Reading Anthropic's report "Detecting and countering misuse of AI: September 2026" two things are very clear:
1. The end is nigh; everyone in cyber should resign and should focus on playing World of Warcraft: Forever instead.
2. There is no such thing as usage of AI by Western Threat Actors/APTs, clearly us here in the west are all GOATED and hand-cranking our way up the attack chain.
A lot of people are missing Terence Tao’s point and thinking “mathematicians are upset that AI is better than them.” That’s not what he’s saying, and some people are forgetting that Tao is one of the most AI-pilled mathematicians out there.
His point is that when people work on discovering something, along the way they invent new concepts. Those concepts later become useful far beyond the original goal, and enables further inventions. Finding a solution does matter, but the intermediate idea is often what makes the field richer, because other people can share it and build the next thing from it.
In tech, we can use the analogy of collaborative software. We started with algorithms for merging changes in a Word document, and evolved that to concepts about versions, diffs, and merges, and later to real-time collaboration tools like Git, Google Docs, and Figma. Humans built upon these concepts and developed more powerful solutions.
Terence’s worry is that a machine automating a solution robs the field of the value of developing the intermediate discoveries in the pursuit of larger discoveries.
When automating a solution, the intermediate discoveries and invention of concepts can be buried or completely hidden in the black box. We don’t learn from them to build the next thing; it’s like we never made the invention of collaborative document editing and thus could not have the conceptual understanding to invent the next version – and since it’s hidden, we also don’t socialize them to allow other people to invent, too, a core tenet of collective discovery.
So then, in both code and math, this leads to the atrophy of development of concepts in the field.
In other words: pure ‘solution extraction’ that hides the process of discovery can leave the field with a checked-off theorem but little new insight or new questions to pursue. And it might prevent us from understanding a field deeper.
I am seeing, first-hand, that atrophying of skills in software development. We push buttons and get solutions. There is much less incentive to develop new concepts and human skill. The bet most software companies are making is that LLMs are so effective in writing code that you’re still shipping overwhelmingly more value even with human skill atrophy, and it’s the right bet IMO.
However, much of the software industry is built upon building things, not necessarily novel invention and research. In such an environment, you can say that you accept some atrophying of conceptual invention and human skill for more output.
On the other hand, sectors like math and pure sciences that are focused on invention and insight might be the hardest hit by this.
Practical/applied sciences might fall somewhere in the middle. An Alzheimer’s cure, room-temperature semiconductor, or highly effective carbon capture solution are far too valuable to sandbag and say only humans can do that to develop concepts in the ‘proper’ way. The outcome matters too much to treat the preservation of concept invention as the highest goal. Even there, though, hidden intermediates can slow the next breakthrough if nobody can see how the first one actually worked.
So the question is not “is AI allowed to solve hard problems?” It is “in this field (math, science, tech, etc.), is the answer itself the main point, or are the concepts and abstractions we use to get there also the thing we need to maintain?”
In pure math, there’s an argument that the intermediates are often more useful than the solution, and atrophy in concept development is highly detrimental to the field. Solving Navier–Stokes, contrary to what some people claim, has little practical application, and pure math might be one of those fields where just finding a solution isn’t the entire point, and can actually be contrary to the field, which is what Tao is worried about.
A bit late for New Year, New Me, but there's always time to shift to a new TTP.
Rclone use by ransomware threat actors for data exfiltration is fairly well documented with either include/exclude flags for what winds up being a clown car's worth of file extensions.
This ensures that threat actors only grab files of value that they can use to extort payment through threats of data leaks.
One of my recent investigations showed that this particular threat actor preferred instead to leverage the "--include-from" flag to copy only files and directories that match the filtering patterns, rather than ramming them through the command itself.
The eagle-eyed reader would have noticed that in this case, the usage of C:\ProgramData as a staging area is a dead giveaway. An examination of the "include-file.txt" further strengthens our suspicions.
Takeaway here is to avoid relying on just any one Indicator for detection or analysis, threat actors are always trying to get schwifty.
I sat down and did some schizo ranting for my attempt at a book I might name "Malware 4 Noobs" (no idea yet).
Here is my introduction segment, part zero (no reforms or changes made yet).
If you're noob, please read and give feedback.
https://t.co/h3p0gVpeRR
I see Anthropic is using the comparison jutsu refined by generations of asian parents in preparation for Chinese New Year gatherings:
"oh your agent escaped the lab ah, you know my agent escaped the lab 3 times earlier this year already"
In a review of our cybersecurity evaluations, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations.
Our post describes what happened, how it happened, and what we’re changing. We encourage other AI developers to perform similar reviews.
We conducted this review together with @Irregular, one of our evaluation partners, and thank them for the joint investigation and their collaboration on this post. This type of collaboration is increasingly critical to safe, rigorous evaluation of models, and we look forward to continuing to work together on security.
https://t.co/dKFCdpKd9v