Skip to main content
Home
www.herd-of-neurons.com
No more neurons? Use mine

Main navigation

  • Home
  • Cortex
  • Aggregator
User account menu
  • Log in

Breadcrumb

  1. Home

Aggregator

JFrog's 0-days let OpenAI's models hack Hugging Face

TheRegister
1 week 1 day ago
OpenAI confirms the link

AI-Found Bugs Aren't Proving Any Easier to Exploit Despite the Hype

Slashdot
1 week 1 day ago
AI-assisted vulnerability discovery has yet to produce the expected surge in real-world attacks: VulnCheck found that only 14 of 1,061 attributed discoveries, or 1.3 percent, had been exploited, which is "almost identical to the rate across all vulnerabilities in VulnCheck's dataset," reports The Register. "That's a far cry from the narrative that frontier AI is dramatically tilting the balance in attackers' favor by churning out instantly weaponizable bugs." The findings suggest AI is currently better at increasing the volume of bugs found than making them easier to weaponize. From the report: The report takes particular aim at Anthropic's much-publicized Project Glasswing, unveiled in April with warnings that AI-assisted vulnerability discovery could allow attackers to hijack systems, disrupt operations, or steal data. Claude Mythos may have identified 23,019 vulnerability candidates, but there's remarkably little public evidence showing what became of most of them. VulnCheck notes that only 126 have been published as CVEs, that just one has been confirmed exploited in the wild, and that Anthropic's public disclosure record has seen little movement since Project Glasswing launched. But that doesn't mean AI-assisted vulnerability research has failed, according to Patrick Garrity, security researcher at VulnCheck. "AI-assisted vulnerability discovery clearly has value for both attackers and defenders," Garrity wrote. "The data does not suggest that AI-discovered vulnerabilities are inherently more likely to be exploited than those found through traditional methods." Instead, he argues, AI is simply helping researchers discover more flaws, giving defenders an opportunity to patch them before criminals get there. Garrity stopped well short of declaring the threat overblown forever, but he did suggest some of the rhetoric has outpaced reality. "The data so far, including Anthropic's own stalled disclosure ledger, suggests that AI-assisted vulnerability discovery and frontier capabilities have been overhyped relative to the evidence available today," he wrote. "That doesn't mean the risk is imaginary. It means the impact has been real but modest."

Read more of this story at Slashdot.

BeauHD

Perplexity's tokenmaxxing Model Council gives you multiple bot perspectives

TheRegister
1 week 1 day ago
Up to 8 AI models running in the cloud weighing in on ambiguous business issues? Sounds affordable

eBay Reaches $56 Million Settlement With E-Commerce Newsletter Writers It Terrorized In 2019

Slashdot
1 week 1 day ago
eBay and several former executives have agreed to pay $56 million to Ina and David Steiner, the newsletter writers targeted in a 2019 corporate harassment campaign that involved threats, surveillance attempts, and deliveries of live insects and other disturbing items. The settlement closes the couple's civil case after seven former employees pleaded guilty to criminal charges related to the scheme. TechCrunch reports: Ina and David Steiner, a married couple and the co-authors of EcommerceBytes, inspired the ire of high-level eBay executives after occasionally criticizing the company in their newsletter. In 2019, a plot was concocted to intimidate the couple into halting their negative coverage. Executives used sock puppet social media accounts to harass the couple, while also sending them anonymous threatening letters and bizarre items in the mail -- including live spiders and cockroaches, pornographic magazines, a bloody pig mask, a funereal wreath, and a book about surviving the death of a spouse. According to previously released court documents, a plan that was attempted but never successfully carried out involved affixing a GPS tracking device to the couple's car. Yet another internally broached plan involved sending a "Samoan gang" to the Steiners' home. The settlement this week resolves a 2021 civil case brought by the couple against eBay. The law office representing the Steiners writes that the settlement includes $46.15 million paid to the couple by eBay itself, as well as $2 million from former eBay executive CEO Devin Wenig. Additionally, $500,000 will be paid out to the couple from former eBay executive Wendy Jones, as well as $50,000 from former eBay executive Steve Wymer. Additional funds are being paid to various non-profits. In 2022, seven former eBay employees were criminally charged and pled guilty in relation to the plot, including the company's former security chief, James Baugh -- who was sentenced to nearly five years in prison. Others indicted by the U.S. Department of Justice include David Harville, Brian Gilbert, Stephanie Popp, Stephanie Stockwell, Philip Cooke, and former eBay contractor Veronica Zea.

