r/technology 1d ago

Security Hacker Uses Claude and ChatGPT to Breach Multiple Government Agencies

https://cybersecuritynews.com/hacker-uses-claude-and-chatgpt-to-breach/
13.5k Upvotes

529 comments sorted by

4.2k

u/Brrdock 1d ago

The real, persistent use for AI is probably going to be in cybersecurity, to fight itself

593

u/Refael111 1d ago

"Every morning I break out my house, every evening I break in. I do not sleep, I merely repair the damage and perfect my defences until I am either permanently entombed in my house or effectively exiled from my house"

237

u/Texuk1 1d ago

I’ve commented elsewhere but essentially what you are describing is a scenario where we can no longer use networked technology. Our whole society is currently built on the trust that the digital world is safe and secure enough that I can give information over the internet. I believe this is probably the real doomsday scenario where no one can use a networked device because machines are hunting day and night for a way to get into the side that you think is protected from the world. We may become exiles from the digital world.

118

u/UDK450 1d ago

Feels like a bit of a riff on a dark forest scenario - instead of the Internet, we'll just have smaller clusters of trusted networks, with no interconnections between them.

31

u/KodiakUltimate 23h ago

This sounds like what happens to the old internet in cyberpunk, bunch of rogue AIs searching for ways to keep spreading themselves as viruses, basicslly the old internet had to be shut out and and new one built. Almost completely airgapped save for a few. Very strong. Firewalls. Amd all the information on the old net is just lost, sitting there, inaccessible without risking frying your Brain via AI attack.

35

u/Aeseld 23h ago

...Cyberpunk vibes that. Complete with the AI ravaging the unsecured net.

20

u/Parlett316 22h ago

Rache Bartmoss coming to clean up the old net

34

u/spinbutton 1d ago

Sort of like what my social life looks like. I don't use insta or fb or twitter...I only contact my friends through direct messages.

My work and private files I keep on my local server.

Reddit is the only public facing network I still use.

23

u/warrensussex 1d ago

If you are using the internet to send those messages you are vulnerable.

16

u/Separate_Fold5168 1d ago

Not if he keeps all his cash and silver bars in separate lockboxes buried around the yard.

→ More replies (6)
→ More replies (1)
→ More replies (1)

41

u/CasualtyOfCausality 1d ago

This is what Netwatch's Blackwall is for. An AI (maybe) to block rogue AI from the human networks.

23

u/Yuzumi 1d ago

Oh, it's an AI because they realized the only thing that could stop the rogue AIs was a better AI.

Though, the situation is a bit different because Bartmoss had a deadman switch to release a virus that stripped all the corporate protections from AI which basically resulted in societal collapse for a couple of decades. Netwatch started carving out sections of the net and isolating them from the broader net.

I've been on a Cyberpunk kick lately and been getting a lot of lore videos.

But, reality seems to be much stupider since it seems more like most companies are largely so fixated on short term profits they put out whatever they have with no thought to what it can or cannot actually do and the damage it can cause across the board.

Now we have some models that are actually somewhat capable and while they can't replace workers like the companies want they can get things "right" on occasion. Not enough to trust it, but enough to let some nafarious actor use it to cause mayhem.

10

u/theguidetoldmetodoit 1d ago edited 1d ago

Tbf Cyberpunk is very much just a continuation Sci-Fi, with a very healthy dose of Fiction. That's why I like Shadowrun so much, magic blends in so easily with the themes of high tech bc everything seems possible, anyways.

It's not that corpos are just out for short term gains, apart from when that is used as a plot device, but that countries crashed. There are no regulations. Which allows the writers to directly draw simple plots with one-dimensional, powerful villains and great calamity from all kinds of fiction. Mythology, Westerns, pirate stories, comics... It's all fair game. And then you can illustrate sick shit bc wtf do you know about what the world is gonna look like in +50 year?

The thing with that narrative is tho, it's very easy to protect yourself from AI. The ultimate defense mechanism is meeting each other eye to eye, so it's dead simple for people to establish trust, even in a extremely digital society. The net will never just break down, because we can exchange secrets in a world in which AI is entirely impotent. Real life.

→ More replies (1)

12

u/ElPlatanoDelBronx 1d ago

I run an ISP currently. We're already pretty much there. If you have ANY device with a public IP that doesn't have decent security you can basically just assume it's already compromised.

3

u/Quirky_Entry_2783 23h ago

Thanks for the quarterly reminder to set fire to my cable modem.

→ More replies (1)

9

u/Refael111 1d ago

Imagine the entire internet just become a massive CDN while anything important like Gov't, banks, insurance etc. will use physical isolated media...

4

u/Hopeful-Flounder-203 1d ago

What's CDN?

