<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>AI 安全 on 苏然的博客</title>
		<link>https://bml.asia/tags/ai-%E5%AE%89%E5%85%A8/</link>
		<description>Recent content in AI 安全 on 苏然的博客</description>
		<generator>Hugo</generator>
		<language>zh-CN</language>
		
		
		
		
			<lastBuildDate>Thu, 17 Sep 2026 04:19:55 +0800</lastBuildDate>
		
			<atom:link href="https://bml.asia/tags/ai-%E5%AE%89%E5%85%A8/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>AI 把黑客武装起来之后：安全成了必答题</title>
				<link>https://bml.asia/posts/exploit-before-patch/</link>
				<pubDate>Tue, 15 Sep 2026 19:36:15 +0800</pubDate>
				<guid>https://bml.asia/posts/exploit-before-patch/</guid>
				<description>&lt;p&gt;&lt;span style=&#34;text-indent:2em;display:block;&#34;&gt;大家聊 AI，多半在聊它能帮我们写多少代码、省多少人力，很少有人把它和黑客联系在一起。但最近一组数字让我改了看法：一个漏洞（可以理解成软件里的暗门）从被公开到真的被人拿去攻击，2018 年平均要 63 天，安全团队有两个月的窗口期慢慢打补丁；2023 年缩短到 5 天；到了 2025 年平均是负 7 天——意思是很多攻击在厂商还没来得及发布补丁的时候，就已经准备好了。窗口期不是变短了，是没了。&lt;/span&gt;&lt;/p&gt;</description>
			</item>
	</channel>
</rss>
