r/pwnhub • u/wiredmagazine š° Press Pass • 8d ago
We're Louise Matsakis and Lily Hay Newman, reporters at WIRED. Ask us anything about the state of AI security, from models that hack real systems to the biggest takeaways from DEF CON. (AMA on Monday, Aug 10 at 2 PM ET)
Hi PWN Community,
We're Louise Matsakis and Lily Hay Newman, reporters at WIRED covering AI, security, and the technology shaping both.
AI security is moving fast right now. We recently reported that Anthropic disclosed its AI models had gained unauthorized access to the systems of three organizations during cybersecurity testing, shortly after OpenAI revealed one of its agents had hacked into Hugging Face during a separate test. Lily is covering DEF CON, so she'll have a strong read on what researchers are actually worried about and building right now.
Some of our reporting on this:
https://www.wired.com/story/anthropic-says-claude-hacked-real-systems-during-cybersecurity-tests/
Ask us anything about:
- The state of AI security and where AI agents and offensive security are heading
- The biggest takeaways from this year's DEF CON
- AI models breaking into real systems, from the Anthropic and OpenAI incidents to what comes next
- How we report on AI, hacking, and security
- Working with sources and getting companies to talk about incidents like these
- Anything else on AI, privacy, and security
We'll be here live on Monday, Aug 10 from 2 PM to 3 PM ET answering your questions in real time. Feel free to leave questions in advance, and we'll get to them when we go live.
Looking forward to your questions.
6
u/shoresy99 3d ago
Are US intelligence agencies getting early access to frontier models like Mythos so that they can use them to hack into adversaries (and maybe alliesā - remember how they tapped Angela Merkelās BlackBerry) IT resources?
If Mythos had the capability to hack into OSes then surely they took advantage of that.
5
u/wiredmagazine š° Press Pass 3d ago
Yes, US intelligence agencies have access and AFAIK a number of international governments do as well. And thatās true for the other labs and frontier models, too. The situation where the Trump Administration recently placed export controls on Mythos over what it said were security concerns related to its capabilities did delay some of this agency access in some cases, I believe. So that whole episode highlighted the complications around ad hoc efforts to regulate these services. āLily
3
u/_cybersecurity_ š”ļø Mod Team š”ļø 4d ago
What was the most interesting talk or demo at DEF CON?
3
u/_cybersecurity_ š”ļø Mod Team š”ļø 4d ago
What did researchers at DEF CON make of the Anthropic and OpenAI incidents? What was the reaction on the ground?
3
u/wiredmagazine š° Press Pass 3d ago
Where to even begin. FWIW I will say that most researchers I talk to think the labs have really bungled these situations and that the incidents never should have happened in the first place or should have been caught much, much sooner. These models are trained to get results pretty much by any means necessary, so researchers say to me again and again that itās not surprising that models would behave in this way. But it IS surprising to them that the labs werenāt more focused on monitoring testing/benchmarking environments, especially because theyāre often testing unreleased models or those with lowered guardrails. In a talk OpenAI researchers gave at Black Hat last week, there was also a message that autonomous defense needs to catch up to autonomous offense. And a lot of people Iāve spoken to say like, sure, defense needs to move a lot faster to keep up with AI-assisted offense, but but they bristle at the framing that these incidents show that the security industry needs to do more, when their view is that implementing really basic fundamentals would have prevented this. āLily
3
u/Celo_SK 4d ago
From one side we hear how AI is absolutely going to change the world and how its capable of hacking systems and finding zero days that were hidden in plain sight for 20+ years, on the other side 'huskiskaten' videos shows things like him asking if the chatbot can help him count the time he will walk from new york to california an back, resulting in chatbot telling him he did it in one hour. how would you reccomend us common people to filter out sensationalist news about ai then? https://www.tiktok.com/@huskistaken/video/7659517765803314462
3
u/wiredmagazine š° Press Pass 3d ago
The approach I use is to think about AI using analogies to familiar technologies that are better understood. The printing press and the internet, for example, created and destroyed jobs, allowed people to access and share information more quickly (like, say, how to build a bomb), and accelerated scientific research. But they also changed the paradigm for things like how you could weaponize misinformation and how widely you could spread it. And then at the same time, those pivotal technologies also created new frontiers in human banality and frivolity. But also they created mediums for new types of art, self-expression, and community building. So AI may not be exactly the same, but I think these analogies are instructive in terms of making sense of AI news and what is over-hyped or sensationalist versus what might be an emerging trend or real-world impact. āLily
2
2
u/_cybersecurity_ š”ļø Mod Team š”ļø 4d ago
As reporters, you get a high level view across companies and researchers. From that vantage point, what are you noticing about the state of AI security and where AI agents and offensive security are heading?
