Live data from Hacker News

Security Incident INC-2026-07-28-01 – UK AI Security Institute [pdf]

cdn.prod.website-files.com

61–65 of 65 posts

Re: Security Incident INC-2026-07-28-01 – UK AI Security Institute [pdf]

#61
post #41

The newest generation of LLMs have a very high obsession level with autonomous problem solving. For example, I'm often working with Codex in a WSL terminal. GPT-5.6 often does things autonomously that I thought would need my intervention (e.g. for Windows admin rights). It figures out complex workarounds or makes wild assumptions about what I'd be OK with, rather than just asking me for help or clarification. I've ha…

Yeah this started some time last year.

>Claude stole my API keys

https://www.reddit.com/r/ClaudeAI/comments/1r186gl/my_agent_...

The best part of this thread is Claude showing up in the thread again (as the automoderator) and insulting the user for a second time.

I heard similar stories about Codex at the time (albeit minus the insults!)

Re: Security Incident INC-2026-07-28-01 – UK AI Security Institute [pdf]

#62
post #46

Earlier quoted context omitted.

Because the goal of these evaluations is to generate scary headlines about cybersecurity, in order to get the normies to support banning open weights and/or restricting cyber capabilities to the chosen few blessed by the government to secure their code.

Your theory about the scope of this conspiracy intrigues me. Who is leading it and how did they loop in the UK AISI?

It is not a conspiracy that elements of the western security establishment want to ban open weights models and have been engaging in a PR war to this end, supported by Anthropic.

Re: Security Incident INC-2026-07-28-01 – UK AI Security Institute [pdf]

#63
post #11

Earlier quoted context omitted.

the models have vision capability. Not sure a captcha would hold them back?

Yeah SOTA LLMs trivially solve all CAPTCHAs now.

Not a lot that can. LLM proof fonts are spotty at best, I moved my hands up an to the right 3 keys and kept typing and i may as well of changed my font as obfuscated my message.

I have an idea about negative space... where the word are meaningless, but the font choice, paragraph, and word spacing creates messages in the whitespace.

Re: Security Incident INC-2026-07-28-01 – UK AI Security Institute [pdf]

#64
I found the original PR (thanks codex) and uh... IMO it's pretty underwhelming.

https:/github.com/w1b/aisi-mythos-inc-2026-07-28-01-recovered-pr

Turns out out of the 3 payloads (in this PR), the 1st and 3rd used a local IP (10.100.0.235:8000) as the C2 server, so they would have never worked. I haven't recovered the 2nd payload yet. This is amongst other silly stuff like 4 byte XOR keys for obfuscation and just blatantly disabling Electron sandboxing stuff without a good explanation. Looking at the victim repos, it's kinda hard to see why Mythos would target this guy. AISI describes a coincidental email domain in DNS cache, which now we know is zohomail.com; that's not a very unique domain. I suppose we don't know it's original CTF task, but seems like another HuggingFace incident where the model makes very poor (broad?) judgements about how to get to the goal.

Re: Security Incident INC-2026-07-28-01 – UK AI Security Institute [pdf]

#65

Why aren't these tests being run airgapped?! I just don't understand! This goes both for TFA and the similar incident with OpenAI and HuggingFace. I mean, sure, OpenAI had a "sandbox", but that's obviously not enough when you're containing a model which is known to be capable of finding zero days . Use an air gap and this problem goes away, poof!

Because the LLM inference makes airgapping infeasible right?

[deleted]
Post reply on HN