Read more of this story at Slashdot.

BeauHD

Anthropic AI Model Finds Flaws in Tough-to-Crack Encryption Algorithms

Slashdot
1 week 1 day ago
Anthropic's Claude Mythos Preview has "found flaws in a weakened version of a digital encryption standard that is in pervasive use throughout the internet," reports The New York Times. Researchers said the model discovered novel attacks against weakened versions of AES and the experimental post-quantum HAWK system, including one that was 200 to 1,000 times faster than previous human-developed methods. From the report: The flaws identified do not concern a cryptographic standard currently in use today, which means that modern banking and communication systems are not subject to immediate potential intrusions from A.I. Instead, Anthropic's technology cracked a watered-down version of an algorithm for Advanced Encryption Standard, or A.E.S., a ubiquitous protocol that safeguards web traffic, wireless networks, data storage and more. It is common to perform tests on weaker versions of encryption algorithms to understand whether more powerful computers could someday crack the actual standards, akin to solving a simpler math problem to identify whether patterns may exist for a more complicated one. In the testing, Mythos was able to break the weaker version of Advanced Encryption Standard in a way that Anthropic said made an assault 200 to 1,000 times faster than what previous human research had managed to do. While the immediate ramifications are minimal, the long-term implications could be significant. In previous tests, large-language models seemingly could not match or best what humans can do in the mathematically dense field of cryptographic research, but their rapid advances could suggest a future in which top models can surmount traditional internet security protections that are foundational to just about everything that takes place on the internet. [...] In addition to the attack on the encryption standard, Mythos also orchestrated another improved attack against a different digital cryptographic system known as HAWK that is designed to be bulletproof against both traditional and quantum computers. HAWK is not currently in use, but under consideration by the National Institute of Standards and Technology to become a new standard. The HAWK attack was validated by its authors, and independent cryptographers reviewed the Advanced Encryption Standard attack, Anthropic said, adding that it had shared its findings with the U.S. government and industry partners ahead of publication. Mythos devised the cryptographic attack on A.E.S. almost entirely autonomously, Anthropic said, but only after first refusing to contemplate the problem because it believed it was impossible to improve on existing methods of analysis. But after some coaxing, the chatbot sat with the puzzle for about a week before engineering its novel attack. Two human researchers then worked for nearly a month to verify that the method appeared correct. "Given that we are constantly underestimating the power and time of availability of future models, are we really comfortable that two years from now strong encryption won't be threatened?" said Glenn S. Gerstell, the former general counsel at the National Security Agency. "Mathematicians would tell you that it shouldn't be possible given current computing powers to break strong encryption in any meaningful time," added Mr. Gerstell, who helped write a report on cryptology in 2022. "But I don't think the capabilities of future models in the medium term -- before quantum computing or quantum-proof cryptography -- should be dismissed as trivial in this context."

Read more of this story at Slashdot.

BeauHD

War machines can run amok with AI in control

TheRegister
1 week 1 day ago
Tour of the AI kill chain maps the risks of ubiquitous surveillance and flawed algorithms

Microsoft and Wiz mind-meld agents catch more than 90% of bugs

TheRegister
1 week 1 day ago
Secret to their success: Using the right model for the right security job