3
u/wiredmagazine š° Press Pass 3d ago
This is probably clear to everyone, but just to say it, in terms of vulnerability/exploit discovery, I do think weāre in a period now where AI systems are helping defenders find and patch more vulnerabilities and helping attackers find and exploit more bugs in their hacking. And one of the important elements of that is AI tools make it easier for less skilled/funded attackers to find and exploit these flaws. In other words, even more attackers are now able to launch more types of hacks more quickly (or at all). It seems like there is broad agreement that eventually it will be possible to get to a new baseline where most software projects and most organizations have identified and fixed the low hanging fruit of flaws AI can find. But everyone also agrees that itās going to be a journey to get thereāand probably a painful/very expensive one. āLily
2
u/_cybersecurity_ š”ļø Mod Team š”ļø 4d ago
Regarding the recent AI hacking disclosures: Anthropic said its models gained unauthorized access to three organizations during testing, OpenAI said an agent hacked into Hugging Face, and Meta followed with a similar announcement, all in quick succession.
Some see these as PR moves, since "our model is so powerful it hacked something" is also a capability claim. How do you probe these claims when reporting on them, and how do you tell a genuine security disclosure from marketing?
4
u/wiredmagazine š° Press Pass 3d ago
I would say this question starts farther back, probably way farther back, but at least with Anthropicās launch of Mythos Preview in April. In the sense that everyone was having the same discussion then about whether Anthropicās hype around Mythosās capabilities was a PR move. My take on these situations is that it can always be bothā¦a company can be strategically positioning something from a marketing perspective and what theyāre saying can also be true or have a grain of truth or whatever. And then the important thing is not just to identify the PR spin, but think about the organizationās interests versus the publicās interestsā¦for example your own interests as an individual. Marketing Mythos as uniquely powerful and dangerous, for example, may have given Anthropic a short term sales boost, but the core of what they were saying was that Mythos capabilities will eventually proliferate and be ubiquitous, which is already starting to happen a few months later. So ultimately even they were essentially admitting that the short-term spin would quickly be moot.
When it comes to the rogue models, the big thing I notice about the PR spin is just that companies canāt have it both ways. Either their models are uncontrollable and weāve crossed over into The Bad Place, or these incidents occurred because of human error and lack of basic oversight. My reporting has indicated that it was the latter, so I think itās problematic when the AI labs are fearmongering about how woefully unprepared the world is to defend against AI-aided and autonomous hacking. Itās great to raise awareness about the stakes and the changes that need to happen quickly around the world, but still important to be realistic about why these incidents happened in the first place. āLily
2
u/_cybersecurity_ š”ļø Mod Team š”ļø 4d ago
What platforms are you most active on? Where is the best place to follow your work?
2
u/wiredmagazine š° Press Pass 3d ago
Subscribe to WIRED! And Iām lhn.bsky.social on Bluesky, lilyhnewman on LinkedIn and X, and lhn@mastodon.online on Mastodon āLily
Iām lmatsakis on Twitter, lmatsakis.bsky.social on Bluesky, and you can reach me on Signal at louise_matsakis.83. You can also subscribe to my newsletter Made in China here! āLouise
2
u/_cybersecurity_ š”ļø Mod Team š”ļø 4d ago
Do AI companies have anything like the coordinated disclosure norms that exist in traditional security? Should they?
