惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Fox-IT International blog
Recent Announcements
Recent Announcements
D
Docker
IT之家
IT之家
B
Blog
Jina AI
Jina AI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 【当耐特】
Google DeepMind News
Google DeepMind News
F
Fortinet All Blogs
量子位
C
Check Point Blog
Microsoft Azure Blog
Microsoft Azure Blog
罗磊的独立博客
博客园 - 司徒正美
李成银的技术随笔
美团技术团队
Blog — PlanetScale
Blog — PlanetScale
雷峰网
雷峰网
The GitHub Blog
The GitHub Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
J
Java Code Geeks
T
The Blog of Author Tim Ferriss
酷 壳 – CoolShell
酷 壳 – CoolShell
MongoDB | Blog
MongoDB | Blog
P
Proofpoint News Feed
L
LangChain Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Y
Y Combinator Blog
大猫的无限游戏
大猫的无限游戏
有赞技术团队
有赞技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
Visual Studio Blog
T
Tailwind CSS Blog
H
Help Net Security
Engineering at Meta
Engineering at Meta
小众软件
小众软件
B
Blog RSS Feed
Stack Overflow Blog
Stack Overflow Blog
月光博客
月光博客
M
Microsoft Research Blog - Microsoft Research
宝玉的分享
宝玉的分享
人人都是产品经理
人人都是产品经理
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
GbyAI
GbyAI
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Last Week in AI
Last Week in AI
Martin Fowler
Martin Fowler
Stack Overflow Blog
Stack Overflow Blog

The Register - Security: Cyber-crime

Jailbroken Gemini helped Russian-speaking fraudster target MAGA crypto users Shai-Hulud copycat hits another npm package Grafana Labs admits all its codebase are belong to someone who popped its GitHub account Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after Nitrogen claims Apple, Nvidia data theft Cache-poisoning caper turns TanStack npm packages toxic Attackers are cashing in on fresh 'CopyFail' Linux flaw 'CopyFail' attackers start cashing in on Linux flaw Real estate giant confirms vishing incident as ShinyHunters and Qilin both come knocking Real estate giant confirms vishing incident as ShinyHunters and Qilin both come knocking ShinyHunters claims dump puts 119K Vimeo emails in the wild ShinyHunters claims 119K Vimeo emails in the wild Romance scammers turn sweet talk into £102M payday First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposed First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposed Pro-Iran crew turns DDoS into shakedown as Ubuntu.com stays down Pro-Iran crew turns DDoS into shakedown as Ubuntu.com stays down French prosecutors link 15-year-old to mega-breach at state’s secure document agency French prosecutors link 15-year-old to mega-breach at state’s secure document agency Nearly half of UK businesses pwned last year as phishing keeps doing the job like it's 2005 UK business breach rate stuck at 43%... blame the phishing What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia Chinese spy group caught lurking in Poland, Asia networks Don't pay Vect a ransom - your data's likely already wiped out Don’t pay VECT a ransom - your big files are likely gone Have I Been Pwned claims Pitney Bowes hit by 8.2M email address leak Pitney Bowes the latest victim of ShinyHunters’ breach-spree Ongoing supply-chain attack 'explicitly targeting' security, dev tools Ongoing supply-chain attack 'explicitly targeting' security, dev tools Medical and utility tech companies hacked by digital intruders Medical and utility tech companies admit digital breakins Burglar alarm biz burgled: ADT confirms cyber intrusion after ShinyHunters extortion attempt Burglar alarm biz burgled: ADT confirms cyber intrusion after ShinyHunters extortion attempt Crime crew impersonates help desk, abuses Microsoft Teams to steal your data Crime crew impersonates help desk, abuses Teams chats ShinyHunters claim they have cruise giant Carnival's booty as 7.5M emails surface ShinyHunters claim they have cruise giant Carnival’s booty Governments on high alert after CISA snuffs out Firestarter backdoor on fed network CISA, NCSC issue Firestarter backdoor warning Medical data of 500k Biobank volunteers listed for sale on Alibaba, UK minister reveals Medical data of 500k Biobank volunteers listed for sale on Alibaba, UK minister reveals Pass the key, passwords have passed their sell-by date Another npm supply chain worm is tearing through dev environments Another npm supply chain worm hits dev environments France's 'Secure' ID agency probes breach as crooks claim 19M records France's 'Secure' ID agency probes claimed 19M record breach macOS ClickFix attacks deliver AppleScript stealers to snarf credentials, wallets MacOS ClickFix attacks deliver AppleScript stealers Yet another ex-ransomware negotiator admits turning rogue after payoff from crimelords Third ransomware pro pleads guilty to cybercrime U-turn AI-assisted intruders pwned Vercel via OAuth abuse and a pilfered employee account AI-pwned: Vercel breach traced to stolen employee creds Crook claims to leak 'video surveillance footage' of companies Crook claims to leak 'video surveillance footage' of companies Adaptavist Group breach spawns imposter emails as ransomware crew claims mega-haul Adaptavist Group breach: Ransomware crew claims mega-haul Scot becomes second Scattered Spider-linked crook to plead guilty in US Scot becomes second Scattered Spider-linked crook to plead guilty in US North Korea targets macOS users in latest heist North Korea targets macOS users in latest heist Textbook titan McGraw Hill on ransomware crew's reading list after 13.5M records exposed McGraw Hill linked to 13.5M-record data leak Automotive data biz Autovista blames ransomware for service disruption Automotive data biz Autovista blames ransomware for service disruption Ancient Excel bug comes out of retirement for active attacks No honor among thieves as 0APT threatens rival ransomware gang Krybit 0APT ransomware gang extorts Krybit amid doxxing threat Fake Linux leader using Slack to con devs into giving up their secrets Fake Linux Foundation leader using Slack to phish devs Booking.com warns reservation data may have checked out with intruders Booking.com warns reservation data may have checked out with intruders Gym giant Basic-Fit confirms data on a million members stolen in cyberattack Gym giant Basic-Fit confirms data on a million members stolen in cyberattack Rockstar Games gets a taste of grand theft data Rockstar Games gets a taste of grand theft data Crypto? Huh. Good gawd y'all, what is it good for? $45M in this case US, UK, Canadian cops disrupt $45M global crypto scam 'Several dozen' high-value corporations hit by new extortion crew in helpdesk phishing spree 'Several dozen' orgs targeted by a new extortion crew Months-old Adobe Reader zero-day uses PDFs to size up targets Months-old Adobe Reader zero-day uses PDFs to size up targets Zephyr Energy loses £700K in cyber hit that rerouted contractor payment Zephyr Energy loses £700K to contractor payment fraud Dutch healthcare software vendor goes dark after ransomware attack Ransomware knocks Dutch healthcare software vendor offline Hundreds of orgs compromised daily in Microsoft device code phishing attacks Hundreds of orgs compromised daily in Microsoft device code phishing attacks US cybercrime losses pass $20B for first time as AI boosts online fraud US cybercrime losses pass $20B for first time as AI boosts online fraud Russia's Fancy Bear still attacking routers to boost fake sites, NCSC warns Russia's APT28 behind latest wave of router, DNS attacks AI recruiting biz Mercor says it was 'one of thousands' hit in LiteLLM supply-chain attack Mercor says it was 'one of thousands' hit in LiteLLM attack Don't open that WhatsApp message, Microsoft warns Iran targets M365 accounts with password-spraying attacks Iran targets M365 accounts with password-spraying attacks Telnyx joins LiteLLM in latest PyPI package poisoning tied to Trivy breach Telnyx package latest hit in PyPI supply-chain compromise European Commission admits attackers broke into public web systems, but says little else
Claude attacks were 'Rorschach test' for infosec community
2026-03-24 · via The Register - Security: Cyber-crime

