬeฬ une IA capable dโ€™analyser du code source et de deฬtecter des vulneฬrabiliteฬs de manieฬ€re autonome. Le nom โ€œBig Sleepโ€ vient dโ€™ailleurs du roman noir de Raymond Chandler (lien affilieฬ), un clin dโ€™ล“il au coฬ‚teฬ deฬtective de lโ€™IA.

La premieฬ€re vraie victoire de Big Sleep, cโ€™est donc dโ€™avoir trouveฬ une vulneฬrabiliteฬ stack buffer underflow dans SQLite, la base de donneฬes la plus utiliseฬe au monde. Cette faille eฬtait passeฬe sous le radar de tous les outils de fuzzing traditionnels et des chercheurs humains. Lโ€™IA a reฬussi aฬ€ lโ€™identifier en analysant les patterns de code et en comprenant la logique profonde du programme.

Ce qui est vraiment fou avec Big Sleep, cโ€™est sa capaciteฬ aฬ€ comprendre le contexte et la seฬmantique du code car contrairement aux outils de fuzzing classiques qui bombardent le programme avec des donneฬes aleฬatoires pour voir sโ€™il crashe, Big Sleep lit et comprend reฬellement ce que fait le code.

Cโ€™est la diffeฬrence entre un lecteur de Korben.info qui lit lโ€™un de mes articles et qui est content. Et un lecteur de Korben.info (ou pas dโ€™ailleurs) qui lit lโ€™un de mes articles en diagonale (ou juste le titreโ€ฆlol), qui ne comprend rien et qui part ensuite mโ€™insulter sur les reฬseaux sociaux ^^.

Google explique que Big Sleep utilise une approche en plusieurs eฬtapes. Dโ€™abord, lโ€™IA analyse le code source pour comprendre sa structure et son fonctionnement. Ensuite, elle identifie les zones potentiellement vulneฬrables en se basant sur des patterns connus mais aussi sur sa compreฬhension du flux de donneฬes. Enfin, elle geฬneฬ€re des cas de test speฬcifiques pour confirmer lโ€™existence de la vulneฬrabiliteฬ.

![](data:image/svg+xml,%3Csvg xmlns='http://www.w3.org/2000/svg' viewBox='0 0 1024 441'%3E%3C/svg%3E)

Les 20 vulneฬrabiliteฬs deฬcouvertes touchent diffeฬrents types de logiciels, des bibliotheฬ€ques systeฬ€me aux applications web. Google reste discret sur les deฬtails exacts pour des raisons eฬvidentes de seฬcuriteฬ, mais ils confirment que toutes les failles ont eฬteฬ corrigeฬes avant toute exploitation malveillante. Cโ€™est le principe du responsible disclosure : on trouve, on preฬvient, on corrige, et seulement apreฬ€s on communique.

Ce qui diffeฬrencie Big Sleep de XBOW, cโ€™est surtout lโ€™approche. Laฬ€ ouฬ€ XBOW excelle dans les bug bounties publics avec une approche plus agressive, Big Sleep semble plutoฬ‚t orienteฬ vers lโ€™analyse en profondeur de code complexe. Les deux IA sont donc compleฬmentaires et montrent bien que lโ€™avenir de la cyberseฬcuriteฬ passera par ces assistants intelligents.

Dโ€™ailleurs, Google ne compte pas garder Big Sleep pour lui et lโ€™eฬquipe travaille sur une version open source qui permettra aฬ€ la communauteฬ de beฬneฬficier de cette technologie. Lโ€™ideฬe cโ€™est de deฬmocratiser la recherche de vulneฬrabiliteฬs pour que meฬ‚me les petites entreprises puissent seฬcuriser leur code.

Mais attention, tout nโ€™est pas rose non plus car que se passera-t-il si des acteurs malveillants mettent la main sur ce genre dโ€™IA ? La course aux armements entre attaquants et deฬfenseurs risque de fortement sโ€™acceฬleฬrer drastiquement. Google assure avoir mis en place des garde-fous, mais on sait tous que dans le domaine de la seฬcuriteฬ, rien nโ€™est jamais garanti aฬ€ 100%.

Selon Google, Big Sleep peut analyser en quelques heures ce qui prendrait des semaines aฬ€ une eฬquipe humaine et contrairement aฬ€ vous les vacanciers eฬternels, lโ€™IA ne se fatigue pas, ne fait pas dโ€™erreur dโ€™inattention, et peut traiter des volumes de code monumentaux. Sur les 20 vulneฬrabiliteฬs trouveฬes, au moins 5 eฬtaient consideฬreฬes comme critiques avec un score CVSS supeฬrieur aฬ€ 8.

Pour voir les dernieฬ€res deฬcouvertes de BigSleep cโ€™est par ici.