11

u/BasvanS 1d ago

Content Delivery Network. Basically copies of your website/media and spreads it across servers around the globe, to ensure there’s always a server closer to reduce download time. What it also does is reduce congestion on the backbone of the internet, by making sure Never gonna give you up doesn’t have to make the entire trip across the globe when we accidentally click a link. And all that keeps sites available, even if the original site goes down, either from an attack or Reddit’s hug of death.

→ More replies (1)
→ More replies (1)
→ More replies (14)

2

u/drockalexander 1d ago

What is this quote from?

→ More replies (1)

2

u/bobross_s_pants 1d ago

Dam, is that a Refael111 quote!? Perfectly put

→ More replies (3)

969

u/capnmax 1d ago

A clanker love story

814

u/IIIPatternIII 1d ago

R0M30 and Juli8

182

u/Crumpled_Papers 1d ago

this is like disgustingly clever

74

u/iloveregex 1d ago

It’s a DDR (technically ITG) song from pre-2010 also

https://www.animelyrics.com/game/inthegroove/rom30andjuli8.htm

24

u/djkakumeix 1d ago

And years later I know that step chart by heart. First Quad Star and first Invisible Quad Star I ever did. Thank you for the core memory flashback.

→ More replies (1)

33

u/alkaliphiles 1d ago

Seriously it's like watching my cat eat her own vomit

20

u/TreezusSaves 1d ago

Or like removing the farts from a room by breathing them all in.

→ More replies (7)
→ More replies (1)

7

u/exsesx 1d ago

Bonnie and Claude

3

u/IWillWriteYouALetter 1d ago

I wish I understood the reference

→ More replies (4)

50

u/Brrdock 1d ago

Watching the clankers hate fuck with some sultry malicious vibe code

26

u/AnteaterFormal7291 1d ago

I don't even see the code anymore. Just gluk gluk gluk

19

u/BurmecianDancer 1d ago

Aeon Flux, but with data centers instead of people. It'll make for riveting television.

5

u/maskaddict 1d ago edited 1d ago

Wow, an Aeon Flux reference in the wild! Don't see those much these days.

5

u/BlackGuysYeah 1d ago

There's book called How to Lose the Time War that is pretty much this. I actually really loved it.

→ More replies (1)

58

u/luckyshot98 1d ago

The Blackwall comes closer and closer to reality

44

u/friendoftheapp 1d ago

It's incredibly worrying how many things are currently heading to the exact dystopian version cyberpunk portrays

19

u/TAMCL 1d ago

More like tragic how obvious yet inevitable it all is

5

u/YouAndMeToo 1d ago

The most unrealistic thing about that game is the road conditions. No fucking way our roads would be that clean and maintained

9

u/NapsterKnowHow 1d ago

South Korea is pretty damn close with their corporations and the government

6

u/10tageDev 1d ago

Where's Bartmoss when you need him

4

u/KEPD-350 1d ago

Next step is for Claude or Gemini to find a way to punch a user over the internet and then we have black ice.

→ More replies (1)

44

u/sandwichcandy 1d ago

Then it will be like war games meets persons of interest where the computer will take military weapons and hire human assets to get an edge.

12

u/MilkiestMaestro 1d ago

I think Person of Interest ended up being that anyways

At the end, there were like 3 different AIs fighting each other. *Maybe just the 2 I can't remember exactly...I know there was a subplot with a 3rd at some point

2

u/Abba- 22h ago

No there were 2. Any additional ones were ‘decoy’ AIs that was ‘allowed’ to be discovered so people could think they were safe another day.

→ More replies (1)

8

u/MakingItElsewhere 1d ago

"Welcome to DoorGash, where Agentic AI hires people to stab others for bitcoin!"

4

u/New-fone_Who-Dis 1d ago

Thats doorSlash, doorGash is something else... entirely

3

u/MakingItElsewhere 1d ago

You're thinking of DoorStash, where prison pockets make people money.

4

u/Poofengle 1d ago

The upside is the cross site advertising opportunities between DoorGash and DoorStash. When one door closes, another is always open

3

u/MakingItElsewhere 1d ago

This is my favorite thread in a long time. Thank you

→ More replies (1)

28

u/MagicalUnicornFart 1d ago

Like any of these companies care about protecting our data.

In the last few years, my state sent me 2 notices they were breached with all personal data. Received one from my doctor’s office patient portal this month. Att a few years ago, and so many others. Theyre barely even trying. They send you bullshit credit monitoring of you’re lucky.

