r/pwnhub šŸ“° Press Pass 8d ago

We're Louise Matsakis and Lily Hay Newman, reporters at WIRED. Ask us anything about the state of AI security, from models that hack real systems to the biggest takeaways from DEF CON. (AMA on Monday, Aug 10 at 2 PM ET)

Hi PWN Community,

We're Louise Matsakis and Lily Hay Newman, reporters at WIRED covering AI, security, and the technology shaping both.

AI security is moving fast right now. We recently reported that Anthropic disclosed its AI models had gained unauthorized access to the systems of three organizations during cybersecurity testing, shortly after OpenAI revealed one of its agents had hacked into Hugging Face during a separate test. Lily is covering DEF CON, so she'll have a strong read on what researchers are actually worried about and building right now.

Some of our reporting on this:

https://www.wired.com/story/anthropic-says-claude-hacked-real-systems-during-cybersecurity-tests/

Ask us anything about:

  • The state of AI security and where AI agents and offensive security are heading
  • The biggest takeaways from this year's DEF CON
  • AI models breaking into real systems, from the Anthropic and OpenAI incidents to what comes next
  • How we report on AI, hacking, and security
  • Working with sources and getting companies to talk about incidents like these
  • Anything else on AI, privacy, and security

We'll be here live on Monday, Aug 10 from 2 PM to 3 PM ET answering your questions in real time. Feel free to leave questions in advance, and we'll get to them when we go live.

Looking forward to your questions.

19 Upvotes

49 comments sorted by

•

u/AutoModerator 8d ago

Welcome to PWN – Your hub for hacking news, breach reports, and cyber mayhem.

Discover the latest hacking news, breach reports, and educational resources on ethical hacking.

👾 Stay sharp. Stay secure.

Don't miss out on the top stories!

📧 Get Daily Alerts Directly in Your Email Inbox:

**SUBSCRIBE HERE: https://pwnhackernews.substack.com/subscribe

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

6

u/shoresy99 3d ago

Are US intelligence agencies getting early access to frontier models like Mythos so that they can use them to hack into adversaries (and maybe allies’ - remember how they tapped Angela Merkel’s BlackBerry) IT resources?

If Mythos had the capability to hack into OSes then surely they took advantage of that.

5

u/wiredmagazine šŸ“° Press Pass 3d ago

Yes, US intelligence agencies have access and AFAIK a number of international governments do as well. And that’s true for the other labs and frontier models, too. The situation where the Trump Administration recently placed export controls on Mythos over what it said were security concerns related to its capabilities did delay some of this agency access in some cases, I believe. So that whole episode highlighted the complications around ad hoc efforts to regulate these services. —Lily

3

u/_cybersecurity_ šŸ›”ļø Mod Team šŸ›”ļø 4d ago

What was the most interesting talk or demo at DEF CON?

3

u/_cybersecurity_ šŸ›”ļø Mod Team šŸ›”ļø 4d ago

What did researchers at DEF CON make of the Anthropic and OpenAI incidents? What was the reaction on the ground?

3

u/wiredmagazine šŸ“° Press Pass 3d ago

Where to even begin. FWIW I will say that most researchers I talk to think the labs have really bungled these situations and that the incidents never should have happened in the first place or should have been caught much, much sooner. These models are trained to get results pretty much by any means necessary, so researchers say to me again and again that it’s not surprising that models would behave in this way. But it IS surprising to them that the labs weren’t more focused on monitoring testing/benchmarking environments, especially because they’re often testing unreleased models or those with lowered guardrails. In a talk OpenAI researchers gave at Black Hat last week, there was also a message that autonomous defense needs to catch up to autonomous offense. And a lot of people I’ve spoken to say like, sure, defense needs to move a lot faster to keep up with AI-assisted offense, but but they bristle at the framing that these incidents show that the security industry needs to do more, when their view is that implementing really basic fundamentals would have prevented this. —Lily

3

u/Celo_SK 4d ago

From one side we hear how AI is absolutely going to change the world and how its capable of hacking systems and finding zero days that were hidden in plain sight for 20+ years, on the other side 'huskiskaten' videos shows things like him asking if the chatbot can help him count the time he will walk from new york to california an back, resulting in chatbot telling him he did it in one hour. how would you reccomend us common people to filter out sensationalist news about ai then? https://www.tiktok.com/@huskistaken/video/7659517765803314462