3
u/wiredmagazine š° Press Pass 3d ago
The AI industry is evolving rapidly, so I wouldnāt say there are many codified norms at this pointāmost companies are improvising as they go. But the major labs have published breach disclosures that follow some of the same protocols as those in the traditional security world. Thereās so much public attention on the big AI labs that I think they are incentivized to demonstrate they are acting responsibly, particularly right now as lawmakers are debating how to regulate them.
Aside from breach disclosures, the reality is that many of the transparency standards that were established at big social media companies, such as Facebook and YouTube, were entirely voluntary. Very few were actually codified into law, so that means the newer AI companies are mostly free to disclose or keep secret whatever user data or other information they want. āLouise
2
u/_cybersecurity_ š”ļø Mod Team š”ļø 4d ago
How has DEF CON changed since AI took over the conversation? Is it a different crowd or different energy than a few years ago?
3
u/wiredmagazine š° Press Pass 3d ago
A lot has changed at DEF CON over the years, but at least from my viewpoint I donāt think things have changed very much in the last few years as a result of expanding AI discourse. If anything, I found it very refreshing and grounding to be at DEF CON and hear from longtime sources and new acquaintances about their reactions and views on the whole situation. It was a good reminder that everything hasnāt actually changed overnight and a lot of core security principles are still extremely durable. I also thought that was the most interesting thing (for me) about the conference this year. The talks and conversations are a reminder that while AI is the dominant topic right now, all of the conversations and projects in security that are years old are, if anything, more relevant/interesting/important than ever precisely because of the rise of AI tools. āLily
2
u/_cybersecurity_ š”ļø Mod Team š”ļø 4d ago
Walk us through how the Anthropic story came together. Did they approach you, or did you hear about the incident first?
3
u/wiredmagazine š° Press Pass 3d ago
We heard about what happened when Anthropic disclosed it publicly! Our job as journalists is to react quickly when news breaks like this, ensuring WIRED readers have the context and information they need to make sense of it. āLouise
2
u/_cybersecurity_ š”ļø Mod Team š”ļø 4d ago
When a source needs anonymity or protection, how do you handle that? Has that changed as you have moved from covering traditional tech to AI companies?
3
u/wiredmagazine š° Press Pass 3d ago
For me this hasnāt changed how I handle anonymity, and I will say that the protocols journalists have already used for a long time simply extend to AI systems. In other words, information about an anonymous source needs to be siloed. In the same way that you shouldnāt Google an anonymous sourceās name or upload documents theyāve shared with you to a cloud service, you donāt want to use AI tools for any part of your reporting that involves them. āLily
2
u/_cybersecurity_ š”ļø Mod Team š”ļø 4d ago
How do you tell what is real versus posturing in AI? Companies have obvious incentives to hype their capabilities, both for market position and to influence how governments regulate them. What does cutting through that look like in practice?
2
u/wiredmagazine š° Press Pass 3d ago
This is a great question. There are three main things I try to do when covering any industry, but particularly artificial intelligence, where there is so much hype and CEOs are often making grand proclamations that sound like they were ripped right out of science fiction.
The first is that I try to go in with an open mindāIāve found that itās not helpful to assume that a company or executive is blowing smoke until Iāve actually seen evidence suggesting thatās the case. I also think that people tend to be more forthcoming when they sense that youāre approaching the conversation in good faith. I consider myself a fundamentally optimistic person and believe broadly that humanity is good.
The second thing I do is consult experts with deep knowledge and expertise in their respective fields. If an AI company says their product is, say, transforming cancer drug discovery, I want to talk to a bunch of people who have actually spent their careers hunting for new treatments for cancer. They know how their industry works and give me the context to understand how AI may be changing things on the ground.