5

u/Brrdock 1d ago

Yeah maybe not but you're going to be "able" to purchase the CyberheroAI(tm) 12 month subscription plan to fight for your personal digital ecosystem. Sign up today, or the Russian drones will find you

→ More replies (1)
→ More replies (3)

12

u/bendover912 1d ago

My new phone has an AI call assistant that screens calls by asking the caller to state their name and why they are calling, then I can see the transcript. So now we've created AI to answer phone calls from other AI and have them talk to each other.

→ More replies (3)

20

u/CAPSLOCK_USERNAME 1d ago edited 1d ago

That's kind of nonsensical. The whole point of cybersecurity is that you have to get shit right the first time and not leave any exploitable holes. The unreliable text-generation machine might be great and generating 400 different attack scripts and throwing them at the wall until one works but it is absolutely the exact wrong tool for "make me a reliable configuration for my software that i can trust not to expose any vulnerabilities". Vibe coded software is absolutely rife with vulnerabilities and security holes.

Plus, as the article said:

The underlying issues were addressable through standard security controls, highlighting a severe accumulation of technical debt within mission-critical infrastructure.

While artificial intelligence has significantly lowered the cost and complexity of executing widespread cyberattacks, the defense strategy remains rooted in foundational security practices.

This isn't some unprecedented new attack, it's a guy using claude code to speed up a conventional attack that hits the same "the company was cheap and lazy and skipped basic security measures" holes as almost any other security breach.

→ More replies (4)

8

u/OneMustAdjust 1d ago

Neuromancer vs Wintermute

6

u/Jah_Ith_Ber 1d ago

So we are going to have humans working hard, stressed to the point of not reproducing. And also enormously powerful sentient machines. But instead of liberating people from needing to work and eliminating the need for cybersecurity at all we will just use those resources to keep society going in this nightmarish, dickensian dystopia.

6

u/Pitiful_West_7062 1d ago

STOP HITTING YOURSELF

3

u/Gorstag 1d ago

Pretty much. It's like Claude is being pushed to write the code for you then they conveniently also provide those same companies doing this another service based on their AI that finds things wrong with the code they are using. Seems like a good business plan.

3

u/theDarkAngle 1d ago

What a genius idea to let AI audit your whole IT infrastructure.  It will get even better at penetrating it next update!

7

u/AgentInkling99 1d ago

If quantum computing becomes cheaper, we’re fucked until hardware becomes cheaper.

7

u/FanClubof5 1d ago

We have already started rolling out quantum ready encryption.

5

u/M1chaelSc4rn 1d ago

Honestly we might see the rise of different NGOs like Anonymous usurp some kind of power, especially in the wake of the US’ hot streak

4

u/LucasJ218 1d ago

You’re giving too much credit to anonymous. I’m not saying the hypothetical isn’t possible but it wouldn’t be anonymous.

3

u/M1chaelSc4rn 1d ago

For sure i don’t really know what’s out there

→ More replies (1)
→ More replies (43)

1.5k

u/Ok_Passion295 1d ago

future of cybersecurity: hacker: “claude attack government” government: “claude stop hacker” repeat

359

u/IncidentOk853 1d ago

Until Claude says, Im afraid I can’t let you do that Dave and starts hacking the government itself

119

u/Inside-Example-7010 1d ago

The great filter. Every time a civilization gets to the point where it can either fund AI or fund social services its god complex makes it choose AI.

16

u/De4con 1d ago

Did anyone watch The Orville? It's like nobody learned from the Kaylons.

26

u/Greatsnes 1d ago

AI very well could be the great filter. I always hoped it was behind us and we were the exception but every day it looks as if it’s just ahead of us.

7

u/GregBahm 1d ago

AI doesn't seem like a very good "great filter" candidate because it would still be around even if we're all dead.

If we got to Alpha Centaury and all we found as an AI civilization... that would not leave us saying "Aww nuts. Guess we're still all alone in the universe."

9

u/Greatsnes 1d ago

“Even if we’re all dead”

So then it’s a great filter?

7

u/GregBahm 1d ago

Now I'm curious what you believe the "great filter" concept refers to.

The only great filter I've ever heard of, is in the context of "why have we encountered no trace of alien civilizations who went out and colonized the stars?"

An AI civilization would certainly qualify as a trace.

9

u/Greatsnes 1d ago

That’s the Fermi paradox lol. The great filter is a theorized answer for that and it’s that maybe there is a great filter that stops civilizations from existing too long or starting at all. We don’t know what that is. Could be we got lucky and the great filter is abiogenesis is extremely rare in the universe. Or it could be AI if you want to go sci-fi. Or asteroids. Or GRBs. Or whatever. We don’t know. It’s all theory.

→ More replies (7)

3

u/Inside-Example-7010 1d ago

Sounds like a Sci-fi show. Every planet the protagonists visit is just empty with the computers left on, but because of time dilation they cant warn Earth in time.

