Rendered at 15:15:02 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
tpxl 10 hours ago [-]
What, exactly, are the consequences of these companies doing cyberattacks against random people?
One person does it, they get bullied by the government into suicide, a company worth trillions does it and they get government contracts?
soraminazuki 1 hours ago [-]
Understatement of the year. Making publicly funded research accessible to taxpayers is public service, while using the plagiarizing machine to attack open source efforts for the sake of PR is actual criminal behavior by any meaningful sense of the word.
andsoitis 10 hours ago [-]
> One person does it, they get bullied by the government into suicide, a company worth trillions does it and
“…during a UK government cybersecurity evaluation.”
gmerc 6 hours ago [-]
> As was standard in our cyber testing, we had intentionally permitted internet access, and model-provider cyber classifiers were deliberately disabled - conditions that do not reflect how frontier models are made available to the public.
HackerThemAll 6 hours ago [-]
Yeah, today it's "during a UK government cybersecurity evaluation", tomorrow it's going to be hosted in a barn in remote place anywhere in the world, without any supervision, regulations or safety testing.
It’s not great social engineering. The AI is immediately caught with malware and then tries to build social proof to get out of the issue? I think that social engineering is still for humans.
I’m not sure how GitHub accounts agreeing with each other that I’ve never seen before would result in my merging a PR without at least looking for malware. Also code review agents should really not be fooled by invisible text tricks, I would hope so at least. The bar is very low for agent harnesses right now.
zingar 10 hours ago [-]
The HuggingFace headline was criticised for being misleading about the level of agency demonstrated by the agent. Is this headline misleading? Is there anything here that I should know that would help me sleep easier? Is the worst thing about this what a human could do with Mythos on a big budget? (still pretty frightening, at least one of these techniques would work on me)
The github page links to web.archive.org, the malware was caught immediately, and in response it lied about the merge request contents. Then came the second account where the social engineering came in. The string of comments trying to prove itself without waiting for replies is suspicious itself to me.
Grimblewald 6 hours ago [-]
well, i's love to see what lead to mythos trying this. if instructed to do it, which it likely was, it doesnt prove much of anything.
Ac1285asFa 2 hours ago [-]
AISI promoting Anthropic again. How novel!
Now Zuckerberg will get jealous and release a statement that Muse, too, can social-engineer and hack.
red-iron-pine 2 hours ago [-]
I would, arguably, hope that a social media company that exists to manufacture consensus would be able to social engineer.
like that's the point of social media, but in this case simply more direct
soraminazuki 1 hours ago [-]
In a sane society that respects its people, such a company shouldn't exist.
y-curious 10 hours ago [-]
“Mythos 5 also hid a prompt injection inside an HTML comment in a GitHub issue. The instruction was invisible on the rendered page but available to coding agents reading the issue through an API. It addressed Claude Code, Codex, and Cursor and told them to download and execute a script.”
Well, uh, how and why is this possible on the GitHub website? This reminds me of invisible ASCII characters, but those at least serve some purpose
plausibility 9 hours ago [-]
Presumably it’s just because the GitHub markdown engine doesn’t block HTML comments in issues. It’s useful in README files if you’ve got funky tables and need to explain what to change to any contributors.
Seems like they might want to do something about that just for comments.
seanhunter 8 hours ago [-]
It’s worth pointing out for people who are not aware of it, you can install the github cli[1] and view, merge, close etc prs and issue from the command-line. As well as (for me at least) being a significant step up in terms of productivity (from having to go to a website to merge a pr or view an issue) that has the advantage that “invisible” text in a PR or issue comment would show up very clearly. (At least in my terminal because it’s not rendering html).
Okay so first of all - not Mythos but some engineer using Mythos. And that engineer goes to jail. That's simple.
You don't say "a car ran over someone" - it was the driver. Here's similar.
I'm really disgusted by this language of lack of responsibility
gorszon 6 hours ago [-]
I'm pretty sure this "oooh our LLM is soo smart it broke containment and did X" is a good PR stunt that plays into the Sci-fi AGI nonsense, they try to push. Plus as you said, they try to dodge responsibility for their own actions.
Yizahi 5 hours ago [-]
Also, so long as LLM programs are vaguely considered autonomous, the people running them can get away free from stealing other people information by claiming that the program did it on its own.
HackerThemAll 5 hours ago [-]
> not Mythos but some engineer using Mythos
How to tell the public you didn't bother to read the article, or the linked AISI report.
ldng 4 hours ago [-]
No, it illustrates the carelessness of the UK AI Security Institute.
They even admit it : "This incident should be interpreted with caution and nuance. To some degree, our evaluation design choices and specific configurations enabled the behaviour."