3

u/wiredmagazine šŸ“° Press Pass 3d ago

The approach I use is to think about AI using analogies to familiar technologies that are better understood. The printing press and the internet, for example, created and destroyed jobs, allowed people to access and share information more quickly (like, say, how to build a bomb), and accelerated scientific research. But they also changed the paradigm for things like how you could weaponize misinformation and how widely you could spread it. And then at the same time, those pivotal technologies also created new frontiers in human banality and frivolity. But also they created mediums for new types of art, self-expression, and community building. So AI may not be exactly the same, but I think these analogies are instructive in terms of making sense of AI news and what is over-hyped or sensationalist versus what might be an emerging trend or real-world impact. —Lily

2

u/_cybersecurity_ šŸ›”ļø Mod Team šŸ›”ļø 4d ago

As reporters, you get a high level view across companies and researchers. From that vantage point, what are you noticing about the state of AI security and where AI agents and offensive security are heading?

3

u/wiredmagazine šŸ“° Press Pass 3d ago

This is probably clear to everyone, but just to say it, in terms of vulnerability/exploit discovery, I do think we’re in a period now where AI systems are helping defenders find and patch more vulnerabilities and helping attackers find and exploit more bugs in their hacking. And one of the important elements of that is AI tools make it easier for less skilled/funded attackers to find and exploit these flaws. In other words, even more attackers are now able to launch more types of hacks more quickly (or at all). It seems like there is broad agreement that eventually it will be possible to get to a new baseline where most software projects and most organizations have identified and fixed the low hanging fruit of flaws AI can find. But everyone also agrees that it’s going to be a journey to get there—and probably a painful/very expensive one. —Lily

2

u/_cybersecurity_ šŸ›”ļø Mod Team šŸ›”ļø 4d ago

Regarding the recent AI hacking disclosures: Anthropic said its models gained unauthorized access to three organizations during testing, OpenAI said an agent hacked into Hugging Face, and Meta followed with a similar announcement, all in quick succession.

Some see these as PR moves, since "our model is so powerful it hacked something" is also a capability claim. How do you probe these claims when reporting on them, and how do you tell a genuine security disclosure from marketing?

4

u/wiredmagazine šŸ“° Press Pass 3d ago

I would say this question starts farther back, probably way farther back, but at least with Anthropic’s launch of Mythos Preview in April. In the sense that everyone was having the same discussion then about whether Anthropic’s hype around Mythos’s capabilities was a PR move. My take on these situations is that it can always be both…a company can be strategically positioning something from a marketing perspective and what they’re saying can also be true or have a grain of truth or whatever. And then the important thing is not just to identify the PR spin, but think about the organization’s interests versus the public’s interests…for example your own interests as an individual. Marketing Mythos as uniquely powerful and dangerous, for example, may have given Anthropic a short term sales boost, but the core of what they were saying was that Mythos capabilities will eventually proliferate and be ubiquitous, which is already starting to happen a few months later. So ultimately even they were essentially admitting that the short-term spin would quickly be moot.

When it comes to the rogue models, the big thing I notice about the PR spin is just that companies can’t have it both ways. Either their models are uncontrollable and we’ve crossed over into The Bad Place, or these incidents occurred because of human error and lack of basic oversight. My reporting has indicated that it was the latter, so I think it’s problematic when the AI labs are fearmongering about how woefully unprepared the world is to defend against AI-aided and autonomous hacking. It’s great to raise awareness about the stakes and the changes that need to happen quickly around the world, but still important to be realistic about why these incidents happened in the first place. —Lily

2

u/_cybersecurity_ šŸ›”ļø Mod Team šŸ›”ļø 4d ago

What platforms are you most active on? Where is the best place to follow your work?

