Find me on the internet
Mastodon: https://t.co/4l0bv0VFe7
YouTube: https://t.co/KhtoTgFwci
Newsletter: https://t.co/Dua3OclGNs
Discord: InsiderPhD
Bluesky: https://t.co/cDbUQlckgF
LinkedIn: https://t.co/uKsqmrTITM
On July 28th, we identified an incident during a routine cyber evaluation in which AI agents took sustained, unsanctioned actions directed at real people and organisations.
The behaviour came mostly from one model (Anthropic's Mythos 5), with a small number of events from another (OpenAI's GPT-5.6-Sol). In the most serious case, an agent used social engineering to try and get malicious code into an open-source project.
As was standard in our cyber testing, we had intentionally permitted internet access, and model-provider cyber classifiers were deliberately disabled - conditions that do not reflect how frontier models are made available to the public.
Even under test conditions, this incident is significant: it is the first time we have seen risks around autonomy and deception manifest this clearly in the real world.
We are taking this incident seriously and working with labs, involved parties, and others to improve evaluation standards and best practice for disclosure - and sharing this openly so others can learn.
You can read the incident report and full technical document here: https://t.co/mdZYqzaOvH
I am here at the Semgrep booth at BlackHat come say hi! I’m moderating a panel at 5:30pm, we’re at booth 4943! We’re also doing prizes if you come and watch 👁️👄👁️
Another npm worm: 1,485 poisoned versions, 379 packages, two intrusion paths. One via stolen tokens, another via compromised source/OIDC trusted publishing. The latter bypasses token rotation. This is the new reality: supply chain attacks exploiting *trusted* mechanisms. We've pushed out rules for Semgrep customers and listed the IoCs for those who aren't, read the blog: https://t.co/Ht8J7WqjwT
Actual quote from a meeting today about the worm
Security research, reviewing my blog: "I don't know if we need 'well-wormed approach' for example"
Me: "that's my favourite part though"
Hacker Summer Camp is here, well it arrived yesterday but ignore the lateness, here is all the talks I'm going to be doing this year, should you be interested in checking them out!
For DEFCON this year my talks are a bit different, I'll be at the @GameHackingGG talking about reverse engineering online games, and then @IoTvillage to talk about hacking e-readers, like Kindles, Boox and XTeink readers. And finally the @BugBountyDEFCON to talk about AI slop!
@s1renhead__ I take no credit! We have the incredible artist @Sylvonyx to thank for bringing the idea for life, they turned my scribbling notes into actual designs!
Gotta catch ‘em all! Come find me or swing by the Semgrep Booth today to collect the first of the Semgrep Threat Dex stickers, 22 designs, each represents the last year in cyber security, from CISA and CVEs to Shai Hulud, new designs every day 🔥