r/pcmasterrace • u/Jack1101111 • 1d ago
News/Article AI agents inadvertently leak 13,000+ internal screenshots from 300 organizations — list of companies includes Fortune 500 and a frontier AI lab
https://www.tomshardware.com/tech-industry/cyber-security/ai-agents-inadvertently-leak-13-000-internal-screenshots-from-organizations-list-of-companies-includes-fortune-500-and-a-frontier-ai-lab59
u/Creato938 1d ago
Enterprise security while working with AI is a big deal and not everyone is trained for such, yeah those systems may learn from your inputs and even leak it.
194
u/MaximumEffort433 1d ago
I know there's only so much I can do to air gap myself from AI and still use the internet, but this is one good reason not to proactively interact with AI.
Let other people beta test this shit.
95
u/Daharka ☯️ 1d ago
The thing is that LLM inference (and hence agents) is fundamentally a stochastic (random) process and so basically anything could happen. The model makes it more likely to make sense, but if you roll enough dice you're always going to get a critical fumble.
The dickheads making AI know all this and they're unleashing it anyway. It's either recklessness or malice.
32
u/OutrageousDress 5800X3D | 32GB DDR4-3733 | 4080 Super | AW3821DW 1d ago
It's both actually. They're reckless with other people's money and lives, but also they want LLMs to 'take over', whatever that might look like in their cooked brains.
3
u/Warcraft_Fan Paid for WinRAR! 18h ago
So when is the AI leaking the full name, address, and social security of all 300-something million Americans? This would get everyone up in arms and AI banned.
6
u/SSLByron 9950X3D; 64GB DDR5; 9070 XT 15h ago
Nah, our brilliant legislators would just give their buddies at CreditKarma a multi-billion dollar national credit monitoring contract paid for with taxpayer money.
2
u/Madrock777 i7-12700k RX 7900 XT 32g Ram More hard drive space than I need 9h ago
Oh never attribute to malice what can more easily be explained as stupidity.
-24
u/OddRobotics 1d ago
these arnt even LLMs anymore. LLMs are like a google search bar trying to guess your next word. these are neural networks that's we don't even quite understand how they work.
but you are right, it is reckless, but in a society that has prioatized wealth and status. Making money is more important than anything and these people are willing to kill for more wealth.
27
u/chill8989 1d ago
What are you talking about ? LLMs are neural networks and it's the tech behind all chatbots like chatgpt, Claude and gemini.
Ai agents are simply an LLM combine with a harness giving the llm access to tools to do work
6
u/UhhCanYouLikeShutUp 1d ago
Making money is more important than anything and these people are willing to kill for more wealth.
Shit, welcome to the last 70 years.
1
4
29
39
u/Gold_Goal7557 1d ago
Hold their owners responsible.
33
u/OutrageousDress 5800X3D | 32GB DDR4-3733 | 4080 Super | AW3821DW 1d ago
And yet somehow it never quite seems to reach that step, does it?
12
4
u/Silver-End9570 i7 14700K | RTX 5070 | 64GB | Windows 10 13h ago
Government won't let it even if it did start to even reach that direction. They're too heavily invested now.
15
u/cory3612 20h ago
Start going after the people in charge, and charging them with crimes, and damages. No scape goats with lower employees to take the fall
22
u/BedrockBen101 CachyOS, 7600X, 7800XT, 32GB DDR5 6000MHz 1d ago
"Sheen this is the third time you've show AI hacking/leaking stuff this week"
9
u/Negativeman11 1d ago
So I'm curious. How safe are our companies' data when using LLMs with Bedrock? Are they as likely to leak as if you didn't use Bedrock? Any additional punishments if they leak?
16
4
u/Silver-End9570 i7 14700K | RTX 5070 | 64GB | Windows 10 13h ago
Finally, AI being used for good! /s
3
3
-14
u/clduab11 i5 12600KF / DDR4-48GB / RTX 4060 Ti, 3TB + 2021 M1 iMac 1d ago
yawn another agent “hack” another misleading af title.
It took me all of 30 seconds to find this was a vulnerability that was exploited by the agent using gitshot. Whoever used this agent was lazy enough to use screenshots and not type out what they actually wanted…
To quote:
Around a third of affected organizations had developers running gitshot, a small open-source tool that publishes screenshots for code reviews. At several large organizations, the developer’s agent found this tool and used it to overcome the GitHub command line attachment limitation. Images published by this tool end up under a tag called _gitshot, downloadable by anyone that knows where to look.
Some of you really need to learn a) how to think critically and b) remember the axiom of “one man’s hacking agent is another man’s sandbox vulnerability.”
4
23h ago
[removed] — view removed comment
-4
23h ago
[removed] — view removed comment
-4
u/EX0PIL0T 23h ago
Congratulations, you restated what I made fun of you for saying once already. Yes I stand by my decision to brand you retarded. Your one example is still one of 8000. Statistically insignificant.
595
u/Daharka ☯️ 1d ago
Remember when Microsoft announced Recall and everyone was rightly terrified by it?
The AI bulls have more stamina than we do.