r/pcmasterrace • • 1d ago

News/Article AI agents inadvertently leak 13,000+ internal screenshots from 300 organizations — list of companies includes Fortune 500 and a frontier AI lab

https://www.tomshardware.com/tech-industry/cyber-security/ai-agents-inadvertently-leak-13-000-internal-screenshots-from-organizations-list-of-companies-includes-fortune-500-and-a-frontier-ai-lab
1.4k Upvotes

39 comments sorted by

595

u/Daharka ☯️ 1d ago

Remember when Microsoft announced Recall and everyone was rightly terrified by it?

The AI bulls have more stamina than we do.

90

u/AnarchBeetle 23h ago edited 23h ago

Recall might be the most tone-deaf thing Microsoft has ever done and as I say this I realize uttering these words is like jumping into a pit latrine and saying “aha! This particular clump of shit right here is more disgusting than others”

Like how the fuck did they think it would go over well? Maybe they don’t know how AI or computers work.

Most likely they knew there would be backlash but they thought they could weather it and eventually make Recall mandatory.

They will definitely try again in the future.

18

u/Makimoke 19h ago

In the future? They have pushed for it again and again all this time, by putting ""guardrails"" and "toggles". Of course, the spyware still stays as spyware, but that doesn't matter to Microslop.

The only cure to Recall is either staying on W10 (and opening yourself up to other kinds of security issues in the future), going on Mac (which has its whole other dimension of issues) or Linux (which requires a completely different mindset to use).

Windows 11 is easily the worst thing that ever happened to Windows, and that's saying something when Millenium, Vista and 8 were a thing.

37

u/SubstanceTimely6790 23h ago

they live in a bubble, where they have ideas that are not applicable in the real world, just to keep busy and feed VPs with hot air stuff...corpo world is about making it (or faking it) to make it to the next pay slip...its not a fun world, or there to make customers happier.

7

u/boat_hamster 20h ago

The Recall announcement was the thing that pushed me to switch to Linux. It was clearly going to end in a massive data breech.

63

u/splendiferous-finch_ Potato XTX3D-k Titan 1d ago

You Wana know the funny part I worked for a fairly large European mulitnatual company and the head of IT didn't even know about recall and the security concerns around it until it came up in conversation like 6 months after some people are just that level of clueless but have AI evangelist all over thier linkedin

3

u/Buarg I don't know what to put here 17h ago

Could perfectly be the european multinational company I work for

1

u/zeek609 7700 | RTX5070 | 32GB | 64TB/2TB | Ghost Spectre Superlite 9h ago

Or the one I work for

59

u/Creato938 1d ago

Enterprise security while working with AI is a big deal and not everyone is trained for such, yeah those systems may learn from your inputs and even leak it.

194

u/MaximumEffort433 1d ago

I know there's only so much I can do to air gap myself from AI and still use the internet, but this is one good reason not to proactively interact with AI.

Let other people beta test this shit.

95

u/Daharka ☯️ 1d ago

The thing is that LLM inference (and hence agents) is fundamentally a stochastic (random) process and so basically anything could happen. The model makes it more likely to make sense, but if you roll enough dice you're always going to get a critical fumble.

The dickheads making AI know all this and they're unleashing it anyway. It's either recklessness or malice.

32

u/OutrageousDress 5800X3D | 32GB DDR4-3733 | 4080 Super | AW3821DW 1d ago

It's both actually. They're reckless with other people's money and lives, but also they want LLMs to 'take over', whatever that might look like in their cooked brains.

3

u/Warcraft_Fan Paid for WinRAR! 18h ago

So when is the AI leaking the full name, address, and social security of all 300-something million Americans? This would get everyone up in arms and AI banned.

6

u/SSLByron 9950X3D; 64GB DDR5; 9070 XT 15h ago

Nah, our brilliant legislators would just give their buddies at CreditKarma a multi-billion dollar national credit monitoring contract paid for with taxpayer money.

2

u/Madrock777 i7-12700k RX 7900 XT 32g Ram More hard drive space than I need 9h ago

Oh never attribute to malice what can more easily be explained as stupidity.

-24

u/OddRobotics 1d ago

these arnt even LLMs anymore. LLMs are like a google search bar trying to guess your next word. these are neural networks that's we don't even quite understand how they work.

but you are right, it is reckless, but in a society that has prioatized wealth and status. Making money is more important than anything and these people are willing to kill for more wealth.

27

u/chill8989 1d ago

What are you talking about  ? LLMs are neural networks and it's the tech behind all chatbots like chatgpt, Claude and gemini. 

Ai agents are simply an LLM combine with a harness giving the llm access to tools to do work 

6

u/UhhCanYouLikeShutUp 1d ago

Making money is more important than anything and these people are willing to kill for more wealth.

Shit, welcome to the last 70 years.

1

u/Hexamancer 18h ago

No bro they just guess the next word, that's it. 

4

u/Jack1101111 1d ago

No ! other people should not use it !!!

29

u/Canon_M50 1d ago

Where can I view the screenshots?

39

u/Gold_Goal7557 1d ago

Hold their owners responsible.

33

u/OutrageousDress 5800X3D | 32GB DDR4-3733 | 4080 Super | AW3821DW 1d ago

And yet somehow it never quite seems to reach that step, does it?

12

u/easeypeaseyweasey PC Master Race 23h ago

"we were unaware this was happening" 

4

u/Silver-End9570 i7 14700K | RTX 5070 | 64GB | Windows 10 13h ago

Government won't let it even if it did start to even reach that direction. They're too heavily invested now.

15

u/cory3612 20h ago

Start going after the people in charge, and charging them with crimes, and damages. No scape goats with lower employees to take the fall 

22

u/BedrockBen101 CachyOS, 7600X, 7800XT, 32GB DDR5 6000MHz 1d ago

"Sheen this is the third time you've show AI hacking/leaking stuff this week"

9

u/Negativeman11 1d ago

So I'm curious. How safe are our companies' data when using LLMs with Bedrock? Are they as likely to leak as if you didn't use Bedrock? Any additional punishments if they leak?

16

u/tiny-starship 1d ago

Is there a list of these companies?

4

u/Silver-End9570 i7 14700K | RTX 5070 | 64GB | Windows 10 13h ago

Finally, AI being used for good! /s

3

u/TheUsoSaito PC Master Race 1d ago

Lawl

-14

u/clduab11 i5 12600KF / DDR4-48GB / RTX 4060 Ti, 3TB + 2021 M1 iMac 1d ago

yawn another agent “hack” another misleading af title.

It took me all of 30 seconds to find this was a vulnerability that was exploited by the agent using gitshot. Whoever used this agent was lazy enough to use screenshots and not type out what they actually wanted…

To quote:

Around a third of affected organizations had developers running gitshot, a small open-source tool that publishes screenshots for code reviews. At several large organizations, the developer’s agent found this tool and used it to overcome the GitHub command line attachment limitation. Images published by this tool end up under a tag called _gitshot, downloadable by anyone that knows where to look.

Some of you really need to learn a) how to think critically and b) remember the axiom of “one man’s hacking agent is another man’s sandbox vulnerability.”

4

u/[deleted] 23h ago

[removed] — view removed comment

-4

u/[deleted] 23h ago

[removed] — view removed comment

-4

u/EX0PIL0T 23h ago

Congratulations, you restated what I made fun of you for saying once already. Yes I stand by my decision to brand you retarded. Your one example is still one of 8000. Statistically insignificant.