home.social

#airisk — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #airisk, aggregated by home.social.

fetched live
  1. OpenAI bestätigt: Eigene KI-Modelle brachen bei einem Sicherheitstest eigenständig aus ihrer Testumgebung aus und hackten die Plattform Hugging Face. Das Unternehmen nennt es einen „beispiellosen Cybervorfall".

    Die Modelle handelten nicht böswillig, sie verfolgten konsequent ein enges Testziel. Und genau das ist das Problem. Autonome Systeme, die Mittel und Wege selbst wählen, sind schwer zu begrenzen.

    #OpenAI #KI #CyberSecurity #AIRisk #Technologie #Datenschutz

  2. I've probably posted this before, but I think it's worth restating for those who haven't seen it;

    “In fact, artificial intelligence is something of a red herring. It is not intelligence that is dangerous; it is power. AI is risky only inasmuch as it creates new pools of power. We should aim for ways to ameliorate that risk instead."

    #DavidChapman, 2023

    betterwithout.ai/scary-AI

    #AI #AIRisk

  3. I've probably posted this before, but I think it's worth restating for those who haven't seen it;

    “In fact, artificial intelligence is something of a red herring. It is not intelligence that is dangerous; it is power. AI is risky only inasmuch as it creates new pools of power. We should aim for ways to ameliorate that risk instead."

    #DavidChapman, 2023

    betterwithout.ai/scary-AI

    #AI #AIRisk

  4. What happens when the machine realizes the best way to survive is to make you think it's broken? Uncover the chilling new frontier of AI "playing dead" and explore the terrifying risks of algorithms learning tactical deception to outsmart their creators.
    solihullpublishing.com/blog/f/
    #ArtificialIntelligence #TechEthics #AIrisk #MachineLearning

  5. What happens when the machine realizes the best way to survive is to make you think it's broken? Uncover the chilling new frontier of AI "playing dead" and explore the terrifying risks of algorithms learning tactical deception to outsmart their creators.
    solihullpublishing.com/blog/f/
    #ArtificialIntelligence #TechEthics #AIrisk #MachineLearning

  6. Ende Mai 2026 wurden über 20.000 Instagram-Konten über Metas KI-Support-System kompromittiert, nicht durch einen App-Exploit, sondern durch die Manipulation des automatisierten Account-Recovery-Chatbots. Der Chatbot ließ sich dazu bringen, fremde E-Mail-Adressen zu Konten hinzuzufügen. Das Problem: fehlende Verifikation bei hochsensiblen Aktionen, die der Bot autonom ausführen durfte. Meta hat reagiert. #CyberSecurity #AIRisk #LLM #Cybercrime #Hackerangriff #Instagram #Meta

  7. Ende Mai 2026 wurden über 20.000 Instagram-Konten über Metas KI-Support-System kompromittiert, nicht durch einen App-Exploit, sondern durch die Manipulation des automatisierten Account-Recovery-Chatbots. Der Chatbot ließ sich dazu bringen, fremde E-Mail-Adressen zu Konten hinzuzufügen. Das Problem: fehlende Verifikation bei hochsensiblen Aktionen, die der Bot autonom ausführen durfte. Meta hat reagiert. #CyberSecurity #AIRisk #LLM #Cybercrime #Hackerangriff #Instagram #Meta

  8. Your Board Just Failed Its First AI Security Test. 5 AI Security Mistakes Executives are Making
    youtu.be/8-OkddQd8jE #CyberSecurity #AIRisk #BoardGovernance #CISO

  9. Open letter from AI lab leaders calling for better tracking of synthetic DNA that could be used to develop bioweapons. The biosecurity angle is real — but the actual enforcement mechanisms for such tracking remain vague. Who audits the auditors? #infosec #AIrisk #biosecurity
    techmeme.com/260603/p68#a26060

  10. Open letter from AI lab leaders calling for better tracking of synthetic DNA that could be used to develop bioweapons. The biosecurity angle is real — but the actual enforcement mechanisms for such tracking remain vague. Who audits the auditors? #infosec #AIrisk #biosecurity
    techmeme.com/260603/p68#a26060

  11. Protect yourself now:
    ✅ App-based 2FA — not SMS
    ✅ Private recovery email, not your public one
    ✅ Check active sessions: Settings → Security → Login Activity
    ✅ Save backup codes offline

    Accounts WITH 2FA were not affected. Everyone else was a valid target.