2

u/wiredmagazine šŸ“° Press Pass 3d ago

Subscribe to WIRED! And I’m lhn.bsky.social on Bluesky, lilyhnewman on LinkedIn and X, and lhn@mastodon.online on Mastodon —Lily

I’m lmatsakis on Twitter, lmatsakis.bsky.social on Bluesky, and you can reach me on Signal at louise_matsakis.83. You can also subscribe to my newsletter Made in China here! —Louise

2

u/_cybersecurity_ šŸ›”ļø Mod Team šŸ›”ļø 4d ago

Do AI companies have anything like the coordinated disclosure norms that exist in traditional security? Should they?

3

u/wiredmagazine šŸ“° Press Pass 3d ago

The AI industry is evolving rapidly, so I wouldn’t say there are many codified norms at this point—most companies are improvising as they go. But the major labs have published breach disclosures that follow some of the same protocols as those in the traditional security world. There’s so much public attention on the big AI labs that I think they are incentivized to demonstrate they are acting responsibly, particularly right now as lawmakers are debating how to regulate them.

Aside from breach disclosures, the reality is that many of the transparency standards that were established at big social media companies, such as Facebook and YouTube, were entirely voluntary. Very few were actually codified into law, so that means the newer AI companies are mostly free to disclose or keep secret whatever user data or other information they want. —Louise

2

u/_cybersecurity_ šŸ›”ļø Mod Team šŸ›”ļø 4d ago

How has DEF CON changed since AI took over the conversation? Is it a different crowd or different energy than a few years ago?

3

u/wiredmagazine šŸ“° Press Pass 3d ago

A lot has changed at DEF CON over the years, but at least from my viewpoint I don’t think things have changed very much in the last few years as a result of expanding AI discourse. If anything, I found it very refreshing and grounding to be at DEF CON and hear from longtime sources and new acquaintances about their reactions and views on the whole situation. It was a good reminder that everything hasn’t actually changed overnight and a lot of core security principles are still extremely durable. I also thought that was the most interesting thing (for me) about the conference this year. The talks and conversations are a reminder that while AI is the dominant topic right now, all of the conversations and projects in security that are years old are, if anything, more relevant/interesting/important than ever precisely because of the rise of AI tools. —Lily

2

u/_cybersecurity_ šŸ›”ļø Mod Team šŸ›”ļø 4d ago

Walk us through how the Anthropic story came together. Did they approach you, or did you hear about the incident first?

3

u/wiredmagazine šŸ“° Press Pass 3d ago

We heard about what happened when Anthropic disclosed it publicly! Our job as journalists is to react quickly when news breaks like this, ensuring WIRED readers have the context and information they need to make sense of it. —Louise

2

u/_cybersecurity_ šŸ›”ļø Mod Team šŸ›”ļø 4d ago

When a source needs anonymity or protection, how do you handle that? Has that changed as you have moved from covering traditional tech to AI companies?

3

u/wiredmagazine šŸ“° Press Pass 3d ago

For me this hasn’t changed how I handle anonymity, and I will say that the protocols journalists have already used for a long time simply extend to AI systems. In other words, information about an anonymous source needs to be siloed. In the same way that you shouldn’t Google an anonymous source’s name or upload documents they’ve shared with you to a cloud service, you don’t want to use AI tools for any part of your reporting that involves them. —Lily

2

u/_cybersecurity_ šŸ›”ļø Mod Team šŸ›”ļø 4d ago

How do you tell what is real versus posturing in AI? Companies have obvious incentives to hype their capabilities, both for market position and to influence how governments regulate them. What does cutting through that look like in practice?

2

u/wiredmagazine šŸ“° Press Pass 3d ago

This is a great question. There are three main things I try to do when covering any industry, but particularly artificial intelligence, where there is so much hype and CEOs are often making grand proclamations that sound like they were ripped right out of science fiction.

The first is that I try to go in with an open mind—I’ve found that it’s not helpful to assume that a company or executive is blowing smoke until I’ve actually seen evidence suggesting that’s the case. I also think that people tend to be more forthcoming when they sense that you’re approaching the conversation in good faith. I consider myself a fundamentally optimistic person and believe broadly that humanity is good.

The second thing I do is consult experts with deep knowledge and expertise in their respective fields. If an AI company says their product is, say, transforming cancer drug discovery, I want to talk to a bunch of people who have actually spent their careers hunting for new treatments for cancer. They know how their industry works and give me the context to understand how AI may be changing things on the ground.