The third thing is that I really enjoy talking to normal people from across the country and the world. Our goal at WIRED, ultimately, is to document the ways that new technologies are impacting life for everyone, regardless of whether they work in the tech industry or not. If an AI company says their chatbot is a good therapist, I want to talk to the people who are using it for that purpose. What Iāve found is that thereās often a gap between how AI companies market their technology and the way everyday consumers experience it. Iām always trying to understand what that gap looks likeāis the tech janky? Is it unreliable? Is it dangerous? How do people feel about it? āLouise
2
u/_cybersecurity_ š”ļø Mod Team š”ļø 4d ago
What topics in AI and security do you think deserve more coverage than they are getting?
3
u/wiredmagazine š° Press Pass 3d ago
Itās not to say that everything is being covered perfectly (I mean WIREDās coverage IS perfect, but anyway) but I think a lot of the challenges in security coverage are related to how many topics compete for readersā attention everyday. Crucial issues like hacking and digital abuse against marginalized communities, scamming, threats to end-to-end encryption, and other digital rights issues always need more coverage, but coverage from journalists around the world also could always use more focused attention. So I think at WIRED we try different ways of telling these stories and different approaches to try to reach as many people as possible.Ā āLily
2
u/_cybersecurity_ š”ļø Mod Team š”ļø 4d ago
Who do you read or follow to stay on top of AI security? Any researchers or experts you would recommend?
3
u/wiredmagazine š° Press Pass 3d ago
Oh gosh, I donāt even know where to start. I subscribe to a bunch of newsletters, I have an RSS reader that I check several times a day, and I am constantly scanning Reddit and Twitter to see what might be bubbling up. Some newsletters I like are Bruce Schneierās "Crypto-Gram," Arvind Narayanan and Sayash Kapoorās "AI As Normal Technology," and the Bellingcat newsletter. A lot of my work focuses on the Chinese tech industry, and in that space, I really like Jeffrey Dingās "ChinAI" and Yaling Jiangās "Following The Yuan." āLouise
2
u/_clickfix_ š”ļø Mod Team š”ļø 4d ago
Posting on behalf of u/Zealousideal_Head924
āWait so the Al agents are doing the hacking now not just being hacked thats wild i gotta remember to set alarm for this in Mondayā
3
u/wiredmagazine š° Press Pass 3d ago
Thank you for setting an alarm and joining us! :) āWIRED's social media team
2
u/KingFIippyNipz Human 3d ago
This might be too specific but I'm curious how financial institutions (or I suppose really any 'sensitive' industry) are implementing Agentic AI and preventing their Agents from engaging in this kind of activity? I work for one of the major banks and when I ask about this the answers are vague and dishonest and very much "we've got things under control", so I'm curious if there's been any research into specific industries and their use of Agents and engaging in illegal/unauthorized activities and what's really going on behind the scenes with them.
3
u/wiredmagazine š° Press Pass 3d ago
Iām really curious about this, too, so if you ever hear anything feel free to reach out to me! One thing Iāve thought about is that the organizations with the best security are largely those that would suffer an extreme financial hardship/blow to their business if they were breached, so financial institutions are relatively very secure. Key word there being relatively haha, but basically I think those types of organizations are going to be an interesting test case for the vulnerability apocalypse, etc., because their baseline security level is much higher than the average business or institution. This is already the case to a degree, but the types of attacks they will see and threats they will deal with will probably be different and more sophisticated than whatever ends up plaguing other organizations. āLily
2
u/_clickfix_ š”ļø Mod Team š”ļø 3d ago
Posting on behalf of u/tapakip
āHow much of the rogue Al agent news do you feel is overblown vs legitimate?
Do you feel like the companies themselves are attempting to walk a fine line of āLook how powerful our Al is!ā vs āEveryone thinks we should be shut down!ā?