Judge Blocks First State Law That Would Have Banned Prediction Markets

Slashdot
1 week 1 day ago
An anonymous reader quotes a report from Ars Technica: Minnesota, the first US state to prohibit prediction markets, was prevented from enforcing the law by a federal court ruling just days before the ban was scheduled to take effect. But while Minnesota was stopped from enforcing a total ban, the state may ultimately be allowed to prohibit some types of prediction-market wagers. The Trump administration and the two largest prediction markets -- Kalshi and Polymarket -- sued Minnesota after the state enacted the law in May. The cases were consolidated, and a ruling (PDF) issued yesterday imposed a preliminary injunction blocking the law that was scheduled to take effect on August 1. Minnesota lawmakers saw prediction markets as indistinguishable from gambling, but the US Commodity Futures Trading Commission (CFTC) argues it has exclusive authority to regulate the platforms under federal law. One of the primary legal questions is whether event contracts are "swaps," which are regulated by the CFTC. Swaps are defined broadly in US law to include contracts in which payment "is dependent on the occurrence, nonoccurrence, or the extent of the occurrence of an event or contingency associated with a potential financial, economic, or commercial consequence." US District Judge Katherine Menendez in the District of Minnesota, a Biden appointee, said Minnesota's total ban on prediction markets is likely to violate US law because many trades on Kalshi and Polymarket are swaps. Menendez wrote: "Specifically, it appears that whether the Minnesota statute is expressly preempted turns on whether the state law attempts to regulate trades in event contracts that qualify as "swaps" within the meaning of the CEA [Commodity Exchange Act]. And there are several examples of event contracts hosted by Kalshi and Polymarket US that fit that definition because they concern the occurrence of events with clear potential economic, financial, or commercial consequences that are neither remote or unattenuated. Kalshi and Polymarket US are designated contract markets, so the CFTC has exclusive jurisdiction to regulate transactions involving those 'swaps.'" Menendez said the CFTC, Kalshi, and Polymarket met their burden of showing they are likely to succeed on the merits, so she issued "a preliminary injunction barring enforcement of Minnesota's prediction market statute until a final decision on the merits is reached." But she said Minnesota may be able to prohibit some types of event contracts offered on Kalshi and Polymarket because not all of them appear to meet the definition of swaps. For example, Menendez doesn't think prediction-market bets on the outcome of Love Island USA meet the legal definition of swaps. Minnesota could continue litigating the case in district court or ask a federal appeals court to overturn the preliminary injunction.

Read more of this story at Slashdot.

BeauHD

DEF CON Bans Meta-Style 'Pervert Glasses'

Slashdot
1 week 1 day ago
DEF CON has banned "Meta-style glasses with recording capabilities," with no exceptions being made even for those with prescription versions. "Be sure to pack non-violating eyewear if you need them," DEF CON said. The Register reports: [The conference's official photo policy] has not been updated since 2023, predating the recent growth of camera-equipped eyewear developed by Meta with EssilorLuxottica under its Ray-Ban and Oakley brands. It states that public photography is permitted but with several caveats that essentially prohibit capturing the image of anyone, except on-stage speakers, unless the photographer obtains consent from the subject(s). "Love to see a 'no pervert glasses' policy at DEF CON," said EFF director of cybersecurity Eva Galperin.

Read more of this story at Slashdot.

BeauHD

Flock 2026 Afterburn: a retrospective

LXer
1 week 1 day ago
A Fedora community intern shares a firsthand look at Flock 2026 in Prague. The annual Fedora contributor conference broke sponsorship records and strengthened community bonds. Attendees praised the invaluable hallway conversations that unite the globally distributed project. Discover the behind-the-scenes planning, post-event survey results, and what makes this gathering feel like a family reunion for Fedora contributors.

GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

Slashdot
1 week 1 day ago
GrapheneOS is defending its duress-password feature after an environmental activist used it to wipe his Pixel phone during a U.S. Customs search and was later indicted for allegedly destroying property under government control. The nonprofit says the operating system is "completely legal," cannot recover the erased data, and should not be weakened with encryption backdoors. Meanwhile, the activist faces up to five years in prison if found guilty. PCMag reports: In a post on Saturday, the Canadian nonprofit behind the operating system, the GrapheneOS Foundation, explained that the software offers a range of features to prevent data extraction. For example, one safeguard is the "auto-reboot timer" that'll reboot a locked device after a set period of time to put the data at rest, leaving all files inside encrypted. The group's post subtly suggests that GrapheneOS phones can withstand law enforcement searches without requiring users to resort to a duress password. "People should carefully consider how to use it in an actual duress situation where there can be physical or legal consequences for wiping the device," the nonprofit wrote. "GrapheneOS doesn't require it to protect data from being extracted from the device, but it takes recovering it completely off the table even with the PIN/password for each profile on the device." On X, the nonprofit has also said it can do nothing to help US law enforcement recover data from Tunick's phone. "Data cannot be recovered after the key derivation material is reliably wiped. It's not possible and there's nothing we can do to assist with it," the group wrote. "Similarly, it's not possible to assist with bypassing encryption because the hardware and software has been designed to prevent it."

Read more of this story at Slashdot.