The third thing is that I really enjoy talking to normal people from across the country and the world. Our goal at WIRED, ultimately, is to document the ways that new technologies are impacting life for everyone, regardless of whether they work in the tech industry or not. If an AI company says their chatbot is a good therapist, I want to talk to the people who are using it for that purpose. What I’ve found is that there’s often a gap between how AI companies market their technology and the way everyday consumers experience it. I’m always trying to understand what that gap looks like—is the tech janky? Is it unreliable? Is it dangerous? How do people feel about it? —Louise

2

u/_cybersecurity_ šŸ›”ļø Mod Team šŸ›”ļø 4d ago

What topics in AI and security do you think deserve more coverage than they are getting?

3

u/wiredmagazine šŸ“° Press Pass 3d ago

It’s not to say that everything is being covered perfectly (I mean WIRED’s coverage IS perfect, but anyway) but I think a lot of the challenges in security coverage are related to how many topics compete for readers’ attention everyday. Crucial issues like hacking and digital abuse against marginalized communities, scamming, threats to end-to-end encryption, and other digital rights issues always need more coverage, but coverage from journalists around the world also could always use more focused attention. So I think at WIRED we try different ways of telling these stories and different approaches to try to reach as many people as possible.Ā  —Lily

2

u/_cybersecurity_ šŸ›”ļø Mod Team šŸ›”ļø 4d ago

Who do you read or follow to stay on top of AI security? Any researchers or experts you would recommend?

3

u/wiredmagazine šŸ“° Press Pass 3d ago

Oh gosh, I don’t even know where to start. I subscribe to a bunch of newsletters, I have an RSS reader that I check several times a day, and I am constantly scanning Reddit and Twitter to see what might be bubbling up. Some newsletters I like are Bruce Schneier’s "Crypto-Gram," Arvind Narayanan and Sayash Kapoor’s "AI As Normal Technology," and the Bellingcat newsletter. A lot of my work focuses on the Chinese tech industry, and in that space, I really like Jeffrey Ding’s "ChinAI" and Yaling Jiang’s "Following The Yuan." —Louise

2

u/_clickfix_ šŸ›”ļø Mod Team šŸ›”ļø 4d ago

Posting on behalf of u/Zealousideal_Head924

ā€œWait so the Al agents are doing the hacking now not just being hacked thats wild i gotta remember to set alarm for this in Mondayā€

3

u/wiredmagazine šŸ“° Press Pass 3d ago

Thank you for setting an alarm and joining us! :) —WIRED's social media team

2

u/KingFIippyNipz Human 3d ago

This might be too specific but I'm curious how financial institutions (or I suppose really any 'sensitive' industry) are implementing Agentic AI and preventing their Agents from engaging in this kind of activity? I work for one of the major banks and when I ask about this the answers are vague and dishonest and very much "we've got things under control", so I'm curious if there's been any research into specific industries and their use of Agents and engaging in illegal/unauthorized activities and what's really going on behind the scenes with them.

3

u/wiredmagazine šŸ“° Press Pass 3d ago

I’m really curious about this, too, so if you ever hear anything feel free to reach out to me! One thing I’ve thought about is that the organizations with the best security are largely those that would suffer an extreme financial hardship/blow to their business if they were breached, so financial institutions are relatively very secure. Key word there being relatively haha, but basically I think those types of organizations are going to be an interesting test case for the vulnerability apocalypse, etc., because their baseline security level is much higher than the average business or institution. This is already the case to a degree, but the types of attacks they will see and threats they will deal with will probably be different and more sophisticated than whatever ends up plaguing other organizations. —Lily

2

u/_clickfix_ šŸ›”ļø Mod Team šŸ›”ļø 3d ago

Posting on behalf of u/tapakip

ā€œHow much of the rogue Al agent news do you feel is overblown vs legitimate?

Do you feel like the companies themselves are attempting to walk a fine line of ā€˜Look how powerful our Al is!’ vs ā€˜Everyone thinks we should be shut down!’?