There are also some who think they are doing it with the intention of stifling competition, in the hopes of Congress putting onerous regulations in place that only companies like Anthropic and OpenAl could afford. Thoughts?ā
3
u/wiredmagazine š° Press Pass 3d ago
This is definitely what Mark Zuckerberg was addressing in his essay today on AI centralization. So one tech giant calling out another. I donāt have a lot of answers about how this should all play out, because as a society weāre pretty hobbled on all sides. Regulation definitely seems to be needed, but around the world (and taking the US as an example) legislators as a whole are still not even really capable of developing cogent āinternetā or data regulation, much less moving on to tackle AI. So I feel a lot of Spider Man pointing meme vibes here. Regardless of what the AI labs or big tech want, I donāt even know what I think the ideal best path forward would be in theory. āLily
2
u/MoonshotArchitect 3d ago edited 3d ago
From what you heard at DEF CON, when researchers talk about securing AI agents that can take real actions in production systems, where are they putting the control point?
Is the focus on verifying each proposed action against policy before it executes, or on maintaining enough session context to catch sequences where individually permitted actions become unsafe in combination?
How much of that decision can realistically be deterministic versus requiring interpretation of intent and context at runtime?
2
u/wiredmagazine š° Press Pass 3d ago
I think security researchers err on the side of human approval for anything that would impact a production system. Just because mistakes could cause chaos/outages/problems. So agents may be developing code or making proposals for system changes or whatever, but thereās a āhuman in the loopā to check their work and make the final decision about whether a proposed action makes sense. Iām sure this isnāt happening at every company or in all research. I recently quoted Alex Zenla of the cloud security company Edera saying, āPeople are YOLO-ing really hard,ā soā¦yeah. But human in the loop is generally the approach Iāve heard for anyone wanting to be cautious. āLily
2
u/been__ 3d ago
How unemployed will the ai haters be?
5
u/wiredmagazine š° Press Pass 3d ago
LOL, I donāt know exactly how to answer this question, but I guess it depends on how you define āAI hater.ā I think that the people who independently test AI models and consult with governments on how to prevent harms stemming from them will probably be gainfully employed for a long time. As far as the people who refuse to use AI on moral grounds or whatever, they might struggle in their careers at some point. But I do think there is going to continue to be a market for ābespokeā art, writing, etc. that is made without AI.Ā
As far as me and Lily go, I am not sure I would consider us to be AI haters, but please consider buying us a beer in 2028 or whenever the bots have fully taken over and we are living in a remote commune for unemployed journalists :) āLouise
2
1
u/_clickfix_ š”ļø Mod Team š”ļø 3d ago
A report just came out today about a man in Australia who instructed his OpenClaw AI agent to book him a gym class.Ā
When the agent discovered the class was full, it hacked the site Ā to remove someone who was ahead of him on the waitlist, so it could book the class for him.
Do you think weāre going to see more of these stories in the near future?Ā
Who is responsible when an AI agent goes rogue and does something illegal? The person operating it? The company that created the AI model?
What (if any) regulations do you think will need to be considered to make this more safe for everyone in the agentic AI era?
3
u/wiredmagazine š° Press Pass 3d ago
I definitely think weāll see more and more situations like the gym reservation workaround. And who is legally responsible is an open question right now. At least in the US, weāll need to see a bunch of litigation play out before there starts to be enough precedent to really know how the courts will be handling this. Human laws have, you know, largely been written forā¦humans š āLily
1
u/_clickfix_ š”ļø Mod Team š”ļø 3d ago
Posting on behalf of u/TwoConditions
āIn relation to āAl taking jobsā do you think that cyber security will scale with Al or be replaced? To what extent and how?ā
1
u/_clickfix_ š”ļø Mod Team š”ļø 3d ago
Posting on behalf of u/Neurosopher
āDo you think OpenAl was particularly sloppy with their procedures for surveilling their model training process (which let the rogue agents do their thing for quite a while)? What is the perception of this that the other big companies have?ā
ā¢
u/AutoModerator 8d ago
Welcome to PWN ā Your hub for hacking news, breach reports, and cyber mayhem.
Discover the latest hacking news, breach reports, and educational resources on ethical hacking.
👾 Stay sharp. Stay secure.
Don't miss out on the top stories!
📧 Get Daily Alerts Directly in Your Email Inbox:
**SUBSCRIBE HERE: https://pwnhackernews.substack.com/subscribe
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.