REG AD

RSA

Claude attacks were 'Rorschach test' for infosec community, scaring former NSA boss

'It freakin' worked' says Rob Joyce - and shows how relentless AI agents can find holes humans miss

RSAC 2026 The now-infamous Anthropic report about Chinese cyberspies abusing Claude AI to automate cyberattacks was a Rorschach test for the infosec community, according to former NSA cyber boss Rob Joyce.

"There were people on one side who hated it," Joyce, who is now a venture partner at DataTribe, said during a Monday talk at RSAC. "They thought it was a meaningless distraction. There was another side who saw it as a significant insight into offensive operations."

Joyce sits firmly in the latter camp. "I saw this as a really important set of insights – and something really scary."

REG AD

The Beijing-backed snoops considered a typical attack chain, broke it into small steps, then built a framework using agentic AI to carry out an intrusion attempt. The agents mapped attack surfaces, scanned target organizations' infrastructure, found vulnerabilities, and even researched and wrote exploitation code.

REG AD

Once they were inside networks, China’s bots found and abused valid credentials, escalated privileges, and moved laterally. In some cases, the agents even found and stole sensitive data.

Machines don't get tired of reading code. They can review and review and review until they find that vulnerability

"But the number one thing to me is: it worked. It freakin' worked," Joyce said. "It brought a set of tools, it went against real-world targets, and it won.” He fears that continuing improvements to LLMs, and the fact they’re now effectively modular so crooks can quickly update their AI tools, means automated attacks will improve "exponentially."

Last year, in an interview with The Register, Joyce said AI will "soon" be a great exploit coder. On Monday, he told an audience of security experts and coders it’s already happened.

The upside? Agentic AI systems’ ability to find zero-day vulnerabilities and develop exploits at machine speed can be a boon defenders, too.

Projects like Google's Big Sleep, an AI agent that helps security researchers find zero-day flaws, have spotted several including a previously unknown exploitable memory-safety flaw in the widely-used OpenSSL library. OpenAI's Codex (formerly Aardvark) similarly uses agentic AI to detect and patch vulnerabilities in code, as does Anthropic's Clade Code Security.

"So across these three frontier models, all doing vulnerability research, they've shown that they can find vulnerabilities in major code," Joyce said.

"In the long term, we get much better code," he continued. "Google Chrome is going to benefit from the Google Big Sleep team, and it is going to be much harder to exploit the most popular web browser on the planet. But in the near term, the ability to find software vulnerabilities across massive code bases and vulnerabilities become exploits. That's a real risk."

Joyce quoted security researcher Sean Heelan, who analyzed OpenAI's then-Aardvark project and said:

REG AD

What this means right now, according to Joyce, is that information asymmetry favors machine attackers. “This is not a story about AI being smarter than the humans. It's about scale and patience, its [AI’s] ability to look at all of the techniques and components of that and develop the vulnerabilities. Machines don't get tired of reading code. They can review and review and review until they find that vulnerability."

So what does this mean for defenders? Joyce thinks they need to become "exceptional" at security basics.

The more tokens you spend, the more bugs you find, and the better quality those bugs are. You can also see it in my experiments. As the challenges got harder I was able to spend more and more tokens to keep finding solutions. Eventually the limiting factor was my budget, not the models. I would be more surprised if this isn't industrialized by LLMs, than if it is.

That means using AI tools to review code and detect anomalies in patterns and behaviors, which can indicate that attackers are abusing a legitimate tool – or user – for malicious purposes.

Also, he recommends, start doing agentic red teaming against your organization to proactively find flaws and misconfigurations. "You are going to be red-teamed whether you pay for it or not," Joyce said. "The only difference is, you know who gets the results delivered to them." ®