In a development that could transform vulnerability research, security researcher Matt Keeley demonstrated how artificial intelligence can now create working exploits for critical vulnerabilities before public proof-of-concept (PoC) exploits are available. Keeley used GPT-4 to develop a functional exploit for CVE-2025-32433, a critical Erlang/OTP SSH vulnerability with a maximum CVSS score of 10.0. This exploit showcases AI’s growing capabilities in cybersecurity. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. As these tools become more sophisticated, the time between vulnerability disclosure and exploit development continues to shrink, putting increased pressure on organizations to implement rapid patching strategies. Only a day after the vulnerability’s disclosure, multiple researchers had created working exploits, with Platform Security publishing their AI-assisted PoC on GitHub. The vulnerability, disclosed on April 16, 2025, affects Erlang/OTP’s SSH server implementation, allowing unauthenticated remote code execution. While AI democratizes access to security research, it potentially lowers barriers for malicious actors to develop exploits.
This Cyber News was published on cybersecuritynews.com. Publication date: Wed, 23 Apr 2025 02:00:11 +0000