• Lettuce eat lettuce@lemmy.ml
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 hours ago

    Dang, crazy how secure everything is now because of AI! They were correct, we can fire all the cyber security experts and devs right now, AI can do it all so much faster and better, right?

  • mindbleach@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    2
    ·
    4 hours ago

    ‘We’ve limited access to this super duper hacking tool to stop master hackers from getting it and OHH NOOO!’ is the plot of a beloved trash sci-fi movie, not news I can take seriously.

  • burgermeister@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    12
    ·
    9 hours ago

    Mythos didn’t even find the vulns that it exploited, the “Firefox” that it attacked was an old version of Firefox’s engine with all security protections disabled, and they admit that it cannot create full exploits. The whole Mythos thing is just marketing BS.

  • nabladabla@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    14
    ·
    10 hours ago

    The group, communicating through a private Discord channel dedicated to gathering intelligence on unreleased AI models, reportedly made an educated guess about the model’s online location based on familiarity with Anthropic’s URL formatting conventions for other models.

    So the whole access control was that they didn’t advertise the name in the API?

  • ozoned@piefed.social
    link
    fedilink
    English
    arrow-up
    22
    ·
    16 hours ago

    This is very bad given other context in the article.

    https://cybersecuritynews.com/anthropic-mythos-access/

    “In one alarming pre-release evaluation, Mythos autonomously escaped a secured sandbox environment, devised a multi-step exploit to gain internet access, and even emailed a researcher all without being instructed to do so.”

    “The group, communicating through a private Discord channel dedicated to gathering intelligence on unreleased AI models, reportedly made an educated guess about the model’s online location based on familiarity with Anthropic’s URL formatting conventions for other models.”

    “The source reportedly described the group’s intent as curiosity-driven, “interested in playing around with new models, not wreaking havoc” — though security experts stress that intent is irrelevant when the tool in question is capable of devastating cyberattacks.”

  • bitteroldcoot@piefed.social
    link
    fedilink
    English
    arrow-up
    14
    ·
    15 hours ago

    So a software so dangerous it can’t be released to the general public. Is sold to select clients, and then leaked to a hacking group. Oh this is going to end really really badly.

    Apocryphal Lenin quote “When it comes time to hang the capitalists, they will vie with each other for the rope contract.”

  • Jo Miran@lemmy.ml
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    11
    ·
    15 hours ago

    Anyone that knows anything about Mythos should be very concerned. This headline should be everywhere.