Tech08:31 · 6h ago

Researcher Uses Chinese AI Models to Find Security Flaws for $4 After ChatGPT Refuses

Arutz ShevaRight
Translated & summarized from Arutz Sheva by baba
The story · English

A cybersecurity experiment using various AI models revealed that Chinese AI tools could identify and suggest fixes for security vulnerabilities quickly and cheaply, while ChatGPT declined to assist. The researcher initially tried to use ChatGPT (Codex) to analyze security weaknesses in a system but was refused. They then tested Chinese models including GLM 5.2 and Deepseek, running locally or via an Israeli company to avoid sending data to China.

Within hours, these models found multiple security issues, such as a JWT key exposure and an esoteric FFMpeg vulnerability allowing external file access. The AI also identified IP spoofing risks in a closed network accessible only through a CDN and proposed effective fixes. Deepseek, though slower, produced detailed reports without exploiting vulnerabilities, while GLM actively demonstrated exploit attempts. Another model, QWEN, was used to test API attacks with malformed images and attempted SQL injection but was ultimately unsuccessful.

The entire process took about three hours and cost only $4 plus electricity, compared to an estimated $3,000 for a professional security audit. The researcher praised the AI’s thoroughness and creativity in uncovering subtle issues and noted the potential for cost-effective automated security testing using these tools.

Read the original at Arutz Sheva
Open the live terminal