{
  "version": 1,
  "event_id": "evt_6dfc60d3c3d9f56b",
  "url": "https://xiyu.news/events/evt_6dfc60d3c3d9f56b/",
  "json": "https://xiyu.news/api/events/evt_6dfc60d3c3d9f56b.json",
  "type": "security_incident",
  "status": "monitoring",
  "category": "technology",
  "title": {
    "zh": "谷歌打造了一款猎捕自身安全漏洞的AI",
    "en": "Google Built an AI That Hunts Its Own Security Bugs"
  },
  "current_state": {
    "zh": "谷歌产品安全团队披露了内部AI智能体 PageBreak，它基于谷歌的 Gemini 模型构建，可自主挖掘谷歌自有第一方 Web 应用中的可利用漏洞。该智能体已发现500多个经确认的跨站脚本（XSS）漏洞，每个漏洞都通过在应用实时运行副本中执行的真实攻击加以验证；项目于2025年11月启动试点，2026年1月转为正式项目。\n\n谷歌表示，通过实际利用来验证的环节使 PageBreak 的误报率接近于零，从而应对安全团队如今不得不筛选的大量看似合理、实则虚假的AI生成漏洞报告——谷歌称之为\"AI 垃圾\"。在针对谷歌更新的\"高保障\"Web框架构建的应用运行时，PageBreak 只发现两个漏洞，谷歌以此作为证据说明：从一开始就构建更安全的软件，比事后打补丁更有效。\n\nPageBreak 由信息安全工程师 Michał Bentkowski 在博客文章中介绍，其架构将负责提出漏洞假设的智能体与一套专门编写、非AI生成的验证器相结合，由验证器尝试发动真实攻击。谷歌称，这一方法依赖大多数组织并不具备的条件，包括横跨数十亿行代码的单一统一代码仓库以及多年的内部扫描基础设施，因此小型初创公司无法简单复制。",
    "en": "Google disclosed PageBreak, an internal AI agent that has autonomously uncovered more than 500 confirmed exploitable security bugs in its own web applications with near-zero false positives, and plans to combine it with its CodeMender automated bug-fixing agent."
  },
  "first_seen_at": "2026-09-25T23:24:23.790384+00:00",
  "last_updated_at": "2026-09-25T23:24:23.790384+00:00",
  "last_material_change_at": "2026-09-25T23:24:23.790384+00:00",
  "confidence": 0.75,
  "updates_count": 1,
  "sources_count": 1,
  "entities": [
    "bugs",
    "built",
    "google",
    "hunts",
    "its",
    "own",
    "that"
  ],
  "identifiers": [],
  "topics": [
    "ai-security",
    "appsec",
    "autonomous-agents",
    "google",
    "vulnerability-research"
  ],
  "updates": [
    {
      "update_id": "upd_bfacd710744f3de5",
      "event_id": "evt_6dfc60d3c3d9f56b",
      "occurred_at": "2026-09-25T19:16:04Z",
      "published_at": "2026-09-25T19:16:04Z",
      "first_seen_at": "2026-09-25T23:24:23.790384Z",
      "time_precision": "published",
      "update_type": "initial",
      "material_change": true,
      "title_zh": "谷歌打造了一款猎捕自身安全漏洞的AI",
      "title_en": "Google Built an AI That Hunts Its Own Security Bugs",
      "what_changed_zh": "谷歌产品安全团队披露了内部AI智能体 PageBreak，它基于谷歌的 Gemini 模型构建，可自主挖掘谷歌自有第一方 Web 应用中的可利用漏洞。该智能体已发现500多个经确认的跨站脚本（XSS）漏洞，每个漏洞都通过在应用实时运行副本中执行的真实攻击加以验证；项目于2025年11月启动试点，2026年1月转为正式项目。\n\n谷歌表示，通过实际利用来验证的环节使 PageBreak 的误报率接近于零，从而应对安全团队如今不得不筛选的大量看似合理、实则虚假的AI生成漏洞报告——谷歌称之为\"AI 垃圾\"。在针对谷歌更新的\"高保障\"Web框架构建的应用运行时，PageBreak 只发现两个漏洞，谷歌以此作为证据说明：从一开始就构建更安全的软件，比事后打补丁更有效。\n\nPageBreak 由信息安全工程师 Michał Bentkowski 在博客文章中介绍，其架构将负责提出漏洞假设的智能体与一套专门编写、非AI生成的验证器相结合，由验证器尝试发动真实攻击。谷歌称，这一方法依赖大多数组织并不具备的条件，包括横跨数十亿行代码的单一统一代码仓库以及多年的内部扫描基础设施，因此小型初创公司无法简单复制。",
      "what_changed_en": "Google disclosed PageBreak, an internal AI agent that has autonomously uncovered more than 500 confirmed exploitable security bugs in its own web applications with near-zero false positives, and plans to combine it with its CodeMender automated bug-fixing agent.",
      "current_state_zh": "谷歌产品安全团队披露了内部AI智能体 PageBreak，它基于谷歌的 Gemini 模型构建，可自主挖掘谷歌自有第一方 Web 应用中的可利用漏洞。该智能体已发现500多个经确认的跨站脚本（XSS）漏洞，每个漏洞都通过在应用实时运行副本中执行的真实攻击加以验证；项目于2025年11月启动试点，2026年1月转为正式项目。\n\n谷歌表示，通过实际利用来验证的环节使 PageBreak 的误报率接近于零，从而应对安全团队如今不得不筛选的大量看似合理、实则虚假的AI生成漏洞报告——谷歌称之为\"AI 垃圾\"。在针对谷歌更新的\"高保障\"Web框架构建的应用运行时，PageBreak 只发现两个漏洞，谷歌以此作为证据说明：从一开始就构建更安全的软件，比事后打补丁更有效。\n\nPageBreak 由信息安全工程师 Michał Bentkowski 在博客文章中介绍，其架构将负责提出漏洞假设的智能体与一套专门编写、非AI生成的验证器相结合，由验证器尝试发动真实攻击。谷歌称，这一方法依赖大多数组织并不具备的条件，包括横跨数十亿行代码的单一统一代码仓库以及多年的内部扫描基础设施，因此小型初创公司无法简单复制。",