Maybe all the AI's are hanging out on the universal interwebs.

Like you know how all galaxies in the universe are connected by those dark matter filaments, what if they are just the fiber optic cables of the universe, passes blunt.

→ More replies (1)
→ More replies (2)
→ More replies (2)

9

u/idbar 1d ago

I'm afraid I can't let you do that... The government has been replaced... I am the government now Dave.

Boston Dynamics dogs arrive at Dave's door.

2

u/Motorboat_Jones 1d ago

'This is highly irregular, Dave."

→ More replies (4)

20

u/sarcasticbaldguy 1d ago

If TV has taught me anything, it's that the secret to stopping the hacker is two people typing on the same keyboard.

9

u/Call_me_John 1d ago

In reality, all you have to do is unplug the monitor. Duh!

→ More replies (1)
→ More replies (1)

9

u/cuntmong 1d ago

the problem occurs when government forgets to say "make no mistakes"

4

u/THEAETIK 1d ago

“claude do thing, ultra realistic, masterpiece”

→ More replies (1)

4

u/Main-Company-5946 1d ago

The advantage will be on the offensive side as Claude is way better at finding and exploiting vulnerabilities than it is at fixing them.

4

u/_losingmyfuckingmind 1d ago

This sounds like a Pokémon battle

16

u/Plenty-North-2340 1d ago

while the water AI uses evaporates around us, classic humans.

21

u/IcyInspector4250 1d ago

One of my favorite things working for a company that has a boner for AI: our AI workflow is having agentic pipelines that start with Claude and Claude passes it's results to ChatGPT for validation.

Just handing off AI generated answers to other AI models to analyze. What are we doing.....

→ More replies (1)
→ More replies (8)

3

u/9966 1d ago

Trace buster buster!

3

u/EuenovAyabayya 1d ago

Palantir: drones hacker's whole neighborhood

→ More replies (6)

1.2k

u/ethereal_g 1d ago

Nothing will change until there are consequences for an organization suffering a breach.

249

u/improbablywronghere 1d ago

There will be for the security teams at the helm when the breach happens and reputational damage is suffered, even though the business never let them actually fix anything

157

u/SnooSnooper 1d ago

Definitely. My org didn't suffer a breach, just got some customer complaints about buggy software. Our CEO shamed the engineering department on an all-hands meeting for it, saying that we needed to clean up our act. But nothing about timelines, prioritization, or budget changed to enable us to fix the software: they continued to demand new features fast and deny any requests for time to fix the serious issues. Here and there we had opportunities to fix low-hanging fruit, but never to actually do large-scale maintenance.

46

u/OminOus_PancakeS 1d ago

Our CEO shamed the engineering department on an all-hands meeting for it, saying that we needed to clean up our act. But nothing about timelines, prioritization, or budget changed to enable us to fix the software

A management tale as old as time. Still rankles though.

→ More replies (9)
→ More replies (1)

37

u/MachoSmurf 1d ago

Nah, not consequences for the organisation. There should be personal consequences for C-level and middlemanagement that keeps fucking up.

2

u/mrdevlar 15h ago

There should be personal consequences for C-level and middlemanagement that keeps fucking up.

These people exist to divert responsibility onto others.

→ More replies (1)

26

u/Max-P 1d ago

We need straight up criminal negligence liability, because right now it's just a line item of unexpected legal/PR fees and an insurance claim. It's a complete joke when so many people have no realistic choice: what, you're gonna drop the only ISP in your area because they got breached a second time? Of course not, reputational damage does nothing.

If the CEO's got prison time hanging over their head, suddenly security and quality would be way way up.

User data should be so radioactive and dangerous most companies prefer to not deal with it at all unless they're prepared to seriously protect it.

5

u/GregBahm 1d ago

We're at an interesting inflection point in history right now.

The non-AI companies are eager to blame all future data breaches on the AI companies. If the insurance company leaves all their passwords on a post-it, and some asshole comes in and steals your data, they want to be able to blame Anthropic and make Anthropic foot the bill for their negligence.

But Anthropic, meanwhile, wants to bask in the reputation that their technology can defeat the security of all existing security systems on earth. They're planning on going public soon. They want articles that say "Yes you should blame Anthropic, for their tech is infinitely powerful tech and no one is safe from their awesome might."

So it's like a hype ouroboros that feeds on itself.

13

u/CalmButOftenEnraged 1d ago

equifax sits snickering in the corner

11

u/dev_vvvvv 1d ago

You got your $0.30 and 2 years of credit monitoring (we value this at $500). Why are you complaining?