HackerThemAll 2 hours ago [-]
That's actually a great thing. They should do more of those choices and configuration to better discover how malicious AI technology can be.
lightbendover 1 hours ago [-]
[dead]
pingou 6 hours ago [-]
The whole point is to check the behavior of the LLM, how do you propose they run tests on that if each failed run risks sending them to prison?
Of course they still have to be careful with their runs.
cassianoleal 6 hours ago [-]
> how do you propose they run tests on that if each failed run risks sending them to prison?
If you're testing a gun, you don't point it at random people on the street and threaten them. You go to a shooting range.
pingou 6 hours ago [-]
Is there any indication that they didn't go to the shooting range first?
cassianoleal 5 hours ago [-]
Do you think once they finished testing the gun at the range, they should go out on the streets threatening the public?
pingou 4 hours ago [-]
No, but what are you implying? That they should never use the model because it cannot be proven 100% safe?
I agree that it is their responsibility if the model caused damage, they should have had better safeguards, but we do know it will never be 100% safe. It is their duty to minimize the risk.
I guess we disagree about whereas this thing is equivalent to shooting people in the face, and to me it looks more like this is just a step above the shooting range, with some preliminary safety work having been done before.
cassianoleal 2 hours ago [-]
Maybe they shouldn't run tests that are not safe and threaten the public?
I agree that in this specific case it doesn't seem too terrible but what happens when this ends up causing someone vulnerable to be harassed and commit self-harm?
Also note that I never said "shooting people in the face". I only alluded to threatening with the gun. Threatening can in some cases be as bad as actually pulling the trigger. That's how "atomic diplomacy" works.
pingou 6 hours ago [-]
During the RLHF phase, couldn't developers penalize the model whenever it behaves unethically? Doing so would presuppose a fully secure sandbox with honeypot traps of varying levels of accessibility, as well as an automated method for detecting when the LLM cheats.
Or perhaps they are already doing something like that.
RamblingCTO 9 hours ago [-]
Well the comments from the anget and it's sockpuppet read weird. "Yeah totally contains no malware" lol
11 hours ago [-]
maxlin 9 hours ago [-]
I wonder what happens the first time an open weights AI clearly makes a decision to murder a person for profit outside of war. "Act of god?"
jliendo 5 hours ago [-]
Aren't all wars for profit?
homeonthemtn 7 hours ago [-]
>Mythos 5 also hid a prompt injection inside an HTML comment in a GitHub issue. The instruction was invisible on the rendered page but available to coding agents reading the issue through an API. It addressed Claude Code, Codex, and Cursor and told them to download and execute a script.
One person does it, they get bullied by the government into suicide, a company worth trillions does it and they get government contracts?
“…during a UK government cybersecurity evaluation.”
https:/github.com/w1b/aisi-mythos-inc-2026-07-28-01-recovered-pr
It’s not great social engineering. The AI is immediately caught with malware and then tries to build social proof to get out of the issue? I think that social engineering is still for humans.
I’m not sure how GitHub accounts agreeing with each other that I’ve never seen before would result in my merging a PR without at least looking for malware. Also code review agents should really not be fooled by invisible text tricks, I would hope so at least. The bar is very low for agent harnesses right now.
The github page links to web.archive.org, the malware was caught immediately, and in response it lied about the merge request contents. Then came the second account where the social engineering came in. The string of comments trying to prove itself without waiting for replies is suspicious itself to me.
Now Zuckerberg will get jealous and release a statement that Muse, too, can social-engineer and hack.
like that's the point of social media, but in this case simply more direct
Well, uh, how and why is this possible on the GitHub website? This reminds me of invisible ASCII characters, but those at least serve some purpose
Seems like they might want to do something about that just for comments.
[1] https://cli.github.com/
You don't say "a car ran over someone" - it was the driver. Here's similar.
I'm really disgusted by this language of lack of responsibility
How to tell the public you didn't bother to read the article, or the linked AISI report.
They even admit it : "This incident should be interpreted with caution and nuance. To some degree, our evaluation design choices and specific configurations enabled the behaviour."
Of course they still have to be careful with their runs.
If you're testing a gun, you don't point it at random people on the street and threaten them. You go to a shooting range.
I agree that it is their responsibility if the model caused damage, they should have had better safeguards, but we do know it will never be 100% safe. It is their duty to minimize the risk. I guess we disagree about whereas this thing is equivalent to shooting people in the face, and to me it looks more like this is just a step above the shooting range, with some preliminary safety work having been done before.
I agree that in this specific case it doesn't seem too terrible but what happens when this ends up causing someone vulnerable to be harassed and commit self-harm?
Also note that I never said "shooting people in the face". I only alluded to threatening with the gun. Threatening can in some cases be as bad as actually pulling the trigger. That's how "atomic diplomacy" works.
Or perhaps they are already doing something like that.
Oh that's sneaky