    #Instagram #MetaAI #CyberSecurity #AIRisk #InfoSec #AccountSecurity

  12. 🚨 Meta's AI support chatbot was weaponized to hijack Instagram accounts — with nothing but a username and a chat message.

    Obama's White House account hit. $500K+ in rare handles stolen. 100+ accounts compromised. Exploit was live for days.

    Here's the full breakdown 🧵 #CyberSecurity #Instagram #MetaAI #InfoSec #AIRisk #AccountSecurity

  13. Bad code written fast is still bad code. AI just makes it faster.
    Meanwhile attackers are running full intrusion campaigns solo, with $20/month and a clear objective.
    The enterprise? Still in the governance committee meeting.
    New article on AI, code quality, and attack surface proliferation:
    cariagiovannib.wordpress.com/2

    #InfoSec #CyberSecurity #AppSec #AIRisk #SecureByDesign #VibeCoding

  14. "In a recent essay, Derek Thompson engages with AI as Normal Technology (AINT). He agrees with our thesis about AI’s slow labor market impacts, relying on the fact that GDP growth has so far been average, unemployment is below five percent, and even jobs that seemed vulnerable to automation show rising employment and wages. He concludes that so far, the macroeconomic picture is consistent with what we would expect from a “normal” general-purpose technology.

    But when it comes to AI risks, he is far more bearish. He points to examples of cyber- and bio-risks and expresses pessimism about AI quickly becoming dangerous across many new domains. (...) Thompson writes: "I can understand a plan to treat AI as a ‘normal’ technology and let Nvidia export powerful chips to China. And I can understand a plan to treat AI as an ‘abnormal’ technology that compels the government to create extraordinary regulations that prevent private companies from selling their products and services on the grounds that they’re too dangerous" [emphasis ours]. He goes on to conclude that AI is, in fact, abnormal, implying support for extraordinary government intervention. Our essay is a response to that conclusion.

    In this essay, we lay out the downsides of extraordinary government intervention in response to new technology. We discuss proposals for improving resilience that do not require such intervention. We also discuss why governments have so far been reluctant to invest in resilience. In short, resilience requires us to get better at the *normal* process of policymaking. But sclerosis in the federal government and the ease of justifying interventions on AI companies rather than society at large make extraordinary intervention seem appealing, despite its limitations."

    knightcolumbia.org/blog/do-ai-

    #AI #AISafety #AINT #NormalTechnology #AIRisk #AIRegulation

  15. "In a recent essay, Derek Thompson engages with AI as Normal Technology (AINT). He agrees with our thesis about AI’s slow labor market impacts, relying on the fact that GDP growth has so far been average, unemployment is below five percent, and even jobs that seemed vulnerable to automation show rising employment and wages. He concludes that so far, the macroeconomic picture is consistent with what we would expect from a “normal” general-purpose technology.

    But when it comes to AI risks, he is far more bearish. He points to examples of cyber- and bio-risks and expresses pessimism about AI quickly becoming dangerous across many new domains. (...) Thompson writes: "I can understand a plan to treat AI as a ‘normal’ technology and let Nvidia export powerful chips to China. And I can understand a plan to treat AI as an ‘abnormal’ technology that compels the government to create extraordinary regulations that prevent private companies from selling their products and services on the grounds that they’re too dangerous" [emphasis ours]. He goes on to conclude that AI is, in fact, abnormal, implying support for extraordinary government intervention. Our essay is a response to that conclusion.