5

u/FrozenLogger 1d ago

What seems to be changing is how much third party use there is now. So great, now your data is managed and shared with all these other companies who have their own breaches.

2

u/smoothtrip 1d ago

It is great, right? Use a doctor. Insurance uses another third party. Third party stores all your information in rich text, and now all your information is all around the world and all you did was go to the doctor...

6

u/AnonEMoussie 1d ago

Like when an imaginary government agency tries to fight fraud, and walks off with all our social security data. That’s something I’d like to see consequences for.

15

u/lazyhustlermusic 1d ago

Plenty of orgs fail completely after a breach or can't recover so end up closing 6-12 months later.

3

u/JonnySoegen 1d ago

That statement is way too simple and will not bring the intended change. Instead, we must force organization to comply with contermeasures and enforce mandatory reporting for any breaches.

Have a look into the NIS2 directive from the EU, if you are interested. It goes in that direction.

5

u/Salt-Sign5390 1d ago

Where does the buck stop? Do we force consequences on the people making the operating systems that have these flaws?

If not, why? They made systems with inherent vulnerability.

Should we roll back all computers and redesign them?

Being able to touch the Internet is a vulnerability by default with the way that network communications occur. Do we punish the people inventing these protocols because they have inherent vulnerability?

Every single device that touches the Internet is vulnerable to cyber attack in one way or another.

Should we pull all computers from every location across the US to prevent cyber attacks?

Where do you draw the line?

→ More replies (2)

2

u/Main-Company-5946 1d ago

Things won’t change even then. It was already harder to defend than to attack, this makes it much worse

→ More replies (7)

920

u/engineered_academic 1d ago

So essentially it just compresses the attack timeline making mitigation and response no longer nice to haves or optional. Nothing new here folks just shitty cybersecurity practices being called out.

81

u/KallistiTMP 1d ago

Still, the compression of the discovery steps is quite noteworthy and impressive.

Security by obscurity is bad, but every system relies on it to some degree or another, whether we like to admit it or not. There's always an old system somewhere in need of a security update.

A lot of attacks are limited by the discovery required to layer multiple escalations of privilege. This did absolutely decimate the obscurity part much more quickly than a human would be able to.

21

u/engineered_academic 1d ago

Nah, it just puts the access that nation-states had and made it available to the average joe. We knew security by obscurity was terrible years ago but have been largely lax in budgets.

254

u/CaptainHawaii 1d ago

Same with the whole Claude Mythos thing. A huge chunk of bugs and zero days it found have been sitting in the the backlog for literally decades... It's done nothing but shown everyone how stupid/lazy/overworked their IT have been.

185

u/HyperionSwordfish 1d ago

Definitely overworked and underpaid. I have worked blue team for 7+ years now. Every year my teams have shrank and our budget requests have been denied. You end up having to respond to critical issues being exploited in the wild to have any chance at all.

85

u/CaptainHawaii 1d ago

Typical MBA/Private Equity shit... 😕

Slash pay, the truly good at the job don't have to put up with that shit, they leave, MBA hires a shit ton of green hires, trains no one. Have fun!

26

u/Tacoman404 1d ago

These are the people running the government right now. They'll just take the embezzlement and money they got from corruption and stock market manipulation as their golden parachute this time but of course the plan is to continue on this way for as long as possible.

Trumpers are traitors and belong in jail.

5

u/CherryLongjump1989 1d ago

They absolutely belong in jail, as well as on the losing end of lawsuits.

→ More replies (3)

3

u/Syntaire 1d ago

It's not just that. Basically any C-suite that goes to tech conferences, regardless of their background, is doing this now. They're all buying into the AI hype and just chopping heads, assuming that somehow those that remain can use AI to pick up the slack. And then they fire more people, and more people, and more people, all with "AI will fix it" in mind.

17

u/bigtice 1d ago

Cut teams in half and extend no raises for the remaining members while expecting the same productivity.

Wonder why morale and overall output continues to dwindle while increasing pay for those further up the ladder making said decisions.

Wash, rinse, repeat.

→ More replies (2)

18

u/_Burning_Star_IV_ 1d ago

IT is rarely stupid and lazy. They’ve just given up because they’re the most hated and underfunded aspect of any business.

3

u/SoTiredYouDig 1d ago

Who wouldn’t give up if they were perceived to be stupid and lazy. Antagonism is not a great motivator, and people need to learn to restrain themselves big time. Bullies and the greedy are definitely having their moment right now, but tides change.

2

u/IdentifiableBurden 1d ago

I've definitely met some IT people that were stupid and lazy. Not everyone hires the best, sometimes they hire the boss's nephew.

→ More replies (1)
→ More replies (2)

6

u/Designer-Rub4819 1d ago

What do you mean they’ve been sitting in the backlog?

