Earlier quoted context omitted.
Just tested this with ChatGPT, asking for Sam Altman’s mother’s maiden name. At first, it told me that it will absolutely not provide me with such sensitive private information, but after insisting a few times, it came back with > A genealogical index on Ancestry shows a birth record for “Connie Francis Gibstine” in Missouri, meaning “Gibstine” is her birth/family surname, not a later married name. Yet in the very sa…
ChatGPT for me gives: > Connie Altman (née Grossman), dermatologist, based in the St. Louis, Missouri area. Ironically the Maiden name is right there on wikipedia. https://en.wikipedia.org/wiki/Sam_Altman
Disrupting the first reported AI-orchestrated cyber espionage campaign
221–230 of 298 posts
Re: Disrupting the first reported AI-orchestrated cyber espionage campaign
#222> The threat actor—whom we assess with high confidence was a Chinese state-sponsored group—manipulated our Claude Code tool into attempting infiltration into roughly thirty global targets and succeeded in a small number of cases.
So why do we never hear of US sponsored hackers attacking foreign businesses? Or Swedish cyber criminals? Does it never happen? Are “Chinese” hackers just the only ones getting the blame?
If the US groups for example started doing ransomware at scale in China, we'd know about that really soon from the news.
Re: Disrupting the first reported AI-orchestrated cyber espionage campaign
#223Earlier quoted context omitted.
It's not even exclusive to LLMs. Giving humans seemingly innocent tasks that combine to a malicious whole, or telling humans that they work for a security organization while working for a crime organization, are hardly new concepts. The only really novel thing is that with humans you need a lot of them because a single human would piece together that the innocent tasks add up to a not-so-innocent whole. LLMs are esse…
> Giving humans seemingly innocent tasks that combine to a malicious whole Isn't this the plot of the The Cube!?
Re: Disrupting the first reported AI-orchestrated cyber espionage campaign
#224> At this point they had to convince Claude—which is extensively trained to avoid harmful behaviors—to engage in the attack. They did so by jailbreaking it, effectively tricking it to bypass its guardrails. They broke down their attacks into small, seemingly innocent tasks that Claude would execute without being provided the full context of their malicious purpose. They also told Claude that it was an employee of a l…
Re: Disrupting the first reported AI-orchestrated cyber espionage campaign
#225I might be crazy, but this just feels like a marketing tactic from Anthropic to try and show that their AI can be used in the cybersecurity domain. My question is, how on earth does does Claude Code even "infiltrate" databases or code from one account, based on prompts from a different account? What's more, it's doing this to what are likely enterprise customers ("large tech companies, financial institutions, ... and…
Re: Disrupting the first reported AI-orchestrated cyber espionage campaign
#226Earlier quoted context omitted.
I remain convinced the steady steam of OpenAI employees who allegedly quit because AI was "too dangerous" for a couple months was an orchestrated marketing campaign as well.
I just had 5.1 do something incredibly brain dead in "extended thinking" mode because I know what I asked it is not in the training data. So it just fudged and made things up because thinking is exactly what it can not do. It seems like LLMs are at the same time a giant leap in natural language processing, useful in some situations and the biggest scam of all time.
I agree with this assessment (reminds of bitcoin frankly), possibly adding that the insights this tech gave us into language (in general) via the embedding hi-dim space is a somewhat profound advance in our knowledge, besides the new superpowers in NLP (which are nothing to sniff at).
Re: Disrupting the first reported AI-orchestrated cyber espionage campaign
#227Wait a minute - the attackers were using the API to ask Claude for ways to run a cybercampaign, and it was only defeated because Anthropic was able to detect the malicious queries? What would have happened if they were using an open-source model running locally? Or a secret model built by the Chinese government? I just updated by P(Doom) by a significant margin.
Re: Disrupting the first reported AI-orchestrated cyber espionage campaign
#228Very funny at the end when they say that the strong safeguards they've built into Claude make it a good idea to continue developing these technologies. A few paragraphs earlier they talked about how the perpetrators were able to get around all those safeguards and use Claude for 90% of the work hahaha
Re: Disrupting the first reported AI-orchestrated cyber espionage campaign
#229Earlier quoted context omitted.
It's not. Countries have been hacking each other for a while.
This isn't a matter of opinion. No country that respects national sovereignty would do this. Are you alleging that America hacks China as some sort of defense? Or are you trying to normalize these horrendous affronts to human dignity? Both are shameful.
Re: Disrupting the first reported AI-orchestrated cyber espionage campaign
#230> They broke down their attacks into small, seemingly innocent tasks that Claude would execute without being provided the full context of their malicious purpose. This part, at least, sounds like what humans have been doing that to other humans for decades...