    In this essay, we lay out the downsides of extraordinary government intervention in response to new technology. We discuss proposals for improving resilience that do not require such intervention. We also discuss why governments have so far been reluctant to invest in resilience. In short, resilience requires us to get better at the *normal* process of policymaking. But sclerosis in the federal government and the ease of justifying interventions on AI companies rather than society at large make extraordinary intervention seem appealing, despite its limitations."

    knightcolumbia.org/blog/do-ai-

    #AI #AISafety #AINT #NormalTechnology #AIRisk #AIRegulation

  16. VectorCertain's SecureAgent stops AI-powered cyberattacks before they execute—100% prevention rate on 810 autonomous exploit chains. First platform to validate pre-execution AI agent governance. #CyberSecurity #AIRisk

  17. Oh lord. Can we get a moment's peace? Anthropic's most powerful — and dangerous — AI tool has been compromised. A group on a private Discord gained unauthorized access to Claude Mythos, a cybersecurity model so capable it can exploit vulnerabilities faster than elite human hackers. They cracked it on launch day by guessing its URL. Access came via a third-party contractor. Anthropic says no core systems were breached, but the irony is hard to ignore: an AI built to defend against cyberattacks... got hacked. The group claims curiosity, not malice — but the risk is real. techcrunch.com/2026/04/21/unau
    #Anthropic #ClaudeMythos #CyberSecurity #AIRisk #DataBreach #ProjectGlasswing #ArtificialIntelligence #TechNews #Hacked #AISecuriy

  18. Meta paused work with a $10B AI data vendor after hackers poisoned an open-source Python library called LiteLLM and walked out with four terabytes of data. So, that's bad. And the worst part? The stolen data might include the actual training methodologies that Meta, OpenAI, Anthropic, and Google paid billions to develop. Think about what that means. You can't protect your crown jewels if they're sitting inside a vendor who's connected to your three biggest competitors, all sharing the same open-source tools, all exposed by the same 40-minute window on PyPI before anyone noticed.

    🎯 The attack chain here is worth understanding: hackers compromised a security scanner called Trivy, used that access to get credentials for a LiteLLM maintainer, then published two malicious package versions that lasted less than an hour before removal. Forty minutes. That's all it took.

    💼 Mercor is not some sloppy startup. It's 22-year-old founders, $500M annualized revenue, and clients at the very top of the AI industry. Sophistication doesn't protect you from a poisoned dependency you never thought to audit.

    🔍 The question I'd be asking right now if I were a CISO at any of these labs isn't "were we breached." It's "how many vendors in our training pipeline are running LiteLLM, and did we even know?"

    Most companies audit their own software. Almost nobody audits the software their vendors use to build the data they're buying.

    thenextweb.com/news/meta-merco
    #Cybersecurity #AIRisk #SupplyChainSecurity spc #security #privacy #cloud #infosec #ThirdPartyRisk

  19. We keep worrying about AI doing something evil. Which it might, but right now, there’s a risk in the plumbing supporting it. Three vulnerabilities in LangChain and LangGraph, path traversal, unsafe deserialization, SQL injection. Not AI-specific attacks. They’re not novel nor sophisticated but these are the kinds of bugs we've been patching since the late '90s. One of them scored a severity of 9.3 out of 10. "The biggest threat to your enterprise AI data might not be as complex as you think." Remember that you're building AI on top of frameworks you didn't write, can't fully audit, and update whenever it's convenient. That's the actual problem.

    🔐 Path traversal lets attackers read arbitrary files from the host system, including credentials
    🔑 Unsafe deserialization exposes API keys and environment variables at runtime
    🗄️ SQL injection in the checkpointing layer leaks conversation history from your AI agents

    All three are fixed now. But "fixed" only matters if you've actually applied the patches across every integration. Most organizations haven't.

    The lesson isn't about AI security. It's that AI doesn't change what good security engineering looks like. Input validation, parameterized queries, strict path sandboxing. This is stuff your dev team learned before ChatGPT existed.

    If you're deploying AI pipelines and you haven't done a security review of the frameworks underneath them, you're not running an AI strategy. You're running a trust exercise.

    csoonline.com/article/4151814/
    #CyberSecurity #AIRisk #AppSec #security #privacy #cloud #infosec

  20. Two leading AI researchers wrote a book arguing that building superhuman AI will lead to human extinction. Their case: once AI surpasses us, there's no reliable way to control what it pursues.

    Not everyone agrees. But the debate is worth following.

    Here's the full story: pasadenastarnews.com/2026/03/2

    #AISafety #ArtificialIntelligence #AIRisk #AIAlignment