Really cool research from @MauroEldritch, Heiner García and https://t.co/oCW1L6mkMn. The amount of visibility they got here is pretty wild.
They set up a fake DeFi startup, hired suspected DPRK IT workers and watched how they actually worked.
A few things that stood out to me: they used dxdiag, systeminfo and wmic to profile the machine and understand the environment, then checked their exit IP before deciding everything looked safe enough to continue.
From there, they set up remote access, used AstrillVPN and VPS infrastructure as their entry points, shared 2FA codes between operators through https://t.co/sSN2jVHxnX, and relied heavily on ChatGPT/Gemini for coding, troubleshooting, translation and creating fake documents.
There’s a ton more around accounts, wallets, browser data, infrastructure and even details about the operators themselves.
The interview videos might still be my favourite part 😂
Really impressive work.
https://t.co/2NKJNGeiyp
If you’re reading about the Delta flight WiFi incident and wondering what a pineapple is, it’s a fruit. They used Mythos to get a fruit to hack the WiFi. That’s how scary AI is.
I would focus on more on cybersecurity. I don’t see “AI security” roles being a big thing, since security responsibilities fall into cyber.
There will likely be very niche (boring in my opinion) roles like AI platform manager/engineer, but they will be for things like managing access to the platforms, configuring settings, etc.
Your best bet is cybersecurity, since you will get exposure on how to secure AI. Good luck on your journey!
In my experience, it’s also easier to bypass guardrails after prompting about some other topic (often similar in nature). Then, after “gaining its trust”, you can begin asking it to do cyber stuff, and it appears more lenient and completes the requests unless you put a bunch of crazy words in your prompt.
Something like:
1. Talk about logging/basic defensive stuff
2. Once you’re a couple of prompts in, it appears to trust you more and kinda “forgets” it’s guardrails
3. You begin to mix in other/offensive topics
Working in security definitely causes unhealthy hours daily on a computer or phone researching and keeping up with things
It’s easy not to realize how many hours we spend because it comes so “naturally”. To others, it looks like phone addiction in public, but it’s research and lifelong learning
I’m trying to reduce phone screen time in public to help with this — the industry takes a toll on you
@cyb3rops Was just thinking this the other day. Also makes it easier for threat actors to run attacks by mimicking certain tradecraft, so attribution accuracy will be cooked
Thanks! I meant the USB spoofing part specifically. From my readings/knowledge, some (all?) DMAs leverage spoofing techniques to mimic external devices like network cards/antennas and whatnot.
Not a new technique, of course! Just throwing words out there for whoever, nowhere near a game cheat developer myself
@stvemillertime People forget (?) AI is human-built. We come with greed, unique thoughts/motives, ideology, etc.
More reason why open-sourcing these things is the way to go. More eyes on AI’s internals means more scrutiny and hopefully more safety, trust, etc (I hope, we’ll see)
I suppose I dislike the description of 'agents going rogue' if only because I think it is an unconscious attempt to excuse ourselves from the responsibility that we programmed a machine poorly (which is something we collectively do quite often).
NightBeacon looks cool so far (not a customer).
IMO, AI-assisted security is automated playbooks refined to boost confidence and automate long term maintenance (e.g., self-learning loops).
Cool seeing it at scale: valuable data most internal SOCs lack, so orgs can't refine agents/models like managed SOCs.
In 1-2 years products will stand out via high-value training data from incidents etc.
Keep innovating - it would be cool to OSS training data, skills, and/or MD files for teams to use in their own SOC 👌
we did it again, say hello to pi-black
go back to use your claude subscription instead of API credits
no claude code proxy
this is the first pi plugin that lets you use claude subscription and NOT API key by spoofing pi client as a normal claude code binary
we reversed engineered the system once again, exactly what we did back in april
now shipping to pi either as a custom patched standalone binary or as a standard pi plugin
@cyb3rops@shotgunner101 I also found a lot of zero days and critical vulnerabilities that are up for sale. Just needs one double click from Admin on windows
@arekfurt I agree, but it’s a hard reality when most companies are pushing for AI & we’re limited on frontier models in the states.
As soon as open source proves solid to companies, we should see massive shifts towards those
It can give you more control over its output.
AI tends to have “AI-slop” tendencies. Without MD/skill files, you deal with “general AI” instead of AI with knowledge, context, references, and instructions that better align results (code, web apps, or other) with your preferences via niche expertise.
There are experts that can explain the technical details behind model behavior but that’s a short version if u understood the question
On the front end, there are things like https://t.co/RjD9GrfJoM