Live data from Hacker News

Disrupting the first reported AI-orchestrated cyber espionage campaign

anthropic.com

111–120 of 298 posts

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#111

Was this written by AI? If not, why not?

Maybe? Why maybe, well, I’d say both AI and their PR team. Why both? Well, because why not?

I think they’re asking because if it’s not good enough for them, why is it good enough for anyone else?

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#112
post #42

It sounds like they directly used Anthropic-hosted compute to do this, and knew that their actions and methods would be exposed to Anthropic? Why not just self-host competitive-enough LLM models, and do their experiments/attacks themselves, without leaking actions and methods so much?

> Why not just self-host competitive-enough LLM models, and do their experiments/attacks themselves, without leaking actions and methods so much? Why assume this hasn't already happened?

Why in this instance leak your actions and methods?

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#113
post #68

I might be crazy, but this just feels like a marketing tactic from Anthropic to try and show that their AI can be used in the cybersecurity domain. My question is, how on earth does does Claude Code even "infiltrate" databases or code from one account, based on prompts from a different account? What's more, it's doing this to what are likely enterprise customers ("large tech companies, financial institutions, ... and…

This isn't a security breach in Anthropic itself, it's people using Claude to orchestrate attacks using standard tools with minimal human involvement. Basically a scaled-up criminal version of me asking Claude Code to debug my AWS networking configuration (which it's pretty good at).

If it was meant as publicity its an incredible failure. They cant prevent misuse until after the fact... and then we all know they are ingesting every ounce of information running through their system.

Get ready for all your software to break based on the arbitrary layers of corporate and government censorship as it deploys.

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#114

I might be crazy, but this just feels like a marketing tactic from Anthropic to try and show that their AI can be used in the cybersecurity domain. My question is, how on earth does does Claude Code even "infiltrate" databases or code from one account, based on prompts from a different account? What's more, it's doing this to what are likely enterprise customers ("large tech companies, financial institutions, ... and…

Not saying this is definitely not a fabrication but there are multiple parties involved who can verify (the targets) and this coincides with Anthropic ban of Chinese entities

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#115
post #38

Earlier quoted context omitted.

Nix makes everything else so hard that I've seen problems with production configuration persist well beyond when they should because the cycle time on figuring out the fix due to evaluations was just too long. In fact figuring out what any given Nix config is actually doing is just about impossible and then you've got to work out what the config it's deploying actually does.

Yes, the cycle times are bad and some ecosystems and tasks are a real pain still. I also agree with you when it comes to the task of auditing every line of Nix code that factors into a given system. Nix doesn't really make things easier there. The benefit I'm seeing really comes from composition making it easier to share and direct auditing effort. All of the tricky code that's hard to audit should be relied on and a…

I think for actual Nix adoption focusing on the cycle time first would bring the biggest benefit by far because then everything will speed up. It's a bit like the philosophy behind 'Go', if the cycle is a quick one you will iterate faster, keep focus and you'll be more productive. This is not quite like that but it is analogous.

That said, I fully agree with your basic tenet about how systems should be composed. First make it work, but make deployment conditional on verified security and only then start focusing on performance. That's the right order and right now we do things backward, we focus on the happy and performant path and security is - at best - an afterthought.

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#116

Anyone using Claude for processing sensitive information should be wondering how often it ends up in front of a humans eyes as a false positive

Anyone using non-self hosted AI for the processing of sensitive information should be let go. It's pretty much intentional disclosure at this point.

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#117

Anyone using Claude for processing sensitive information should be wondering how often it ends up in front of a humans eyes as a false positive

Anyone using non-self hosted AI for the processing of sensitive information should be let go. It's pretty much intentional disclosure at this point.

Worst local (Australia) example of that

  Following a public statement by Hansford about his use of Microsoft's AI chatbot Copilot, Crikey obtained 50 documents containing his prompts...

  FOI logs reveal Australia's national security chief, Hamish Hansford, used the AI chatbot Copilot to write speeches and messages to his team. 
(subscription required for full text): https://www.crikey.com.au/2025/11/12/australia-national-secu...

It matters as he's the most senior Australian national security bureaucrat across five eyes documents (AU / EU / US) and has been doing things that makes the actual cyber security talent's eyes bleed.

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#118
post #28
post #25

>At this point they had to convince Claude—which is extensively trained to avoid harmful behaviors—to engage in the attack. They did so by jailbreaking it, effectively tricking it to bypass its guardrails. They broke down their attacks into small, seemingly innocent tasks that Claude would execute without being provided the full context of their malicious purpose. They also told Claude that it was an employee of a le…

Humans fall for this all the time. NSO group employees (etc.) think they're just clocking in for their 9-to-5.

If AI isn't better than humans then there's no point.

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#119

Earlier quoted context omitted.

Anyone using non-self hosted AI for the processing of sensitive information should be let go. It's pretty much intentional disclosure at this point.

Worst local (Australia) example of that Following a public statement by Hansford about his use of Microsoft's AI chatbot Copilot, Crikey obtained 50 documents containing his prompts... FOI logs reveal Australia's national security chief, Hamish Hansford, used the AI chatbot Copilot to write speeches and messages to his team. (subscription required for full text): https://www.crikey.com.au/2025/11/12/australia-nationa…

Holy crap that is such a bad look. That guy should immediately step down and if he doesn't he should be let go.
Post reply on HN