Lโ€™objectif pour Google aฬ€ terme cโ€™est de creฬer une IA capable de comprendre non seulement le code, mais aussi lโ€™intention derrieฬ€re le code, donc si vous eฬ‚tes deฬveloppeur ou responsable seฬcuriteฬ, il est temps de prendre ce sujet au seฬrieux. Les IA comme Big Sleep et XBOW ne sont pas des gadgets, donc commencez aฬ€ reฬfleฬchir aฬ€ comment inteฬgrer ces outils dans vos processus de deฬveloppement et surtout, nโ€™attendez pas que les attaquants sโ€™en servent contre vous.

Source
posted by pod_feeder

Studying the glowing patterns of Earthโ€™s surface helps us understand human activity, respond to disasters, and witness a changing world.

Studying the glowing patterns of Earth039;s surface helps us understand human activity, respond to disasters, and witness a changing world.

Infiltration And Encirclement: Russiaโ€™s Deadly Push In Pokrovsk southfront.press/russia-deadlyโ€ฆ

Copper torches, lanterns, bars, and chains have been added in today's #Minecraft snapshot 25w32a!

Check out all of the new features in our #MinecraftWiki article and help us document them:
minecraft.wiki/w/Java_Edition_โ€ฆ

#MinecraftSnapshots

Die Polizei nutzt immer รถfter Staatstrojaner. Im Jahr 2023 durfte sie 130 Mal Gerรคte hacken und ausspionieren, 68 Mal war sie damit erfolgreich. Das ist eine Verdopplung innerhalb von zwei Jahren. Das geht aus der offiziellen Justizstatistik hervor.
Justizstatistik 2023: Polizei hackt alle fรผnf Tage mit Staatstrojanern

jonathanturley.org/2025/08/05/โ€ฆ

The comments of Ramirez have clearly struck a nerve on both sides. For my part, I am very proud of both my Irish-Sicilian background. My Sicilian grandparents came to this country at the turn of the century. They were deeply proud of their heritage but always insisted that their children identify as Americans first and foremost.

Yemeni missile fired at Israeli target; sirens sound in central cities english.almayadeen.net/news/poโ€ฆ

Googleโ€™s August Patch Fixes Two Qualcomm Vulnerabilities Exploited in the Wild


Google has released security updates to address multiple security flaws in Android, including fixes for two Qualcomm bugs that were flagged as actively exploited in the wild. The vulnerabilities include CVE-2025-21479 (CVSS score: 8.6) and CVE-2025-27038 (CVSS score: 7.5), both of which were disclosed alongside CVE-2025-21480 (CVSS score: 8.6), by the chipmaker back in June 2025. CVE-2025-21479
posted by pod_feeder

In der Nacht zum Mittwoch wechseln sich Wolken und Sonne ab, im Sรผden ist es gering bewรถlkt. An der Kรผste gibt es noch einzelne Schauer. Die Temperaturen sinken auf 15 Grad an der See und 9 Grad im Harzvorland. Im Binnenland lรคsst der Wind nach und weht aus westlicher Richtung. An der See bleibt es frisch mit starken bis stรผrmischen Bรถen. /LL

GitHub Pull Requests Are Down

Link: github.com/github/site-policy/โ€ฆ
Discussion: news.ycombinator.com/item?id=4โ€ฆ

Gold prices fall on profit-taking saba.ye/en/news3528317.htm

Microsoft's AI-fueled 4 trillion valuation highlights the massive impact of the AI bubble on the US economy. AI investments are now acting as a private sector stimulus, contributing more to US economic growth than consumer spending. However, a clear and sustainable business model remains elusive. In many ways, the current AI boom mirrors the dynamics of the dot-com era.

bloodinthemachine.com/p/the-aiโ€ฆ

#usa #economy #technology

A friend just sent me this article about losing a spouse.

"You think you're prepared.
you go in with boxes and garbage bags. You tell yourself youโ€™ll be strong.
You think, โ€œItโ€™s just stuff.โ€

But then you open a drawer.
And their handwriting is still on a notepad.
Their scent still clings to the sleeves of that sweater you begged them to throw out every winter.
Their shoes are still lined up by the door like they might be back any minute.

to be cont

in reply to HunDriverWidow

No one tells you how heavy an empty coat can feel in your hands.
No one tells you that cleaning out a space can shatter you all over again.

Itโ€™s not just cleaning.
Itโ€™s letting go of little pieces you were never ready to lose.
Itโ€™s closing a drawer for the last time and feeling like youโ€™re betraying them.
Itโ€™s packing up the life you shared, while your heart silently begs, please donโ€™t make me.