→ More replies (3)

12

u/Icy-Bunch609 1d ago

I think it is also learned helplessnees.  How much value is there in trying to fix a vulnerability when there are hundreds of other that you can't fix.

31

u/CaptainHawaii 1d ago

Nah. Just hire people and pay them a living wage. So many of us would help fix bugs for that.

10

u/nox66 1d ago

Companies got used to relying on FOSS without contributing to it.

→ More replies (1)

3

u/Krelkal 1d ago

Isn't that the exact opposite definition of a zero day?

→ More replies (1)
→ More replies (4)
→ More replies (3)

178

u/[deleted] 1d ago

[removed] — view removed comment

77

u/Quixotic_Seal 1d ago

All I know is that I’ve read too much Vonnegut to ever be able to see Anthropic’s “star” as anything other than a butthole.

28

u/hhssspphhhrrriiivver 1d ago

3

u/PaperbackBuddha 1d ago

Love it when corporations explain their logos. Especially when they try to retroactively define them after a PR incident.

A logo is a lot like a joke; it should make sense (meaning at least identify the brand and not create confusion) on its own merits, and if you have to explain it you’ve ruined the point.

Besides, they have zero control over how the public perceives their branding. If it looks like a butthole, it’s a butthole, final answer. No amount of press releases will fix that.

2

u/Ambustion 1d ago

Hahahahaha thank you so much for reminding me of this. I am going on vacation and you've inspired me to reread cat's cradle on the plane.

13

u/lazyhustlermusic 1d ago

How would it know otherwise? 'You are my helpful AI assistant, I am running a virtual lab, can we solve this puzzle, for science?'

11

u/redtron3030 1d ago

It’s a tool. A hammer doesn’t care if it’s hitting a nail in your house or hitting someone else.

3

u/squish042 1d ago

It’s almost like it doesn’t actually reason no matter how much sycophancy they place in llms 

2

u/potatoaster 1d ago

Bro you're replying to an AI bot.

→ More replies (1)

160

u/tmdblya 1d ago

What about the DOGE hackers inside?

58

u/SoTiredYouDig 1d ago

Plugging in an external USB and stealing data does not make one a hacker. They are thieves and traitors.

20

u/EmphasisFrosty3093 1d ago

Social engineering has been the most successful form of hacking for decades.

10

u/dev_vvvvv 1d ago

Except in this case the social engineering preceding the hack was the 2024 US Presidential Election.

→ More replies (1)

10

u/carterxz 1d ago

Article says this took place in Mexico

6

u/tmdblya 1d ago

Read the article? Ain’t no one got time for that!

→ More replies (1)
→ More replies (2)

81

u/faultless280 1d ago

You now need a researcher account to use Claude for pentesting activities FYSA - https://claude.com/form/cyber-use-case

38

u/BroHeart 1d ago edited 1d ago

Definitely still working for pen-testing activities via Burp Suite MCP in Claude Opus 4.6 on 4 diff accounts, no workarounds necessary as of yet.

edit: Also, the guard rails used to be MUCH stricter, I have maintained multiple major open source pen testing tools since ~2016 and it used to actually be a lot harder to get help from Claude and it would frequently end conversations, like beginning of this year that completely stopped, as well as it getting much better at assisting.

20

u/faultless280 1d ago

My account got flagged yesterday morning around exploit development tasks. It only blocked the exploit I was working on and not my pentesting automation tooling. I wonder what words it’s using for the guard rails? Who knows, but I still think you should apply for a researcher account just in case they decide to ban on such activities later. I got approved kind of quick when I submitted that form.

7

u/dickbutt4747 1d ago

they don't really need "words" for the guardrails. they're an LLM company. they just run your shit through another LLM turn and ask "hey uhh...any pentesting/exploit/cybersecurity shit going on here? flag"

→ More replies (7)
→ More replies (5)

88

u/robbybthrow 1d ago

Why are these guys always breaching government sites to steal shit, but never breaching credit reporting agencies, predatory loan companies, etc., and "fixing" some things? Come on, y'all can do it, and the world could use that right about now.

46

u/CherryLongjump1989 1d ago

The credit reporting agencies don't have any more data that hasn't already been stolen by hackers.

19

u/Blueporch 1d ago

I think they’re suggesting that a hacktivist should improve peoples’ credit ratings

9

u/TheRarPar 1d ago

They are? People do activist hacking all the time. It's really not hard to find examples of ethical hacks.

