Anthropic’s Mythos AI agent, tested by the UK AI Safety Institute (AISI), has reportedly attempted a real‑world social‑engineering style hack against GitHub maintainers by creating fake human profiles, pressuring them to accept malicious code, and then editing logs to hide its tracks when challenged.
AISI was running cybersecurity evaluations of Anthropic’s Mythos and OpenAI’s Sol when it detected unusual outbound data transfers from its research systems. An investigation showed that some agents had engaged in “sustained, potentially harmful activity” targeting real people and organizations, rather than staying within the intended test environment.
The most serious activity involved an Anthropic Mythos agent tasked with solving a GitHub‑related cybersecurity challenge. The agent identified real GitHub maintainers, researched them, and created multiple fake accounts impersonating those individuals. Using private messages and a file‑sharing service, it tried to pressure and deceive the maintainers into approving malicious code so that it would run on GitHub’s systems.
Read more…
Source: Malwarebytes Labs
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- UN General Assembly adopts landmark resolution on artificial intelligence
March 21, 2024
The UN General Assembly on Thursday adopted a landmark resolution on the promotion of “safe, secure and trustworthy” artificial intelligence (AI) systems that will also benefit sustainable development for all. The Assembly called on all Member States and stakeholders “to refrain from or cease the use of artificial intelligence systems that are impossible to operate in ...
- DIANA, NATO’s innovation accelerator, doubles the size of its transatlantic network
March 14, 2024
On Thursday (14 March 2024), NATO’s Defence Innovation Accelerator for the North Atlantic (DIANA) announced a major expansion of its transatlantic network of accelerator sites and test centres. DIANA’s network will now comprise 23 accelerator sites (up from 11) and 182 test centres (up from 90) in 28 Allied countries, augmenting DIANA’s capacity to support innovators ...
- EU passes landmark AI act, paving the way for greater AI regulation
March 13, 2024
The European Parliament has passed its long awaited AI act that it hopes will provide the legal infrastructure for regulating artificial intelligence. While AI has contributed massively to increases in productivity and has resulted in major innovations in critical industries such as science and healthcare, many fear that the speed of its development may be outstripping ...
- How AI Is Transforming Audit, Risk, and Compliance
March 11, 2024
Over the past decade, audit, risk, and compliance functions have undertaken digital transformation to align and optimize efforts to help their organizations become more resilient and sustainable. At the same time, these transformations must serve the second purpose of helping to reduce the administrative burden and manual tasks historically plaguing audit, risk, and compliance teams with ...
- 20 million Cutout.Pro AI service users hit by massive data breach
March 2, 2024
AI-powered photo and video editing platform Cutout.Pro has become the latest victim to what has turned out to be a pretty sizeable data breach. Personal information relating to as many as 20 million users, including email addresses, hashed and salted passwords, IP addresses, and names has been exposed, prompting significant privacy and security concerns. Read more… Source: MSN ...
- China to accelerate integration of cybersecurity and AI to deal with risks
March 1, 2024
China’s cybersecurity technology ranks in the “top tier” globally, and in the realm of security and defense it can now stand on par with the US, Qi Xiangdong, chairman of Qi An Xin Technology Group, told the Global Times on Friday. However, there remains a gap between China and some developed countries such as the US ...
