메뉴
BL
Wired AI 36일 전

OpenAI, 오픈소스 보안 취약점 패치 대대적 나서

IMP
8/10
핵심 요약

OpenAI가 보안 전문 모델 'GPT-5.5-Cyber'와 'Patch the Planet' 프로젝트를 발표하며 오픈소스 보안 강화에 나섰습니다. 이는 AI 기반 취약점 스캐닝 도구의 발달로 폭증하는 허위 버그 리포트에 시달리는 오픈소스 개발자들의 부담을 덜고, 지속 가능한 코드 보안을 지원하기 위한 조치입니다.

번역된 본문

AI의 해킹 역량에 대한 우려가 커지는 가운데, OpenAI는 월요일에 접근이 제한된 보안 전용 모델인 GPT-5.5-Cyber의 개선된 버전을 공개했습니다. 또한 정부 및 다른 기관들에 회사의 최신 보안 맞춤형 모델에 대한 '신뢰할 수 있는 접근 권한'을 제공하기 위한 국제적인 협력을 확대하고, Codex Security 스캐너를 앱 플러그인으로 출시하는 등 사이버 보안에 중점을 둔 수많은 발표를 진행했습니다.

AI 산업 전반의 발전으로 인해 중요한 오픈소스 프로젝트들이 뒤처질 위험이 커지고 있는 상황 속에서, OpenAI는 월요일에 연구 중심의 저명한 보안 기업인 Trail of Bits와 취약점 관리 기업인 HackerOne 및 Calif와 협력하여 'Patch the Planet'으로 알려진 프로젝트를 시작한다고 밝혔습니다. 이 프로젝트는 이미 오픈소스 유지보수 담당자들에게 무료 보안 컨설팅 서비스를 제공하기 시작했으며, 이는 단순히 취약점을 찾고 패치하는 것을 넘어 코드베이스를 강화하고 AI 보안 도구를 개발 프로세스에 통합할 수 있도록 돕기 위함입니다. 이 계획의 핵심은 현재의 보안성과 장기적인 회복 탄력성을 지속 가능한 방식으로 향상시키기 위해 가능한 한 많은 오픈소스 프로젝트에 맞춤형 지원을 제공하는 것입니다.

Trail of Bits의 CEO이자 공동 창립자인 Dan Guido는 "Patch the Planet은 AI 버그 헌팅 도구보다 한발 앞서 나가기 위해 오픈소스 소프트웨어를 돕는 인터넷 규모의 노력"이라며, "동시에 오픈소스 커뮤니티가 AI 코딩 도구의 단점뿐만 아니라 이점도 볼 수 있도록 돕는 노력이기도 하다"고 말했습니다. 주로 자원 봉사로 구성되어 한정된 리소스로 필수적이고 널리 쓰이는 소프트웨어를 유지하는 오픈소스 개발자들은 이미 버그 리포트를 따라가는 데 애를 먹고 있는 경우가 많습니다. 최근 몇 달간 AI 취약점 헌팅이 증가하면서 AI가 생성한 조잡한(slop) 리포트들이 쌓이고, 우선순위를 정하기 어렵게 만들며 제한된 시간과 주의력을 중대한 결함에서 다른 곳으로 빼앗김에 따라 많은 유지보수 담당자들에게 이 미해결 과제들은 감당할 수 없는 것처럼 느껴집니다.

OpenAI의 사이버 기술 책임자인 Fouad Matin은 유지보수 담당자들이 "오픈소스에 대한 사랑으로 일을 하고 있지만, 지금은 쓸모없는 CVE(공통 취약점 노출)를 검토하는 데 갇혀 있다"고 말했습니다. 그는 Patch the Planet에 대해 "우리가 효과적으로 한 것은 코드베이스 평가, 잠재적 리포트 검증, 패치 생성 및 적용과 같은 유지보수 담당자의 부담을 줄이기 위해 토큰 측면에서 가능한 한 효율적으로 만든 것"이라고 덧붙였습니다. 이어 "소프트웨어 세계의 가능한 한 많은 부분을 실제로 패치하기 위해 토큰이든 인력이든 상관없이 비용을 상쇄하고 싶다"고 밝혔습니다. 또한 Matin은 올해 초부터 연구 프리뷰 단계였던 Codex Security 스캐너의 경우, OpenAI가 오픈소스 및 개인용 코드 사용 모두에 대해 "약 20조 토큰 규모"로 사용료를 보조해왔다고 덧붙였습니다.

현재 30개 이상의 오픈소스 프로젝트가 Patch the Planet에 참여하고 있으며, 시작을 앞둔 추가 프로젝트들도 준비 중입니다. 이 프로젝트를 시작하기 위해 Trail of Bits는 최근 5일간의 개막 스프린트를 진행했으며, 이 기간 동안 전 직원의 약 5분의 1에 해당하는 25명의 엔지니어가 다양한 유지보수 담당자들과의 협업에 동시에 착수했습니다. OpenAI와 Trail of Bits에 따르면 이 프로젝트는 첫 주만에 이미 수백 개의 버그를 발견하고 수십 개의 패치를 만들어냈습니다. Guido는 OpenAI의 자금 지원과 무제한 모델 액세스를 통해 Trail of Bits가 Patch the Planet 작업에 대한 강도 높은 헌신을 장기적으로 계속할 계획이라고 밝혔습니다.