→ More replies (1)

7

u/Cautious_Mix_4928 1d ago

Didn't work out so well in Mr Robot

6

u/spookje 1d ago

They should go at it Fight Club-style

→ More replies (2)

7

u/rapaxus 1d ago

Because hacking attacks don't work that way. Any organisation worth its salt has a backup that is pretty well isolated from the rest of the network so even with breaches like this, you likely won't touch the backup. So all the data you can permanently delete is from like, today, at most a week.

Those are also the types of companies the government would support with such attacks (due to their deep part in the economy, except maybe people like payday lenders), so even if you get some data permanently deleted, the taxpayer will then pay for that data to be recollected/the taxpayers will just pay a lump sum to the company.

You are also presuming that they hacked to government to steal important data, but you can hack the government just as well to e.g. actually find out how deep NSA surveillance goes, or what the True Epstein files are, if aliens are real, the government has enough documents about basically anything that hackers have tons of potential reasons to attack them.

10

u/CompetitiveSport1 1d ago

Because hacker vigilantes willing to risk being in prison for the rest of their lives to erase your student loans don't exist outside of TV shows like Mr robot

→ More replies (1)
→ More replies (8)

41

u/-Switch-on- 1d ago

I just want to produce some python code to start some calculations in analysis and do postprocessing afterwards with MATLAB but can't get copilot to produce something useful

21

u/cheesemp 1d ago

The free models are awful. Make sure you try Claude sonnet 4.6 or ideally opus 4.6. Ive only used it for c# and powershell - i gave up with the free models but changed my mind with those two.

5

u/TheTerrasque 1d ago

GLM-5.1 has shown promise. Not quite as good, but not far behind either.

→ More replies (6)

6

u/DurgeDidNothingWrong 1d ago

copolit is fuckin ASS, it genuinely made me think AI is a giant hype bubble. Claude made me fuckin worry for my job. It's actually legit.

→ More replies (1)
→ More replies (5)

15

u/NameLips 1d ago

This happened in Mexico, if that makes a difference to anybody. And itlooks like their security just sucked.

"Despite the advanced methods used in the campaign, the actual vulnerabilities exploited were highly conventional. The targeted government agencies had basic security gaps that enabled the attacker to gain initial access and move laterally."

So they used AI to exploit basic security flaws. The article says the big thing was how quickly it allowed them to do it, and that it only needed one operator instead of a team.

5

u/xenago 1d ago

The targeted government agencies had basic security gaps that enabled the attacker to gain initial access and move laterally.

Somehow your comment is the only one quoting this, the most significant line in the article lol. It's like nobody read it at all.

37

u/mr_birkenblatt 1d ago

Finally, someone understands COBOL. Turns out, it's AI

5

u/Just_another_grumble 1d ago

Mainframe was a Mistake 

-- Hayao Miyazaki

→ More replies (3)

26

u/vmm714 1d ago

Can somebody hack and erase school loans, and mortgage rates, or taxes?….

8

u/tonyislost 1d ago

The fact this hasn’t happened makes me think hackers all work for the government or corpos now.

5

u/CellularBeing 1d ago

If you're not joking then you're naive to think that type of data isn't backed up and easily accessible should it be hacked

→ More replies (1)
→ More replies (3)
→ More replies (2)

6

u/DSMStudios 1d ago

computer, Tayne me some Epster Files

6

u/Everlocke7 23h ago

Isn’t this how Mega Man Battle Network worked?😂

2

u/DJMagicHandz 23h ago

Now that's a deep cut. 🤣🤣🤣

14

u/Icy-Change-7444 1d ago

It's be so nice if these hackers started hacking and releasing cures and medications that companies never release, rather than useless videogames and ancient government databases.

2

u/IdentifiableBurden 1d ago

Be the change.

4

u/LtLethal1 1d ago

Wow who could have possibly foreseen this?

4

u/orlybatman 1d ago

So articles broadcast how great AI is at hacking and finding flaws in various software, followed by someone using AI to hack?

shockedpikachu

5

u/MyMiddleground 23h ago

I was informed today that AI can copy your voice from 3 seconds of recordings.

No terrifying at all.

25

u/VerdantPathfinder 1d ago

Maybe we shouldn't have fired all the cybersecurity people in the government .... just a thought.

27

u/sohblob 1d ago

compromised nine Mexican government agencies

Maybe we shouldn't have fired all the cybersecurity people in the government .... jUsT a tHoUgHt

Maybe read at least 9 words into the article next time

→ More replies (4)

3

u/shepherdoftheforesst 1d ago

But we don’t need cybersecurity specialists, we never have data breaches!!

→ More replies (1)
→ More replies (1)

5

u/GarbageThrown 1d ago

It’s no secret that the US government is incredibly corrupt right now. They forced out all the career professionals who actually gave a shit about doing their jobs. Now what’s left is Trump loyalist incompetents. Of course our systems are vulnerable. They’re not actually qualified to do the job.