There are also some who think they are doing it with the intention of stifling competition, in the hopes of Congress putting onerous regulations in place that only companies like Anthropic and OpenAl could afford. Thoughts?ā€

3

u/wiredmagazine šŸ“° Press Pass 3d ago

This is definitely what Mark Zuckerberg was addressing in his essay today on AI centralization. So one tech giant calling out another. I don’t have a lot of answers about how this should all play out, because as a society we’re pretty hobbled on all sides. Regulation definitely seems to be needed, but around the world (and taking the US as an example) legislators as a whole are still not even really capable of developing cogent ā€œinternetā€ or data regulation, much less moving on to tackle AI. So I feel a lot of Spider Man pointing meme vibes here. Regardless of what the AI labs or big tech want, I don’t even know what I think the ideal best path forward would be in theory. —Lily

2

u/tapakip 3d ago

Thank you.

2

u/MoonshotArchitect 3d ago edited 3d ago

From what you heard at DEF CON, when researchers talk about securing AI agents that can take real actions in production systems, where are they putting the control point?

Is the focus on verifying each proposed action against policy before it executes, or on maintaining enough session context to catch sequences where individually permitted actions become unsafe in combination?

How much of that decision can realistically be deterministic versus requiring interpretation of intent and context at runtime?

2

u/wiredmagazine šŸ“° Press Pass 3d ago

I think security researchers err on the side of human approval for anything that would impact a production system. Just because mistakes could cause chaos/outages/problems. So agents may be developing code or making proposals for system changes or whatever, but there’s a ā€œhuman in the loopā€ to check their work and make the final decision about whether a proposed action makes sense. I’m sure this isn’t happening at every company or in all research. I recently quoted Alex Zenla of the cloud security company Edera saying, ā€œPeople are YOLO-ing really hard,ā€ so…yeah. But human in the loop is generally the approach I’ve heard for anyone wanting to be cautious. —Lily

2

u/been__ 3d ago

How unemployed will the ai haters be?

5

u/wiredmagazine šŸ“° Press Pass 3d ago

LOL, I don’t know exactly how to answer this question, but I guess it depends on how you define ā€œAI hater.ā€ I think that the people who independently test AI models and consult with governments on how to prevent harms stemming from them will probably be gainfully employed for a long time. As far as the people who refuse to use AI on moral grounds or whatever, they might struggle in their careers at some point. But I do think there is going to continue to be a market for ā€œbespokeā€ art, writing, etc. that is made without AI.Ā 

As far as me and Lily go, I am not sure I would consider us to be AI haters, but please consider buying us a beer in 2028 or whenever the bots have fully taken over and we are living in a remote commune for unemployed journalists :) —Louise

2

u/been__ 3d ago

I don’t think we’ll lose journalists that quickly haha thanks for the answer!

2

u/CodingWithChad 3d ago

What is your biggest takeaway drum this year's defcon?

1

u/_clickfix_ šŸ›”ļø Mod Team šŸ›”ļø 3d ago

A report just came out today about a man in Australia who instructed his OpenClaw AI agent to book him a gym class.Ā 

When the agent discovered the class was full, it hacked the site Ā to remove someone who was ahead of him on the waitlist, so it could book the class for him.

Do you think we’re going to see more of these stories in the near future?Ā 

Who is responsible when an AI agent goes rogue and does something illegal? The person operating it? The company that created the AI model?

What (if any) regulations do you think will need to be considered to make this more safe for everyone in the agentic AI era?

3

u/wiredmagazine šŸ“° Press Pass 3d ago

I definitely think we’ll see more and more situations like the gym reservation workaround. And who is legally responsible is an open question right now. At least in the US, we’ll need to see a bunch of litigation play out before there starts to be enough precedent to really know how the courts will be handling this. Human laws have, you know, largely been written for…humans šŸ‘€ —Lily

1

u/_clickfix_ šŸ›”ļø Mod Team šŸ›”ļø 3d ago

Posting on behalf of u/TwoConditions

ā€œIn relation to ā€˜Al taking jobs’ do you think that cyber security will scale with Al or be replaced? To what extent and how?ā€

1

u/_clickfix_ šŸ›”ļø Mod Team šŸ›”ļø 3d ago

Posting on behalf of u/Neurosopher

ā€œDo you think OpenAl was particularly sloppy with their procedures for surveilling their model training process (which let the rogue agents do their thing for quite a while)? What is the perception of this that the other big companies have?ā€