this post was submitted on 20 Jun 2026
287 points (97.0% liked)

Technology

86743 readers
3889 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] janus2@lemmy.zip 143 points 1 month ago (5 children)

script kiddies wrecking corporate security is funny
prompt kiddies doing it is just depressing

[–] LiveLM@lemmy.zip 72 points 1 month ago (1 children)

Didn't think I'd ever side with no script kiddie but at this point fuck it.
If your company can't even be bothered to do the bare minimum in security then yeah I hope the least skilled hacker ever comes along and wrecks it.

[–] adespoton@lemmy.ca 20 points 1 month ago (1 children)

Thing is, with the latest frontier models, the least skilled person can find a crack in the most secure company around, as long as they can string a few sentences together.

It isn’t about “bare minimum” anymore. All it takes is a single lapse in vigilance from a single employee, and they’re in… and the LLM doesn’t have to pause to figure out what to do next.

[–] Damage@feddit.it 20 points 1 month ago (3 children)

Pentesters have access to LLMs too

[–] Mika@piefed.ca 28 points 1 month ago

some hacker unleashes malicious AIs to the internet, breaking it apart cause AI keeps finding vulnerabilities in everything and break things faster than humans can fix

corporates build corporate internet and the blackwall, which is AI to fight malicious AIs

Gooooood morning Night City!

[–] ByteJunk@lemmy.world 7 points 1 month ago* (last edited 1 month ago) (1 children)

Yeah, but an LLM's arms race isn't "doing the bare minimum in security", which is what the poster before was saying.

This is a genuine concern, where whoever has access to the best/most recent/most expensive models can unleash chaos - I'm talking state-sponsored attacks, mega-corp espionage, bored billionaires,...

[–] MagicShel@lemmy.zip 4 points 1 month ago (1 children)

The people you listed were already doing this. The problem is Darrell, the guy who thinks Earth is flat, can also do this.

[–] ByteJunk@lemmy.world 4 points 1 month ago* (last edited 1 month ago) (2 children)

Meh. When you're expecting to have to defend against an army battalion, how much of a thread is Darrell the flat-earther and his AR-15?

Because if Darrell is doing damage, you've been conquered and didn't even noticed.

Edit: in case you're not following the thread and feel an urge in your loins to come defend Darrell, do note that I'm not disparaging the issues a dimwit with AI can cause. I'm pointing out that other players will have even larger sticks than your friend Darrell.

Case in point, Darrell will not have Claude Fable. Others will.

[–] adespoton@lemmy.ca 1 points 1 month ago (1 children)

With AI as the army battalion, Darrell becomes a general.

[–] ByteJunk@lemmy.world 2 points 1 month ago

Sure, in a world where the big boys have Death Stars.

[–] minfapper@piefed.social -1 points 1 month ago (1 children)

In this analogy Darrell fires an ICBM, because everyone has access to a ton of those for $20/mo.

The overall point is that doing (what used to be) the bare minimum is no longer even close to enough. To be considered adequate, you need super ironclad defense, because even low skilled attackers have access to very powerful weapons.

[–] ByteJunk@lemmy.world 1 points 1 month ago

You said so yourself, everyone has a ton of those.

Darrell is firing an ICBM at a place that is being hit with hypersonic hydrogen bombs all the time. Either he's hitting rubble, or a damn impressive defense that he's unlikely to break.

[–] adespoton@lemmy.ca 2 points 1 month ago

It’s easier to destroy a house than to build it.

[–] A_norny_mousse@piefed.zip 36 points 1 month ago (2 children)

And no-skilled attackers can buy exploits.

Claude helping is insignificant to the story.

The real headline should be:

At least 14 companies' IT security is practically non-existent

[–] eldebryn@lemmy.world 5 points 1 month ago (2 children)

It is significant because a random teenager can't google "download exploits" and have them available 5mins later.

Powerful AI models and agents though are on your fingertips without you even asking.

Sure, people can buy guns. But what if every person could materialize a chainsaw instead regardless of their skill, maturity, age, or criminal record? 🤔

[–] nomy@lemmy.zip 16 points 1 month ago (1 children)

Random teenagers can absolutely google "download exploits" and have them available, that's pretty much always been the case..

https://www.exploit-db.com/

Full disclosure was a thing once upon a time, where exploits and proofs of concept were dumped publicly, forcing companies to fix the issue or be compromised. That's mostly been moved away from in favor of responsible disclosure, giving companies time to patch the issue before it's known publicly.

Maybe we should be moving back to full disclosure to force these companies to take data security seriously. Or at least then we could point to a known vulnerability as proof the company is shitty and is neglecting their infrastructure.

[–] sukhmel@programming.dev 2 points 1 month ago

Sometimes I read stories of how reading web page source code is tried to be presented as hacking in order to not actually do anything for security, and of white hats sued for doing their job, and think that there are plenty of targets even for someone without exploits or LLMs

[–] 0x0@infosec.pub 2 points 1 month ago (1 children)

Teenagers are definitely able to find exploits via google in 5 if they're motivated.

Buying a disassembled ak-47 on post order and having it shipped to your address anywhere in the world is also possible.

Rules only apply to people that care about them.

[–] MalMen@masto.pt 3 points 1 month ago

@0x0 @eldebryn its not enough to find exploits, you have to know how yo use them... I can see how you can trick AI into guiding you to do a "pen test"

[–] Gust@piefed.social 2 points 1 month ago

At least 14. *screams until hoarse in industrial cybersecurity researcher*

[–] zane@infosec.pub 5 points 1 month ago (1 children)

As someone who works in security, llms just make security happen or not happen faster.

[–] blargh513@sh.itjust.works 3 points 1 month ago

I also work in security.

My company (which can damn well afford the costs) 100% REFUSES to leverage AI in any meaningful fashion. The CISO himself wrote the most braindead email to the CIO saying basically that AI isn't a threat and then showed it to the rest of us like he's proud of it.

I tried to push some adoption of AI based tools to help detect our own weaknesses and do some basic cleanup work. Nope. Stonewalled. I argued that every attacker is stealing accounts and burning tokens to tear us to shreds using every possible tools they can steal or even buy. We use Copilot.

Blank stares and crickets. We just keep managing our shit in spreadsheets that some dumbass emails as attachments and wonders why everyone has a different version of some useless thing.

At least they're paying me well. When they collapse in a little while, I suppose I won't be too surprised.

[–] minorkeys@sh.itjust.works 0 points 1 month ago

Only if you're stuck in the past.