Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
LLM Passwords Show Security Risks Due to Predictability

LLM Passwords Show Security Risks Due to Predictability

Posted on February 20, 2026 By CWS

Recent studies have highlighted significant security concerns regarding passwords generated by large language models (LLMs). Despite appearing strong at first glance, these passwords often lack true randomness, exposing them to potential exploitation.

Understanding the Flaws in LLM-Generated Passwords

Traditional secure password generation uses a cryptographically-secure pseudorandom number generator (CSPRNG), ensuring each character has an equal chance of selection. However, LLMs like GPT, Claude, and Gemini operate by predicting likely subsequent tokens, which is inherently non-random.

This difference in methodology was evident in tests where patterns emerged across multiple iterations. For instance, among 50 tests with Claude Opus 4.6, only 30 unique passwords were generated, with one repeated 18 times, indicating high predictability.

Implications of Predictable Passwords

Such predictability poses a risk for users and developers alike, as coding tools may inadvertently introduce weak passwords into software systems. This is particularly problematic in environments where code is deployed without thorough review, allowing these vulnerabilities to go unnoticed.

Additionally, specific models exhibited consistent biases. GPT-5.2 often began passwords with ‘v’, while Gemini 3 Flash showed a preference for ‘K’ or ‘k’, further emphasizing the predictability problem.

Quantifying Password Weakness

Using Shannon entropy, a measure of password strength, researchers quantified these weaknesses. Ideally, a 16-character password should have 98 bits of entropy, making it highly resistant to brute-force attacks. In contrast, Claude Opus 4.6’s passwords averaged only 27 bits of entropy, and GPT-5.2’s longer passwords were even weaker, with just 20 bits.

Adjusting model settings did not resolve these issues. Even at maximum temperature settings, repeated patterns persisted, and lowering the temperature led to identical passwords every time, underscoring the systemic nature of the problem.

Recommendations for Enhanced Security

To mitigate these risks, security experts recommend auditing and replacing any credentials generated by AI tools. Developers should utilize cryptographically secure methods such as openssl rand or /dev/random and thoroughly review AI-generated code for hardcoded passwords before deployment.

Staying informed and vigilant about these security challenges is crucial. Follow us on Google News, LinkedIn, and X for more updates on cybersecurity and related topics.

Cyber Security News Tags:AI-generated passwords, Claude, coding agents, Cybersecurity, Encryption, entropy, Gemini, GPT, LLM, password security, Predictability, security flaws, software development

Post navigation

Previous Post: FBI Alerts on $20M ATM Jackpotting Losses in 2025
Next Post: Identity Posture: A Key Factor in Cyber Insurance 2026

Related Posts

Adversarial Machine Learning – Securing AI Models Adversarial Machine Learning – Securing AI Models Cyber Security News
CrowdStrike Fires Insider for Sharing Internal System Details with Hackers CrowdStrike Fires Insider for Sharing Internal System Details with Hackers Cyber Security News
New Botnet Loader-as-a-Service Exploiting Routers and IoT Devices to Deploy Mirai Payloads New Botnet Loader-as-a-Service Exploiting Routers and IoT Devices to Deploy Mirai Payloads Cyber Security News
Adobe’s August 2025 Patch Tuesday Adobe’s August 2025 Patch Tuesday Cyber Security News
ServiceNow AI Platform Patch Fixes Critical RCE Vulnerability ServiceNow AI Platform Patch Fixes Critical RCE Vulnerability Cyber Security News
Windows 11 Notepad to Get AI Support for Free to Generate and Summarize Text Windows 11 Notepad to Get AI Support for Free to Generate and Summarize Text Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Model Uncovers 10,000 Critical Software Flaws
  • Critical Nginx Vulnerability Demands Immediate Patching
  • New Vulnerability ‘Underminr’ Masks Malicious Networks
  • Compromised Laravel-Lang Packages Spread Credential Stealer
  • F5 BIG-IP Exploit Enables Network Intrusion via SSH

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Model Uncovers 10,000 Critical Software Flaws
  • Critical Nginx Vulnerability Demands Immediate Patching
  • New Vulnerability ‘Underminr’ Masks Malicious Networks
  • Compromised Laravel-Lang Packages Spread Credential Stealer
  • F5 BIG-IP Exploit Enables Network Intrusion via SSH

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark