I recently found two very interesting Linux binaries uploaded to Virustotal.
I call this malware 'GTPDOOR'.
GTPDOOR is a 'magic/wakeup' packet backdoor that uses a novel C2 transport protocol: GTP (GPRS Tunnelling Protocol), silently listening on the GRX network (1/n) 🧵
GPT-4 is getting worse over time, not better.
Many people have reported noticing a significant degradation in the quality of the model responses, but so far, it was all anecdotal.
But now we know.
At least one study shows how the June version of GPT-4 is objectively worse than the version released in March on a few tasks.
The team evaluated the models using a dataset of 500 problems where the models had to figure out whether a given integer was prime. In March, GPT-4 answered correctly 488 of these questions. In June, it only got 12 correct answers.
From 97.6% success rate down to 2.4%!
But it gets worse!
The team used Chain-of-Thought to help the model reason:
"Is 17077 a prime number? Think step by step."
Chain-of-Thought is a popular technique that significantly improves answers. Unfortunately, the latest version of GPT-4 did not generate intermediate steps and instead answered incorrectly with a simple "No."
Code generation has also gotten worse.
The team built a dataset with 50 easy problems from LeetCode and measured how many GPT-4 answers ran without any changes.
The March version succeeded in 52% of the problems, but this dropped to a pale 10% using the model from June.
Why is this happening?
We assume that OpenAI pushes changes continuously, but we don't know how the process works and how they evaluate whether the models are improving or regressing.
Rumors suggest they are using several smaller and specialized GPT-4 models that act similarly to a large model but are less expensive to run. When a user asks a question, the system decides which model to send the query to.
Cheaper and faster, but could this new approach be the problem behind the degradation in quality?
In my opinion, this is a red flag for anyone building applications that rely on GPT-4. Having the behavior of an LLM change over time is not acceptable.
Have you noticed any issues when using GPT-4 and ChatGPT lately? Do you think these problems are overblown?
Our incident responders recently battled TheDukes/CozyBear/APT29 out of a customer environment. We also developed tooling to help investigate the timeline of the breach. We added 3 techniques for the analysis & timestamp enrichment of Shimcache entries https://t.co/uQGERBDLHY
New report from us: ”No Pineapple”.
We asses that this attack campaign is coming the 3rd Bureau of North Korean People’s Army. We believe North Korea used this attack for technological and commercial espionage.
https://t.co/Cwk17ZOhqN
Hello @Uber! We know breaches suck. Wanted to reach out and support with some interesting information on the #uberhack. If you need any more details, feel free to contact us.
#FightAgainstCybercrime
#OmaPosti alkanut käyttää norjalaista Neomics-maksupalvelua, joka vaatii 90 pv:n pääsyn kaikkiin tilitietoihin, myös vuoden tilihistoriaan. Ei kuulosta #GDPR mukaiselta tietojen minimoinnilta? Miksi tällainen, @Postigroup? Olen saanut huolestuneilta kysymyksiä, varmaan tekin.
@jarnomn @THUotila Uusittiin sähköt ja telekaapeloinnit taloon viimevuonna, asensin CAT6 kaapelit ja tv.lle antennikaapelin. Tuo CAT6 taitaa vaan olla kustanustehokkain omakotitaloon.
#Poliisi'n tietoon on tullut lähiaikoina aiempaa enemmän venäjänkielisiä kalastelupuheluita. Puheluissa venäjää puhuva soittaja on esittäytynyt viranomaiseksi tai pankkivirkailijaksi ja pyrkinyt saamaan uhrin pankkitietoja tai uhrin tekemään rahasiirtoja.
I'm excited to release a tool that I wrote at @countercept to help triage Windows event logs.
Chainsaw is a RUST CLI tool to quickly search and hunt through event logs. It supports @sigma_hq detection rules to identify potential threats.
More info here: https://t.co/BCluN5Kx2W
Mass exploitation of Atlassian Confluence CVE-2021-26084 is ongoing and expected to accelerate. Please patch immediately if you haven’t already— this cannot wait until after the weekend.
Some PowerShell Empire stagers from Aug 16th using localhost[.]run as C2 proxy @localhost_run:
126bf4bd512630.localhost[.]run
a9cf9ed2ded30d.localhost[.]run
https://t.co/uwd5VRoQiH