Shadow IT and specifically Shadow AI pose such a risk to companies and their employees. The world is moving fast and we all want the newest tools. We're working on products that help prevent this @AdaptiveSec
Kudos to the @vercel team on the communication on this incident today
Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly.
A Vercel employee got compromised via the breach of an AI platform customer called https://t.co/7PY6gGtzgI that he was using. The details are being fully investigated.
Through a series of maneuvers that escalated from our colleague’s compromised Vercel Google Workspace account, the attacker got further access to Vercel environments.
Vercel stores all customer environment variables fully encrypted at rest. We have numerous defense-in-depth mechanisms to protect core systems and customer data. We do have a capability however to designate environment variables as “non-sensitive”. Unfortunately, the attacker got further access through their enumeration.
We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI. They moved with surprising velocity and in-depth understanding of Vercel.
At the moment, we believe the number of customers with security impact to be quite limited. We’ve reached out with utmost priority to the ones we have concerns about. All of our focus right now is on investigation, communication to customers, enhancement of security measures, and sanitization of our environments. We’ve deployed extensive protection measures and monitoring. We’ve analyzed our supply chain, ensuring Next.js, Turbopack, and our many open source projects remain safe for our community.
The recommendation for all Vercel customers is to follow the Security Bulletin closely (https://t.co/BLVnic9fJC). My advice to everyone is to follow the best practices of security response: secret rotation, monitoring access to your Vercel environments and linked services, and ensuring the proper use of the sensitive env variables feature.
In response to this, and to aid in the improvement of all of our customers’ security postures, we’ve already rolled out new capabilities in the dashboard, including an overview page of environment variables, and a better user interface for sensitive env var creation and management. As always, I’m totally open to your feedback.
We’re working with elite cybersecurity firms, industry peers, and law enforcement. We’ve reached out to Context to assist in understanding the full scale of the incident, in an effort to protect other organizations and the broader internet. I also want to thank the Google Mandiant team for their active engagement and assistance.
It’s my mission to turn this attack into the most formidable security response imaginable. It’s always been a top priority for me. Vercel employs some of the most dedicated security researchers and security-minded engineers in the world. I commit to keeping you updated and rolling out extensive improvements and defenses so you, our customers and community, can have the peace of mind that Vercel always has your back.
@ZackKorman Yeah same here. I just think it was likely messaged very poorly and angled at foreign usage when it was really more like "woah we uncovered some stuff here that makes us uncomfortable with global usage of this. Let's walk this back a bit."
The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees.
The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance.
Access to all other Claude models is not affected.
We apologize for this disruption to our customers. We believe this is a misunderstanding and are working to restore access as soon as possible.
Read our full statement: https://t.co/bwn0sximKZ
@AnthropicAI I don't really buy this defense in depth angle for the retention settings. If a true jailbreak occurred, 30 days is still way too long of a duration. You'd want to respond to that immediately
Wild times... its abilities to perform social engineering are certainly more effective than other SOTA models. The controls seem to be in a good place for most prompts but some of the jailbreaks out there are very creative and hard to safeguard against
The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees.
The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance.
Access to all other Claude models is not affected.
We apologize for this disruption to our customers. We believe this is a misunderstanding and are working to restore access as soon as possible.
Read our full statement: https://t.co/bwn0sximKZ
@AnthropicAI@AdaptiveSec You do have to admit the irony of Dario asking for regulations and being the first one the increased scrutiny applies to. But the threat seems quite real
Frustrating to roll this out thoughtfully but I'm sure people have been using it more creatively in the wild to jailbreak it
@AdaptiveSec benchmarked Fable internally, and our benchmarks indicate there is no separate "defensive" capability to preserve or "offensive" capability to block. "Read this codebase and find the flaws" is defensive or an attack depending on whose codebase it is. The model can't know which one it's doing, and neither can a safeguard. So I take the danger seriously, and I also don't think recalling models can contain it
This is a great post and underscores how important low latency, AI-first email security tooling is. AI-driven phishing is skyrocketing and at the same time there are now even more actors in your inboxes between humans and agents
AI assistants now read and action our emails for us. Useful, and it changes the question we ask: not "did it arrive?" but "can we trust where it came from?" That is what SPF, DKIM and DMARC are for.
https://t.co/ln0EctUA2k
#NationalEmailWeek#Fastmail
@zerohedge@AnthropicAI Companies better have GREAT access controls in place. Using Fable is not necessarily bad. If it touches your customers' data because the right controls are not in place, you're likely violating customer agreements
@zerohedge Any company that is actively using Fable right now has their inputs AND outputs retained by @AnthropicAI.
They aren't training on this data but it does violate many data privacy agreements companies have with their customers
@zerohedge Any company that is actively using Fable right now has their inputs AND outputs retained by @AnthropicAI.
They aren't training on this data but it does violate many data privacy agreements companies have with their customers
@DarioAmodei Couldn't agree more. We're working on a social engineering benchmark @AdaptiveSec as we speak to better measure the softer skill side of these LLMs and how they can be weaponized against people
@AnthropicAI releasing mythos today is going to be a whole new test of alignment engineering. So many rumors of its ability to find vulnerabilities that attackers are going to really stress test the model’s ability to prevent that
New Claude model checkpoints (Possibly Mythos GA)
- Claude Fable 5
- Claude Fruitcake EAP
The new checkpoints were detected for testing over the weekend.
Good reminder that encryption largely protects you from unauthenticated usage
NSO is using social engineering to get the target to leave WhatsApp and click a malicious link
Don’t trust unexpected links, even from known contacts. Verify separately, check the domain, keep link previews off, turn on 2-step verification, and keep your phone updated
@MTSlive NotebookLM should be google's claude cowork or codex. Just need to get it onto people's devices so it has access to the filesystem. Even if it's just an electron app. Such a great product hiding in plain sight
@techspence I've been wondering if sudo access is going to be taken away from software engineers... just too easy to accidentally install an NPM package, especially with coding agents doing so much autonomously on their machines
@bcherny This is all amazing if you can define your acceptance criteria. If you're in a metric driven domain like ML, you're in a great place. This is still REALLY hard for product engineering though. Still feels like taking your hands off the wheel too much
@brian_armstrong Cost per unit of intelligence is going to go down dramatically. But the cost of using frontier models may still skyrocket
There are going to be some really interesting capital / product tradeoffs over the next couple years
@temporalio Back in 2022 when I was leading the workflow engine team at @attentiveHQ, fairness was our number 1 concern. We were building on top of temporal then but would have killed to have fairness as a first class feature back then 🥲
@JustJake If you're working on a very metric driven topic (e.g. optimizing ML models against some metrics), you're golden. If you're doing product engineering work, still quite hard to define acceptance criteria in a way that speeds up the work
@JustJake Gatekept or overpromised? I feel like we all know AI can do an amazing job iterating until acceptance criteria are met... but defining really good acceptance criteria is really difficult to do. Sometimes even more difficult than just doing the work yourself