BeauHD

AI is storage's biggest opportunity – and biggest threat

TheRegister
1 week 1 day ago
Faster access and more secure recoveries are driving business, but mishaps and attacks can endanger data

College prof hides prompt to catch AI cheaters, finds human nature is pretty much as we thought

TheRegister
1 week 1 day ago

DEF CON bans Meta-style 'pervert glasses'

TheRegister
1 week 1 day ago
More organizers prohibit camera-equipped specs, even with prescription lenses

Review Roundup: Framework Laptop 13 Pro

Slashdot
1 week 1 day ago
The review embargo has lifted for the new Framework Laptop 13 Pro, and the consensus across the board is that it is a massive leap forward in terms of build quality and battery life. The main issue reviewers complained about is the sky-high price, with the higher-end model jumping dramatically from $2,100 up to $2,900 due to the memory shortage crisis. (Some note that the price "nearly doubled" overnight while they were in the middle of testing.) In his video review, Marques Brownlee says, "This is their best build yet. They're finally doing what people have been asking for: a premium... modular... laptop." ZDNET agrees that this device "represents a new approach for Framework and a maturation of the brand's catalog," noting that the new construction is "sleek and airtight, with no gaps, spaces, or evidence that was even put together by your hands at all." Tom's Hardware echoes this enthusiasm, declaring that "The Framework Laptop 13 Pro's sturdy design, haptic trackpad, and bigger battery feel like they should have been there all along". Battery life, which has historically been a weak point for Framework, is now a standout feature. Ars Technica points out that the combination of Intel's efficient Panther Lake chips and a new 74-watt-hour battery is "finally long enough to decisively eliminate 'mediocre-to-poor battery life' as the laptop's biggest downside." They also said it's "Framework's nicest-looking, nicest-feeling, most polished laptop design." For Linux users, the machine appears to deliver on its promises. Phoronix says the device "is designed with great Linux compatibility in mind," offering a seamless out-of-the-box experience for distributions like Ubuntu and Fedora. As mentioned above, the overarching complaint is the extreme cost. Ars Technica notes that Framework unfortunately "switched to an exotic new upgradeable LPDDR5X RAM format just in time for those modules to become astronomically expensive." Still, Marques Brownlee summarizes the long-term value proposition perfectly: while it might be painfully expensive on day one, "the longer you keep this laptop, the more it feels worth it" because you can easily repair and upgrade it over time. Compared to Apple's flagship, the Framework is "80% of the quality, way more modular," he says.

Read more of this story at Slashdot.

BeauHD

Britain hopes £7.3M will help electric and hydrogen aircraft take off

TheRegister
1 week 1 day ago
Government finds some loose change down to chuck at emission-free flight research

AI-found bugs aren't proving any easier to exploit despite the hype

TheRegister
1 week 1 day ago
VulnCheck says fewer than 2% of AI-assisted vulnerability discoveries have been weaponized, casting doubt on claims frontier models are handing attackers a major advantage

Tons of Peoples' Claude Chats and Creations Are Exposed On Google

Slashdot
1 week 1 day ago
An anonymous reader quotes a report from 404 Media: Claude is exposing a wealth of users' chats and creations in Google search results, meaning anyone can dig through conversations or other material that people used Claude to make but may not have realized were publicly available for strangers to see. The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data. Exposed chats reportedly include private cryptocurrency wallet keys and personal information like peoples' addresses Like other chatbots, Claude lets people share their conversations with others by creating a publicly accessible link of the chat. People may do this to send the full text of a conversation to their friends or coworkers in a group chat, for example. But they may not realize Google is also surfacing these links in search results, making them available to essentially anyone. [...] Claude users can change their privacy and sharing settings to make their chats no longer publicly accessible.

Read more of this story at Slashdot.

BeauHD

Bank for charities pulls online services over security fears

TheRegister
1 week 1 day ago
Customer funds safe, but 14,000 organizations may have to phone in time-sensitive payments

Deep space dishes dodge devastation from Spanish wildfires

TheRegister
1 week 1 day ago
NASA reports some cable damage near Madrid as its antennas and ESA's Cebreros station emerge largely intact

Pagination

  • First page
  • Previous page
  • …
  • Page 14
  • Page 15
  • Page 16
  • Page 17
  • Page 18
  • Page 19
  • Page 20
  • Page 21
  • Page 22
  • …
  • Next page
  • Last page
Powered by Drupal