A stupid but helpful agent is worse for a bad actor than a good agent that refuses
Disrupting the first reported AI-orchestrated cyber espionage campaign
161–170 of 298 posts
Re: Disrupting the first reported AI-orchestrated cyber espionage campaign
#162Guardrails in AI are like a $2 luggage padlock on a bicycle in the middle of nowhere. Even a moron, given enough time, and a little dedication, will defeat it. And this is not some kind of inferiority of one AI manufacturer over another. It's inherent to LLMs. They are stupid, but they do contain information. You use language to extract information from them, so there will always be a lexicographical way to extract said information (or make them do things).
> This raises an important question: if AI models can be misused for cyberattacks at this scale, why continue to develop and release them? The answer is
Money.
Re: Disrupting the first reported AI-orchestrated cyber espionage campaign
#163Re: Disrupting the first reported AI-orchestrated cyber espionage campaign
#164Does the fact that you can arbitrarily “jailbreak” AI with increasingly sophisticated abilities ring any alarm bells? Imagine being able to “jailbreak” nuclear warheads. If this were the case, nobody would develop or deploy them.
No need to break them. Their access code was 0000, everybody knew that
Re: Disrupting the first reported AI-orchestrated cyber espionage campaign
#165I might be crazy, but this just feels like a marketing tactic from Anthropic to try and show that their AI can be used in the cybersecurity domain. My question is, how on earth does does Claude Code even "infiltrate" databases or code from one account, based on prompts from a different account? What's more, it's doing this to what are likely enterprise customers ("large tech companies, financial institutions, ... and…
that's borderline tautological; everything a company like Anthropic does, in the public eye, is pr or marketing. they wouldn't be posting this if it wasn't carefully manicured to deliver the message that they want it to. That's not even necessarily a charge of being devious or underhanded.
Re: Disrupting the first reported AI-orchestrated cyber espionage campaign
#166Re: Disrupting the first reported AI-orchestrated cyber espionage campaign
#167Earlier quoted context omitted.
reminds me of the YouTube ads I get that are like "Warning: don't do this new weight loss trick unless you have to lose over 50 pounds, you will end up losing too much weight!". As if it's so effective it's dangerous.
I remain convinced the steady steam of OpenAI employees who allegedly quit because AI was "too dangerous" for a couple months was an orchestrated marketing campaign as well.
Re: Disrupting the first reported AI-orchestrated cyber espionage campaign
#168Earlier quoted context omitted.
I took it as an honest question, but the quotations mean you're probably right. For the record, it's still a widely used term in DEI contexts, even though there has been some criticism and alternatives promoted: https://en.wikipedia.org/wiki/Person_of_color
Person of color is very different than colored
Re: Disrupting the first reported AI-orchestrated cyber espionage campaign
#169Anyone using Claude for processing sensitive information should be wondering how often it ends up in front of a humans eyes as a false positive
Re: Disrupting the first reported AI-orchestrated cyber espionage campaign
#170 The threat actor—whom we assess with high confidence was a Chinese state-sponsored group—manipulated
Not surprised at all if this is true, but how can they be sure? Access log? They have extraordinary security team? Or some help from three letter agencies?