Daily Beirut

World

Free AI Cracks TikTok—What Happened?

A cybersecurity startup called DepthFirst demonstrated that free, open-source Chinese AI models can identify and exploit software vulnerabilities. In a video shared with The Washington Post, an employee remotely accessed a smartphone's camera and photo album while using TikTok.

··1 min read
Free AI Cracks TikTok—What Happened?
Share

DepthFirst, a cybersecurity startup, revealed that free, open-source Chinese AI models can be used to find and exploit software vulnerabilities.

In a video demonstrating the company’s capabilities and shared with The Washington Post, one of DepthFirst’s employees managed to remotely access the camera and photo album on a smartphone being used to browse the TikTok app.

This was achieved by exploiting a chain of software vulnerabilities within the popular app. The hack was conducted for experimental purposes only and did not target real users.

The AI system developed by the company detected flaws in open-source code used by TikTok before the company was notified, confirmed the issues, and fixed them, according to messages seen by the newspaper.

DepthFirst uses the system to help clients strengthen their defenses. CEO Qasim Methani said the company has uncovered dozens of critical vulnerabilities in software used by millions of people.

These developments come as American companies like Anthropic and OpenAI restrict the capabilities of their "Claude" and "ChatGPT" models in cybersecurity tasks, allowing full use only after verification for select users and organizations. In contrast, Chinese models such as "DeepSeek" and Z.ai allow almost anyone to download and modify them for free.

John Hultquist, senior analyst at Google’s Threat Intelligence Group, said wider availability of this technology makes advanced attackers more capable and lowers the barrier for those with limited skills to carry out cybercrimes.

Unit 42, a unit of Palo Alto Networks, reported using AI-powered tools to analyze nearly 4,000 open-source software projects and discovered over 14,000 confirmed vulnerabilities, more than 99% of which had never been reported before.

They also identified attacks where perpetrators used over 50 techniques to breach a European software company within 10 hours—a task that typically would have taken more than 10 days to complete.

Add Daily Beirut to your Google News feed to get the latest first.
Share