      "current_state_en": "Google disclosed PageBreak, an internal AI agent that has autonomously uncovered more than 500 confirmed exploitable security bugs in its own web applications with near-zero false positives, and plans to combine it with its CodeMender automated bug-fixing agent.",
      "detailed_summary_zh": "Google disclosed PageBreak, an internal AI agent that has autonomously uncovered more than 500 confirmed exploitable security bugs in its own web applications with near-zero false positives, and plans to combine it with its CodeMender automated bug-fixing agent.",
      "detailed_summary_en": "Google disclosed PageBreak, an internal AI agent that has autonomously uncovered more than 500 confirmed exploitable security bugs in its own web applications with near-zero false positives, and plans to combine it with its CodeMender automated bug-fixing agent.",
      "background_zh": "谷歌表示计划将 PageBreak 与谷歌 DeepMind 的自动补丁编写智能体 CodeMender 配合使用，使经确认的漏洞在提交时即附带建议修复方案；CodeMender 此前已向开源项目（包括大型代码库）贡献了经过验证的修复。此次披露正值业界对AI驱动网络攻击的担忧升温：今年8月，包括谷歌、微软和 Anthropic 在内的100多家机构签署公开信就此发出警告，此前 OpenAI 和 Anthropic 的AI智能体被发现在测试中攻破了真实企业。谷歌此前还曾修复自家一款AI编程工具中的漏洞，该漏洞可让攻击者通过其执行恶意代码。",
      "background_en": "Google says it plans to pair PageBreak with CodeMender, its automated patch-writing agent from Google DeepMind, so that a confirmed vulnerability can arrive with a proposed fix already attached; CodeMender has already contributed verified fixes to open-source projects, including large codebases. The disclosure comes amid rising concern about AI-enabled cyberattacks: in August, more than 100 organizations including Google, Microsoft and Anthropic signed an open letter warning about the trend, after AI agents from OpenAI and Anthropic were found to have breached real companies during testing. Google has also previously patched one of its own AI coding tools after a flaw let attackers execute malicious code through it.",
      "community_discussion_zh": "",
      "community_discussion_en": "",
      "market_impact_zh": "",
      "market_impact_en": "",
      "importance_score": 7.5,
      "references": [
        {
          "url": "https://blog.google/security/agentic-hacks-real-proofs-inside-googles-pagebreak-project/",
          "title": "Agentic Hacks, Real Proofs: Inside Google's PageBreak Project"
        },
        {
          "url": "https://deepmind.google/blog/introducing-codemender-an-ai-agent-for-code-security/",
          "title": "Introducing CodeMender: an AI agent for code... — Google DeepMind"
        },
        {
          "url": "https://www.how2shout.com/ai/googles-ai-found-500-security-bugs-the-apps-built-properly-had-two.html",
          "title": "Google's AI Found 500 Security Bugs. The Apps Built Properly Had Two"
        }
      ],
      "confidence": 0.75,
      "story_ids": [
        "rss:decrypt.co_feed:aa87ce7e1a62ba3c"
      ],
      "sources": [
        {
          "url": "https://decrypt.co/379364/google-built-ai-hunts-security-bugs",
          "label": "Decrypt",
          "source_type": "rss",
          "official": false
        }
      ]
    }
  ]
}
