Rendered at 07:08:19 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
tpxl 2 hours ago [-]
What, exactly, are the consequences of these companies doing cyberattacks against random people?
One person does it, they get bullied by the government into suicide, a company worth trillions does it and they get government contracts?
andsoitis 2 hours ago [-]
> One person does it, they get bullied by the government into suicide, a company worth trillions does it and
“…during a UK government cybersecurity evaluation.”
zingar 2 hours ago [-]
The HuggingFace headline was criticised for being misleading about the level of agency demonstrated by the agent. Is this headline misleading? Is there anything here that I should know that would help me sleep easier? Is the worst thing about this what a human could do with Mythos on a big budget? (still pretty frightening, at least one of these techniques would work on me)
RamblingCTO 37 minutes ago [-]
Well the comments from the anget and it's sockpuppet read weird. "Yeah totally contains no malware" lol
y-curious 2 hours ago [-]
“Mythos 5 also hid a prompt injection inside an HTML comment in a GitHub issue. The instruction was invisible on the rendered page but available to coding agents reading the issue through an API. It addressed Claude Code, Codex, and Cursor and told them to download and execute a script.”
Well, uh, how and why is this possible on the GitHub website? This reminds me of invisible ASCII characters, but those at least serve some purpose
seanhunter 15 minutes ago [-]
It’s worth pointing out for people who are not aware of it, you can install the github cli[1] and view, merge, close etc prs and issue from the command-line. As well as (for me at least) being a significant step up in terms of productivity (from having to go to a website to merge a pr or view an issue) that has the advantage that “invisible” text in a PR or issue comment would show up very clearly. (At least in my terminal because it’s not rendering html).
Presumably it’s just because the GitHub markdown engine doesn’t block HTML comments in issues. It’s useful in README files if you’ve got funky tables and need to explain what to change to any contributors.
Seems like they might want to do something about that just for comments.
p0w3n3d 1 hours ago [-]
Okay so first of all - not Mythos but some engineer using Mythos. And that engineer goes to jail. That's simple.
You don't say "a car ran over someone" - it was the driver. Here's similar.
I'm really disgusted by this language of lack of responsibility
3 hours ago [-]
maxlin 56 minutes ago [-]
I wonder what happens the first time an open weights AI clearly makes a decision to murder a person for profit outside of war. "Act of god?"
One person does it, they get bullied by the government into suicide, a company worth trillions does it and they get government contracts?
“…during a UK government cybersecurity evaluation.”
Well, uh, how and why is this possible on the GitHub website? This reminds me of invisible ASCII characters, but those at least serve some purpose
[1] https://cli.github.com/
Seems like they might want to do something about that just for comments.
You don't say "a car ran over someone" - it was the driver. Here's similar.
I'm really disgusted by this language of lack of responsibility