So essentially it just compresses the attack timeline making mitigation and response no longer nice to haves or optional. Nothing new here folks just shitty cybersecurity practices being called out.
[deleted] on
[removed]
ethereal_g on
Nothing will change until there are consequences for an organization suffering a breach.
This is the problem with not having ethical guardrails in place, the opportunities for exploitation are only limited by imagination
tmdblya on
What about the DOGE hackers _inside_?
-Switch-on- on
I just want to produce some python code to start some calculations in analysis and do postprocessing afterwards with MATLAB but can’t get copilot to produce something useful
Someones_Dream_Guy on
Oh no, anyways.
VerdantPathfinder on
Maybe we shouldn’t have fired all the cybersecurity people in the government …. just a thought.
Just-Install-Linux on
Quick deploy MYTHOS
mr_birkenblatt on
Finally, someone understands COBOL. Turns out, it’s AI
FloridaMMJInfo on
So AI is a national security threat and should be made illegal to develop and own.
robbybthrow on
Why are these guys always breaching government sites to steal shit, but never breaching credit reporting agencies, predatory loan companies, etc., and “fixing” some things? Come on, y’all can do it, and the world could use that right about now.
Exponential-777 on
Flair: Ai Bad
Any-Pop-4795 on
[ Removed by Reddit ]
DramaticTry2113 on
Get those files!
Single-Use-Again on
How are ppl doing this? Wouldn’t chat be like “Yeah we don’t do malicious things like that”.
trilobyte-dev on
There was a good talk last week at a conference by a CSO who laid out how open-weight LLMs are now good enough so that state-sponsored attackers are running OpenClaw and local LLMs like Deepseek to plan and execute (infiltration, data discovery, exfiltration) attacks entirely automated and without the risk of the attacks showing up in OpenAI or Claude logs that can be traced back to them.
20 Comments
So essentially it just compresses the attack timeline making mitigation and response no longer nice to haves or optional. Nothing new here folks just shitty cybersecurity practices being called out.
[removed]
Nothing will change until there are consequences for an organization suffering a breach.
You now need a researcher account to use Claude for pentesting activities FYSA – https://claude.com/form/cyber-use-case
The real, persistent use for AI is probably going to be in cybersecurity, to fight itself
future of cybersecurity:
hacker: “claude attack government”
government: “claude stop hacker”
repeat
This is the problem with not having ethical guardrails in place, the opportunities for exploitation are only limited by imagination
What about the DOGE hackers _inside_?
I just want to produce some python code to start some calculations in analysis and do postprocessing afterwards with MATLAB but can’t get copilot to produce something useful
Oh no, anyways.
Maybe we shouldn’t have fired all the cybersecurity people in the government …. just a thought.
Quick deploy MYTHOS
Finally, someone understands COBOL. Turns out, it’s AI
So AI is a national security threat and should be made illegal to develop and own.
Why are these guys always breaching government sites to steal shit, but never breaching credit reporting agencies, predatory loan companies, etc., and “fixing” some things? Come on, y’all can do it, and the world could use that right about now.
Flair: Ai Bad
[ Removed by Reddit ]
Get those files!
How are ppl doing this? Wouldn’t chat be like “Yeah we don’t do malicious things like that”.
There was a good talk last week at a conference by a CSO who laid out how open-weight LLMs are now good enough so that state-sponsored attackers are running OpenClaw and local LLMs like Deepseek to plan and execute (infiltration, data discovery, exfiltration) attacks entirely automated and without the risk of the attacks showing up in OpenAI or Claude logs that can be traced back to them.