this post was submitted on 20 Jun 2026
7 points (100.0% liked)

Technology

87598 readers
3637 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
all 23 comments
sorted by: hot top controversial new old
[–] wewbull@feddit.uk 3 points 2 months ago (1 children)

My takeaway from stories like this is that it was always really easy to crack in to companies, but most knowledgeable people had better things to do.

[–] SocialMediaRefugee@lemmy.world 1 points 2 months ago (1 children)

My feeling is companies leave themselves open by allowing everyone access to the network so the idiot who has been told 50 times not to click on a link in a suspicious email will still do it or hand out passwords to anyone on the phone. Even if you run a tight ship you'll give access to some contractor who doesn't.

[–] Vex_Detrause@lemmy.ca 1 points 2 months ago

A poor IT department is working overtime with limited funds for staff trying to fix stuff while bosses breathing down their necks.

[–] janus2@lemmy.zip 2 points 2 months ago (3 children)

script kiddies wrecking corporate security is funny
prompt kiddies doing it is just depressing

[–] LiveLM@lemmy.zip 1 points 2 months ago* (last edited 2 months ago) (1 children)

Didn't think I'd ever side with no script kiddie but at this point fuck it.
If your company can't be bothered to do the bare minimum in security then yeah I hope the least skilled hacker ever comes along and wrecks it.

[–] adespoton@lemmy.ca 0 points 2 months ago (1 children)

Thing is, with the latest frontier models, the least skilled person can find a crack in the most secure company around, as long as they can string a few sentences together.

It isn’t about “bare minimum” anymore. All it takes is a single lapse in vigilance from a single employee, and they’re in… and the LLM doesn’t have to pause to figure out what to do next.

[–] Damage@feddit.it 1 points 2 months ago (2 children)

Pentesters have access to LLMs too

[–] Mika@piefed.ca 1 points 2 months ago

some hacker unleashes malicious AIs to the internet, breaking it apart cause AI keeps finding vulnerabilities in everything and break things faster than humans can fix

corporates build corporate internet and the blackwall, which is AI to fight malicious AIs

Gooooood morning Night City!

[–] ByteJunk@lemmy.world 0 points 2 months ago* (last edited 2 months ago)

Yeah, but an LLM's arms race isn't "doing the bare minimum in security", which is what the poster before was saying.

This is a genuine concern, where whoever has access to the best/most recent/most expensive models can unleash chaos - I'm talking state-sponsored attacks, mega-corp espionage, bored billionaires,...

[–] A_norny_mousse@piefed.zip 1 points 2 months ago (1 children)

And no-skilled attackers can buy exploits.

Claude helping is insignificant to the story.

The real headline should be:

At least 14 companies' IT security is practically non-existent

[–] eldebryn@lemmy.world -1 points 2 months ago (1 children)

It is significant because a random teenager can't google "download exploits" and have them available 5mins later.

Powerful AI models and agents though are on your fingertips without you even asking.

Sure, people can buy guns. But what if every person could materialize a chainsaw instead regardless of their skill, maturity, age, or criminal record? 🤔

[–] 0x0@infosec.pub -1 points 2 months ago

Teenagers are definitely able to find exploits via google in 5 if they're motivated.

Buying a disassembled ak-47 on post order and having it shipped to your address anywhere in the world is also possible.

Rules only apply to people that care about them.

[–] Fmstrat@lemmy.world 1 points 2 months ago

The attacker’s inexperience was also evident in his operational security failures. At one point he asked Claude to help edit his resume, which contained his full name, location, education history, and LinkedIn profile.

Later, while investigating a potential compromise of one of his own hosts, he inadvertently confirmed his home IP address to the agent. Based on this and other corroborating evidence, the researchers believe the attacker to be a young man based in Addis Ababa, Ethiopia.

Wow.

[–] hayvan@piefed.world 1 points 2 months ago

Alternative title: the ubiquitous race for cheapest developers and fastest time to maket leaves everything insecure.

[–] Tollana1234567@lemmy.today 0 points 2 months ago (1 children)

they fired hordes of tech people, and neglected cybersecurity in many companies. this was bound to happen.

[–] Croquette@sh.itjust.works 1 points 2 months ago

The IT Paradox :

  • "Why am I paying IT if everything works"
  • "Why am I paying IT if nothing works"