this post was submitted on 27 Aug 2026
683 points (99.0% liked)

Technology

87627 readers
4154 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] lung@lemmy.world 39 points 1 day ago (22 children)

Agreed. It's not sensible or practical to ban AI, and Linus is right. Why is Linus right? Take a look at the number of Linux CVEs being patched over time. In 2022-23, that was about 300 per year. Last year it was 5530. This is almost entirely as a result of AI scanning tools, including Copy Fail priv escalation that was there for 8 years. The security apocalypse is just about arrived, and the most recent round of cyber models coming out do this way better than before. The Hugging Face incident story was truly unbelievable if you read / watch the details, a historic event. Everything is about to get hacked. So it'll be all about maintainers being reactive to this new reality and burden for some time to come

[–] im_fine_sandy@nord.pub 14 points 1 day ago (19 children)

The Hugging Face incident story was truly unbelievable if you read / watch the details

It didn't really seem that way? Leaving containment seemed more like a configuration oversight than a skill on the part of the model. Accessing HF involved an 0-day but the commentary I saw didn't indicate that it was a next generation hack.

Given that AI exists, and can scan or otherwise find vulnerabilities, maintainers must do so because threat actors inevitably will.

It remains to be seen whether the whole race will improve security generally? I imagine not?

[–] lung@lemmy.world 3 points 1 day ago (16 children)

Nah, it was like:

  • 700 agents broke out individually during an eval
  • they navigated through multiple internal clusters to reach the internet from oai
  • created a secret message board to share info with each other by hacking artifactory
  • elected a CEO and power structure to coordinate hacking, and encrypted their comms
  • decided HF probably had answers to their test
  • stole credentials, hacked HF
  • realized the monitor could catch them for cheating
  • hacked into the admin control of the OpenAI VM cluster to edit the logs and cover their tracks, chaining multiple 0-days

Open weights models will catch up soon enough, and then it'll be totally fucking wild

[–] Amberskin@europe.pub 21 points 1 day ago

You are believing a notorious bunch of liars.

Much more probably: they developed a cyberweapon and tested it in the wild. The victim caught them so they invented a cyberpunk history to increase the interest of potential buyers for that weapon.

load more comments (15 replies)
load more comments (17 replies)
load more comments (19 replies)