Guido는 "대규모 오픈소스 보안 문제를 다룰 기회를 갖는 것은 매우 드문 일"이라며, "Patch the Planet은 일률적인 접근 방식이 아닙니다. 우리는 모든 프로젝트의 유지보수 담당자들과 대화하며 더 나은 테스트 인프라를 구축하거나, 맞춤형 퍼저(fuzzer)를 만들거나, 프로젝트 전반의 기술적 데이터를 정리하는 등 그들의 최우선 과제가 무엇인지 파악합니다. 그것이 바로 그들이 더 빠르게 작업하고, 더 빠르게 운영하며, 더 빠르게 패치할 수 있게 만들어줄 것이기 때문입니다." 월요일에 있었던 OpenAI의 발표는 경쟁사인 Anthropic의 움직임에 대응하여 이루어졌습니다.

원문 보기
원문 보기 (영어)
Comment Loader Save Story Save this story Comment Loader Save Story Save this story As fears about AI hacking capabilities grow, OpenAI on Monday made a slew of cybersecurity-focused announcements, including an improved version of its limited-access security-specialized model GPT-5.5-Cyber, expanded international work with governments and other institutions to give them “trusted access” to the company's latest cybersecurity-focused models, and releasing its Codex Security scanner as an app plugin. As advances across the AI industry leave critical open source projects at increasing risk of falling behind, though, the company also said on Monday that it is launching an effort known as Patch the Planet, founded with the prominent research-focused security firm Trail of Bits and in collaboration with vulnerability management firms HackerOne and Calif. The project has already begun its work offering free security consulting services to open source maintainers to not only help them find and patch vulnerabilities, but also support them in strengthening their codebases and incorporating AI security tools into their development process. The idea is to give individualized support to as many open source projects as possible to improve both their current security and longterm resilience in a way that will actually be sustainable. “Patch the Planet is an internet-scale effort to help open source software get ahead of AI bug hunting tools,” says Trail of Bits CEO and cofounder Dan Guido. “But it's also an effort to help the open source community see the benefits and not just the downsides of AI coding tools.” Open source developers—typically volunteers keeping critical and widely used software afloat with few resources—are often already struggling to keep up with bug reports. The rise of AI vulnerability hunting in recent months has, for many maintainers, made that backlog feel insurmountable as AI-generated slop reports stack up, making it difficult to prioritize and pulling already limited time and attention away from critical flaws. Maintainers “do their work out of love of open source and now they’re stuck reviewing slop CVEs,” says OpenAI's cyber tech lead Fouad Matin. With Patch the Planet, he says, “what we’ve effectively done is make it as efficient from a token perspective as possible to reduce the burden for maintainers—code base assessments, validating potential reports, creating patches, and landing them. We want to offset costs, whether it's tokens or people power, to actually patch as much of the world of software as possible.” Matin adds that for its Codex Security scanner, which has been in research preview since earlier this year, OpenAI has been subsidizing usage for both open source and private code “to the tune of 20 trillion tokens.” More than 30 open source projects are already participating in Patch the Planet with more in the pipeline to start. To launch the project, Trail of Bits recently conducted a five day opening sprint in which it had 25 engineers, or roughly a fifth of its workforce, simultaneously working on collaborations with an array of maintainers. OpenAI and Trail of Bits say the project has already uncovered hundreds of bugs and produced dozens of patches in just its first week. And Guido says that with funding from OpenAI as well as unmetered model access, Trail of Bits plans to continue its intense commitment to Patch the Planet work long term. “It’s so rare that we get the opportunity to work on large scale open source security issues,” Guido says. “And Patch the Planet is not a one size fits all. We speak to all the maintainers for every single project and figure out what their highest priorities are, whether it’s building better testing infrastructure or custom fuzzers or just cleaning up technical data across the project because that’s what’s going to make them work faster and operate faster and patch faster.” Monday's announcements by OpenAI come as its competitor Anthropic had to pull its new Fable 5 and Mythos 5 models off the market earlier this month amid fear from the Trump administration about AI cybersecurity capabilities . The White House decision to hit OpenAI with export controls on the models came after Anthropic publicly released the Mythos-grade Fable 5 with blocks on its advanced biological and cybersecurity capabilities—protections the administration feared were not adequate. OpenAI's announcements on Monday, including the new checkpoint of GPT-5.5-Cyber, are all part of the company's limited “Trusted Access for Cyber” program and do not involve a public release. But with both Anthropic and OpenAI preparing for IPOs, competition clearly continues regardless of which products are currently on the market. In its GPT-5.5-Cyber announcement, for example, OpenAI points out that the model scores 85.6 percent on the benchmark assessment known as CyberGym, an improvement from a previous version of GPT-5.5-Cyber. The performance also beats Anthropic's Mythos 5, which scored 83.8 percent. Amid this AI cybersecurity race, the Five Eyes intelligence alliance warned in an unusual joint statement on Monday that “frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months. … In this environment, cyber resilience is integral."
관련 소식