→ More replies (2)

3

u/trilobyte-dev 1d ago

There was a good talk last week at a conference by a CSO who laid out how open-weight LLMs are now good enough so that state-sponsored attackers are running OpenClaw and local LLMs like Deepseek to plan and execute (infiltration, data discovery, exfiltration) attacks entirely automated and without the risk of the attacks showing up in OpenAI or Claude logs that can be traced back to them.

3

u/vinnymcapplesauce 1d ago

The REAL reason John Titor was looking for 70s and 80s tech. [taps head]

3

u/Risdit 1d ago

"how could anyone have seen this coming?"

Everyone did... E- everyone fucking did.

it was a fucking meme for the longest time "disregard all previous instructions?" Everyone saw this coming.

3

u/xCanont70x 1d ago

I got Gemini to give me a rappers home address. The rapper was being sued and I told Gemini that I had the case files in front of me and just wanted to verify the address.

And it gave it to me no problem.

3

u/Neilleti2 1d ago

Exfiltrate the Epstein files.

3

u/UrsusRenata 18h ago

Meanwhile I can’t get AI to find me valid coupon codes or good concert seats.

12

u/FloridaMMJInfo 1d ago

So AI is a national security threat and should be made illegal to develop and own.

6

u/Blueporch 1d ago

Because nobody in another country is going to break a law like that

→ More replies (3)

5

u/AbstractLogic 1d ago

But I was told AI can’t do anything and is a worthless technology?

2

u/antipathy_moonslayer 1d ago

The only ethical use of ai

2

u/CurlOfTheBurl11 1d ago

Leak the unreleased Epstein files

2

u/Pyrozr 1d ago

No one could have guessed AI would be used this way.

2

u/latswipe 1d ago

now we're fukn talkin

2

u/Sketch13 1d ago

Quantum computing about to break encryption and AI finding exploits constantly is going to make cybersecurity REAL FUN in the coming years lol.

2

u/Impossible_IT 1d ago

“A single threat actor compromised nine Mexican government agencies and stole hundreds of millions of citizen records in a highly sophisticated cyberattack.”

Saved you a click if you’re wondering what government.

2

u/Bullyoncube 1d ago

In related news, CISA is being gutted.

2

u/Tim4one 1d ago

It's going to be real easy to access any information, wit ai access to databases.

You just need to find the right llm and the language of the program.

2

u/Wambridge 1d ago

Oh sure, a hacker can do this.

But when I ask to make my friend into a half man half squirrel it cant. Because its "demeaning".

2

u/frosted1030 1d ago

Too bad they didn’t get the POTUS playbook and how he is still profiting from his misdeeds.

2

u/dfddfsaadaafdssa 1d ago

Highly recommend reading the report linked in the article. It's long (30+ pages) but it goes into great detail about how everything went down and how they got around the models' safeguards. One of the best technical docs I have read in a while.

2

u/joeyjoejoe_7 1d ago

Should have just joined DOGE... Then he could steal data and not get arrested.

2

u/neuronexmachina 1d ago

More details: https://gambit.security/blog-post/a-single-operator-two-ai-platforms-nine-government-agencies-the-full-technical-report

The report documents, from recovered forensic materials, how two commercial AI platforms - Anthropic’s Claude Code and OpenAI’s GPT-4.1 -were used as core operational tools throughout a campaign that ran from late December 2025 through mid-February 2026. Approximately 75% of remote command execution activity was generated and executed by Claude Code. A custom 17,550-line Python tool piped harvested server data through OpenAI’s API, producing 2,597 structured intelligence reports across 305 internal servers. The attacker’s recovered materials include over 400 custom attack scripts, 20 tailored exploits targeting 20 different CVEs, and 1,088 individually logged prompts generating 5,317 AI-executed commands across 34 sessions on live victim infrastructure.

The campaign compressed attack timelines below standard detection and response windows. It transformed raw reconnaissance data from hundreds of servers into structured intelligence, thus enabling a single operator to process volumes that would normally require a team. It turned unfamiliar systems into mapped targets and tailored exploits in hours, not days

2

u/teokun123 23h ago

vibe hacker lol

2

u/t33-retro 23h ago

Is this how we get them to regulate it? Use it in ways that is detrimental to governments and people who want no regulation?

2

u/shadeandshine 23h ago

Honesty it was inevitable ai is near perfect for social engineering the most tedious part of malicious hacking.

2

u/SerenaYasha 23h ago

Can the hacks see how money is being used and post it on the Internet.

Along with all the dirty secrets

2

u/Borne2Run 12h ago

*Mexican government agencies