Because deep down, youโ€™re not just packing away their things โ€”

Columbia University's recent suspension and expulsion of more than 70 students for a Palestine demonstration is the latest sign the school's crackdown on activism is not simply about campus conduct, but appeasing political pressure from Washington.

mondoweiss.net/2025/08/as-coluโ€ฆ

#Palestine #Israel #Gaza
@palestine @israel

Mark Mansour notes that the overt, unabashed gerrymandering proposed by Texas Republicans is designed, by their own admission, to "enhance the political efficacyโ€ of GOP votes.

What this is really about is enhancing the political efficacy of WHITE RURAL voters. As Mansour says, it's "a chilling disenfranchisement of millions of votersโ€”especially Black, Latino, and Asian Americans."

#Texas #Republicans #gerrymandering #racism
/1

mmansour.substack.com/p/the-teโ€ฆ

in reply to William Lindsey

โ€œTrump knows he canโ€™t win the upcoming mid-term elections, so he is trying to rig them. And the way he is trying to do it is to dismantle the Voting Rights Act of 1965 as we know it. He is trying, for example to try and dismantle Hispanic and African-American opportunity districts."

~ Rep. Greg Casar quoted by John Nicholls

#Texas #Republicans #gerrymandering #racism #SupremeCourt #JohnRoberts
/6

thenation.com/article/politicsโ€ฆ

This entry was edited (2 weeks ago)
in reply to William Lindsey

Billy Begala explains how the Republican gerrymandering proposal wants to "carve up Texas like a Christmas ham," disenfranchising Black and Hispanic voters and privileging rural white ones.

#Texas #Republicans #gerrymandering #racism
/7

contrarian.substack.com/p/repuโ€ฆ

Talk about powerful: Rachel Maddow last night on how "we're beyond waiting and seeing now":

"Whether you're looking at small scale local stories or the biggest picture stories about what's happening in our country, the story is the same and it is now an undeniable thing. We have crossed a line. we are in a place we did not want to be, but we are there."

#Trump #authoritarianism #dictatorship #ICE #MaskedThugs #immigrants #militarism
/1

youtube.com/watch?v=VQbDgOaOh4โ€ฆ

in reply to William Lindsey

"Whether you're looking at small scale local stories or the biggest picture stories about what's happening in our country, the story is the same and it is now an undeniable thing. We have crossed a line. We are in a place we did not want to be, but we are there. The thing we were all warning about for the last few years is not coming. It is here. We are in it."

#Trump #authoritarianism #dictatorship #ICE #MaskedThugs #immigrants #militarism
/2

This entry was edited (2 weeks ago)
in reply to William Lindsey

"We do now live in a country that has an authoritarian leader in charge. We have a consolidating dictatorship in our country. and it sounds melodramatic to say it, i know, but just go with that for a minute, right? Think. Think in melodramatic terms. Think in cinematic terms. Imagine the cartoon level caricature of what you think a dictatorship looks like."

#Trump #authoritarianism #dictatorship #ICE #MaskedThugs #immigrants #militarism
/3

in reply to Dennis Stephens ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ‡ซ๐Ÿ‡ฎ

Reminds me of how, at my writing group last month, one of the members talked about how gross it was that there were people lining up to get autographs from Dean Cain. You know, because heโ€™s MAGA and so the people getting the autographs were probably also pieces of shit.
Iโ€™m sure if I said anything anti-liberal theyโ€™d kick me right out for being โ€œpolitical.โ€ But that dipshit going off about Republicans? A-OK.

GIF (II) Sofia/soxni69 #undressing thong #shavedpussy #nudegirlmodel #petitetits #nudeinnature
This entry was edited (2 weeks ago)

Global voices unite against Israelโ€™s war and starvation campaign in Gaza tehrantimes.com/news/516425/Glโ€ฆ

In 2019, the American Ayatollah (the Supreme Court) said that it was totally fine to gerrymander, as gerrymandered maps could not be reviewed by federal courts (Rucho v. Common Cause).

Now, with a slim majority, Texas Republicans are gerrymandering on racial lines to disempower voters because they cannot win elections on merits. As a result, Texas Democrats have fled the state, denying the governing body of quorum.

This is "American Democracy" failing spectacularly.

texastribune.org/2025/08/04/teโ€ฆ

Anyone in the FA fam suffer from gout? Anyone of you know of any natural remoidies to take? My wife was been in pain for the past 5 days and she went to the ER yesterday. The Er dock determined it was that. No breakage in her right foot. Still waiting on the damn ensurance to approve the med she needs. God I hope i don't get it. Having Arther is bad enough. Glad its not sever though.

#MutualAidRequest #MutualAid

I have been unemployed for over a year, hustling here and there while trying to find something long term in the current hell that is the tech industry. My cat has kidney problems and I need help to cover vet bills amounting to around 500โ‚ฌ.

PayPal: paypal.me/BarbaraL649

Also open to hire making websites for fellow #SexWorkers :ABlobCatCode:

โ‡ง