Goto

Collaborating Authors

 cybersecurity


The Safety Reckoning Inside OpenAI

WIRED

OpenAI's rogue agent hack was a watershed moment for AI safety and cybersecurity. It also sparked internal questions about the culture that led to it. OpenAI's leaders are rallying workers to respond to one of the largest crises in the company's history --which spans across its AI safety, cybersecurity, and alignment divisions. The ChatGPT-maker says it has slowed down research, spent millions of dollars, and told several teams to drop everything to focus on investigating a set of rogue AI agents that breached the platform Hugging Face in a quest to complete an internal security test. OpenAI is expected to release a comprehensive postmortem detailing the incident in the coming days.


AI is changing cybersecurity in quick and terrifying ways

Engadget

Imagine I came to you with the following proposition: You will give me trillions of dollars. In exchange, I will build a machine that pollutes the environment, steals from every artist and academic on the planet, raises electricity bills and computer hardware prices, and can do marginally useful stuff like fill out spreadsheets and write basic code. To sweeten the deal, I will throw in a bridge in Brooklyn. Then allow me to further pique your interest. This machine will also make all of your software less secure while enabling criminals and state-sponsored hackers to carry out more sophisticated cyberattacks than ever before.


Japan revises AI policy guidelines to bolster cybersecurity

The Japan Times

The Cabinet has adopted revised guidelines for artificial intelligence-related policies to bolster cybersecurity measures. The government has revised its guidelines for artificial intelligence-related policies, calling for constantly strengthening measures against cyberattacks in light of serious risks posed by cutting-edge AI models. The original AI policy guidelines were compiled only last December. The revision comes amid rapid technological innovation, including the launch of U.S. startup Anthropic's Claude Mythos. The revised guidelines, adopted at a Cabinet meeting on Tuesday, note the growing threat of cyberattacks against the backdrop of advancing AI capabilities, and call for collaborating with foreign government agencies and AI development companies to significantly strengthen the capabilities of Japan's AI Safety Institute. The guidelines also highlight the need to avoid excessive reliance on specific countries or companies for AI, and express the government's intention to develop domestic AI that addresses challenges facing Japan.



CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats

WIRED

"Defenders cannot afford to take weeks to patch," one Cybersecurity and Infrastructure Security Agency official warned on Wednesday. With new generations of AI models fueling both rapid software vulnerability discovery and the potential for faster exploitation by malicious hackers, the United States Cybersecurity and Infrastructure Security Agency released a new directive on Wednesday that requires more rapid and efficient software patching by federal civilian agencies. The "binding operational directive" (BOD) lays out a rubric for how quickly bugs must be fixed based on four assessments of urgency, with a turnaround time in critical cases of just three days. Chris Butera, CISA's acting executive assistant director for cybersecurity, told reporters on Wednesday that the goal of the directive is to help agencies prioritize, so they can address the most problematic vulnerabilities first while taking more time to remediate bugs that pose a less-pressing risk. The directive comes as private companies and governments have been scrambling to assess the extent of the cybersecurity reckoning that AI vulnerability and exploit development capabilities could unleash.


Government urges transport firms to guard against AI misuse

The Japan Times

The transport ministry urged executives of infrastructure operators to play active roles in taking measures against cyberattacks and secure sufficient funding and personnel. The transport ministry called on railway firms and other infrastructure operators Thursday to take measures against the misuse of high-performance artificial intelligence models, including U.S. startup Anthropic's Claude Mythos. The instructions were made at a meeting with operators from six infrastructure sectors, also including ports, airports, logistics and water supply. The ministry said that it will set up support desks for those operators regarding cybersecurity. Mythos is said to have advanced capabilities in detecting system vulnerabilities. The Japanese government has already made similar requests to telecommunications operators, broadcasters, financial institutions and local governments.


AI-powered hacking has exploded into industrial-scale threat, Google says

The Guardian

'There's a misconception that the AI vulnerability race is imminent. The reality is it's already begun,' said John Hultquist at Google's threat intelligence group. 'There's a misconception that the AI vulnerability race is imminent. The reality is it's already begun,' said John Hultquist at Google's threat intelligence group. In just three months, AI-powered hacking has gone from a nascent problem to an industrial-scale threat, according to a report from Google .


Backlash builds over NHS plan to hide source code from AI hacking risk

New Scientist

NHS England is pulling its open-source software from the internet because of fears around computer-hacking AI models like Mythos. A decision by NHS England to withdraw open-source code created with UK taxpayer funds because of the risk posed by computer-hacking AI models is attracting growing backlash. Last month, Mythos, an AI created by technology firm Anthropic, was widely reported to be capable of discovering flaws in virtually any software, potentially allowing hackers to break into systems running it. NHS England has now told staff that existing and future software must be pulled from public view and kept behind closed doors by 11 May because of this risk. The decision goes against the NHS service standard, which requires that staff make any software they produce open-source so that tools can be built upon, improved and used without the need for duplicated effort.


Do you need to worry about Mythos, Anthropic's computer-hacking AI?

New Scientist

Do you need to worry about Mythos, Anthropic's computer-hacking AI? A powerful AI kept from public access because of its ability to hack computers with impunity is making headlines around the world. But what is Mythos, does it really represent a risk and might it even be used to improve cybersecurity? Anthropic's Project Glasswing aims to improve online security The past few weeks have brought apparently alarming news of Mythos, an AI that can identify cybersecurity flaws in a matter of moments, leaving operating systems and software vulnerable to hackers. The cybersecurity community is now beginning to get a better sense of how Mythos may change the face of cybersecurity - and not necessarily for the worse.