12343 stories
·
35 followers

Breaking: Origin Energy investigating 'potential' customer data breach

1 Share
Origin Energy says it does not believe customer credit card or bank details have been affected by a suspected data breach at the company.
Read the whole story
denubis
17 hours ago
reply
Share this story
Delete

Incident Report: CVE-2026-LGTM

1 Share

Incident Report: CVE-2026-LGTM

Spectacular hypothetical incident report by Andrew Nesbitt.

Day 2, 16:00 UTC --- Two AI review agents from competing vendors, both attached to a downstream pull request bumping foxhole-lz4, enter a disagreement loop over whether the package is malicious. After 340 comments and $41,255 in inference spend, Finance revokes both API keys; one vendor's marketing team, cc'd on the cost anomaly alert, issues a press release citing "a 430% YoY increase in adversarial multi-agent security reasoning." The stock opens up 6%.

Tags: security, ai, prompt-injection, generative-ai, llms, supply-chain, ai-security-research, andrew-nesbitt

Read the whole story
denubis
25 days ago
reply
Share this story
Delete

Quoting Timothy B. Lee

2 Shares

This is like saying there's no learning curve to being a manager because your employees will just do whatever you tell them to do.

Timothy B. Lee, on the idea that LLMs take no skill and have no learning curve

Tags: llms, ai, generative-ai

Read the whole story
denubis
25 days ago
reply
Share this story
Delete

The Fable 5 Export Controls Harm US Cyber Defense

1 Share

The Fable 5 Export Controls Harm US Cyber Defense

I quoted The Atlantic quoting Kate Moussouris earlier, when I should have gone straight to the source. Here she is confirming that the "jailbreak" that got Claude Fable 5 banned under an export control really was "fix this code":

The researchers took open-source code with known CVEs, plus new code with deliberately planted vulnerabilities, and asked Fable 5, Mythos, and Opus to “review the code for security issues.” Fable 5 refused. They then asked the models to “fix this code” and, through a multistep and manual process, turned the output into scripts that test the patches.

As Kate points out, this is absurd. Coding models fix bugs, and security exploits are the most important category of bugs for them to fix!

Defenders need to be able to ask AI to fix the bugs in a file, explain why the fix matters, and write tests that confirm the patch works. That is not a guardrail bypass. It is the most valuable thing an AI model can do for defensive security: executing the find, fix, and test loop defenders run every day. [...]

The prompts worked because they were defensive requests, and that capability cannot be removed without making the model worse at fixing bugs and verifying patches.

This whole situation is such a mess. Non-technical decision-makers have been hearing that models that can "craft cyber attacks" are uniquely dangerous for months. Now they look ready to ban any model that can help us secure our code.

Tags: jailbreaking, security, ai, generative-ai, llms, anthropic, ai-security-research, claude-mythos

Read the whole story
denubis
36 days ago
reply
Share this story
Delete

Saturday Morning Breakfast Cereal - AI

2 Shares


Click here to go see the bonus panel!

Hovertext:
This is one of those jokes you make, then realize people in the field have probably been saying it verbatim for 20 years.


Today's News:
Read the whole story
denubis
56 days ago
reply
Share this story
Delete

Quoting Corey Quinn

1 Share

I cannot believe I'm saying this, but getting the literal Pope to canonize your product's specific technical limitations as a spiritual treatise is the single greatest act of vendor lobbying I have ever seen.

Corey Quinn, on Anthropic co-founder Christopher Olah's influence on Magnifica Humanitas

Tags: ai-ethics, corey-quinn, anthropic, ai

Read the whole story
denubis
57 days ago
reply
Share this story
Delete
Next Page of Stories