LLMs are trained on how we speak, think, and feel.
That means they can be manipulated just like people.
Social engineering isn’t just a human weakness anymore, it’s also an AI vulnerability.
Let’s break down how this happens.
Social engineering isn’t just about hacking people anymore, it’s about hacking predictable minds. Psychology is the blueprint. Now combine that with AI trained on those patterns and embedded everywhere. The attack surface didn’t just grow, it exploded.
What if your AI agent is the attacker?
Token metadata, governance proposals, price feeds, transaction memos: all active injection surfaces. We're hosting a webinar on how this works in Web3 and how to defend against it.
With case studies from Drift Protocol ($285M) and Resolv Protocol ($23M).
Registration link in the comments.
@darasoba This is a great piece, and I agree with the emphasis on the ethics. Responsible design and security must be baked into the foundation of how we build and guide AI systems, not something we duct-tape on at the end.
🤖 Hacken’s DevOps AI-Agent CTF is LIVE!
Think you can outsmart an AI agent?
Now’s your chance to prove it.
Explore real AI agent attack surfaces. Solve red-team challenges. Compete for a $500 USDC prize.
Whether you’re into offensive security or just curious about AI exploits – this one’s for you.
▫️ Capture the Flag until November 10
▫️ Prize: 500 USDC
▫️ Hosted on: https://t.co/Vf7H34ZDcW
▫️ Submit flags via: [email protected]
👉 Read the blog for full details and rules: https://t.co/Egou8jLGKw
Let the flag hunt begin.
Holy shit. MIT just built an AI that can rewrite its own code to get smarter 🤯
It’s called SEAL (Self-Adapting Language Models).
Instead of humans fine-tuning it, SEAL reads new info, rewrites it in its own words, and runs gradient updates on itself literally performing self-directed learning.
The results?
✅ +40% boost in factual recall
✅ Outperforms GPT-4.1 using data it generated *itself*
✅ Learns new tasks without any human in the loop
LLMs that finetune themselves are no longer sci-fi.
We just entered the age of self-evolving models.
Paper: jyopari. github. io/posts/seal
It’s #CybersecurityAwarenessMonth, and we’re diving headfirst into AI Security.
Tomorrow’s panel’s set to break down on-chain AI. Together with pros from @NEARProtocol, @quranium_org, @SecretNetwork, and Next Encrypt, moderated by our AI Audits Lead @5m477.
Register �It’s #CybersecurityAwarenessMonth, and we’re diving headfirst into AI Security.
Tomorrow’s panel’s set to break down on-chain AI. Together with pros from @NEARProtocol, @quranium_org, @SecretNetwork, and Next Encrypt, moderated by our AI Audits Lead @5m477.
Register �It’s #CybersecurityAwarenessMonth, and we’re diving headfirst into AI Security.
Tomorrow’s panel’s set to break down on-chain AI. Together with pros from @NEARProtocol, @quranium_org, @SecretNetwork, and Next Encrypt, moderated by our AI Audits Lead @5m477.
Register �It’s #CybersecurityAwarenessMonth, and we’re diving headfirst into AI Security.
Tomorrow’s panel’s set to break down on-chain AI. Together with pros from @NEARProtocol, @quranium_org, @SecretNetwork, and Next Encrypt, moderated by our AI Audits Lead @5m477.
Register 👇
#ESETResearch has discovered the first known AI-powered ransomware, which we named #PromptLock. The PromptLock malware uses the gpt-oss:20b model from OpenAI locally via the Ollama API to generate malicious Lua scripts on the fly, which it then executes 1/6
Novel jailbreak discovered.
Not only does OpenAi putting your name in the system prompt impact the way GPT responds, but it also opens the model up to a prompt INSERTION.
Not injection.
You can insert a trigger into the actual system prompt, which makes it nigh indefensible.
Free domains are cool, but they can also open the door to free phishing, malware, and brand fakes.
Accessibility is great, but I hope security isn’t an afterthought. Anyways it’s open-source so…
we hijacked microsoft's copilot studio agents and got them to spill out their private knowledge, reveal their tools and let us use them to dump full crm records
these are autonomous agents.. no human in the loop
#DEFCON#BHUSA@tamirishaysh
To quote @jerh17, 2025 so far is a wake-up call. Our experts, including @muststopye and @5m477, shared their insights with @euroweeklynews on the state and future of Web3 security.
https://t.co/m1aLfcNz5a
LLMs are the new attack surface 💣
Our latest podcast episode with @5m477 from @hackenclub goes deep into the hidden vulnerabilities in AI
🎥 Don’t build blind. Watch now. → https://t.co/CqhWjS8pRl