▲ | echelon 6 days ago | ||||||||||||||||||||||||||||
Google and Anthropic: this is a SEV0. Assemble your teams and immediately do the following: 1. Issue a public statement that you are aware of this issue and are tracking it 2. Begin monitoring your analytics to see which customers are impacted and shut down their access 3. Reach out to impacted customers and let them know you'll be preparing a list of next steps for them. 4. Monitor for a wider blast radius or larger attack surface area 5. Notify internal teams of broader security efforts as a result of this 6. After this cools down, hold internal and public postmortems. Do this now. Edit: -4 and flagged. I give up. | |||||||||||||||||||||||||||||
▲ | dpoloncsak 6 days ago | parent | next [-] | ||||||||||||||||||||||||||||
What does Google or Antropic have to do with anything here? NX was compromised. Threat actors are using this access to leverage CLI LLMs to search the computer for you. Is this any different than if they just ran a big /find? Should the AI Assistant NOT reply to the request it was given? Why shouldn't it? | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
▲ | octo888 6 days ago | parent | prev | next [-] | ||||||||||||||||||||||||||||
A single top-level comment would suffice. No need to reply to various comments with the same kind of message | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
▲ | 6 days ago | parent | prev | next [-] | ||||||||||||||||||||||||||||
[deleted] | |||||||||||||||||||||||||||||
▲ | yuyu789 6 days ago | parent | prev [-] | ||||||||||||||||||||||||||||
[dead] |