|
Hey Reader, Anthropic has just announced Project Glasswing. In a nutshell, they are collaborating with major software companies like Apple, Amazon Web Services, Broadcom, Crowdstrike, Microsoft, NVIDIA, the Linux Foundation, etc. because they made a new Claude model called "Mythos" which "has already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser." I don't want to scare you, so I'll start with what you should do to be safe: Keep all of your software up to date at all times. Anthropic has given access to Claude Mythos Preview to major software companies I mentioned above, so they can use it to find these vulnerabilities and fix them. Claude Mythos Preview is NOT released to the general public. I think Anthropic is doing the right thing here. They could have released the model that beats their current flagship model by A LOT on benchmarks, and capitalized on more revenue and more investments coming in. And instead, they did the right thing and kept it to be used for good. Claude Mythos Preview is a model trained for coding. But when you train a model for coding, that also includes cybersecurity, and once you find a security vulnerability, you can also exploit it. Quoting from the announcement, here are some things that Claude Mythos Preview has found: - Mythos Preview found a 27-year-old vulnerability in OpenBSD—which has a reputation as one of the most security-hardened operating systems in the world and is used to run firewalls and other critical infrastructure. The vulnerability allowed an attacker to remotely crash any machine running the operating system just by connecting to it;
- It also discovered a 16-year-old vulnerability in FFmpeg—which is used by innumerable pieces of software to encode and decode video—in a line of code that automated testing tools had hit five million times without ever catching the problem;
- The model autonomously found and chained together several vulnerabilities in the Linux kernel—the software that runs most of the world’s servers—to allow an attacker to escalate from ordinary user access to complete control of the machine.
To be honest, the IT world knew that there were potential bugs and exploits in these software, but they were so hard to find and to exploit that it was a close to 0 chance to be actually exploited. This is what the whole world of Ethical Hacking is based on. An Ethical Hacker finds these vulnerabilites, and instead of exploiting them, they report it to the software company so they can fix it, and they get a reward for it. For example, Apple has a long running Bounty program: It's less money for them to occasionally pay an ethical hacker a bounty than to hire a bunch of them on payroll and pay them every month even if they don't find anything. So what Anthropic is doing now essentially is that they gave out their new Claude Mythos Preview model as an "Ethical Hacker AI for hire" to the companies participating in the program (and they also gave out $100M of compute credits in the program), so the vulnerabilities Mythos Preview can exploit are patched up before it is released. Advice for non-technical folksPlease don't use OpenClaw, Claude Code or OpenAI Codex if you don't know what you're doing. These agentic tools get full access to the computer you run them on, and they can install a lot of things you don't even know about. For example: Let's say you're vibecoding your website in HTML with Claude Code. The agent realizes that it doesn't have the font defined in your branding kit. As it is a paid font, it can't download it from the official source, so then it has to decide whether it should bother you for the font, or try to find it online. Let's say it decides to try to download it from a "free font download" website. It succeeds, and it runs a command to install the font on your computer. All without your supervision or explicit permission. In less than a minute, the AI agent compromised your computer with a random font package that might include a dormant virus. Maybe you won't even notice that something is wrong. Maybe nothing will be wrong for a month. Then the dormant virus gets a command to activate itself and carries out its original mission. I know it is very tempting to want to use Claude Code because you see the flashy demos all the time and you don't want to miss out. And you can use it if you set it up safely:
If you don't know what these mean, you're not ready for Claude Code or agentic tools running on your computer, and that's okay. Reply with "ME" to this email if you'd be interested in joining a 2-hour workshop where we set up Claude Code together in a safe way. (Tickets are going to be $100 for non-members of the Guild) What the future bringsAI LLMs are getting better at coding and thus finding and fixing (or exploiting) security vulnerabilities. Companies (and employees) are adopting more and more agentic tools because they see how much more productive they can be with them. Do you see where this is going? More powerful LLMs for the attackers to use at scale, and more easy targets to pick on. I think the most vulnerable targets will be solopreneurs and small businesses who either:
Medium-sized businesses and Enterprise are not in danger that much (in my limited opinion), because they have the capital to invest into securing their IT infrastructure. Now, I don't know much about scamming people beyond what I see in viral YouTube videos when they expose scammers. What I do know is that you don't need to have the "Ultimate Unhackable Setup 4000", you just need to be difficult enough to reach that the attackers get discouraged and pick easier targets. "You don't have to outrun the bear to get away. You just have to be faster than the guy next to you." — Jim Butcher P.S: Help me send more relevant emails to you:
|
Sign up if you are overwhelmed with all these AI tools out there, and want a clear path as a non-technical business owner.
Hey Reader, Yesterday, I built a new website from almost scratch. Design, layout, copy, deployment. All in one day while also doing other things. No developer. No agency. No Webflow template. Just me and my Claude Code. I started off by having a wireframe I built last week in an hour, that was just about nailing the offer, the positioning and the copy. Here’s how that looked (it already used my brand font and colors): So, I opened Claude Code last morning and told it to: Read the wireframe’s...
Hey Reader, When I first found ChatGPT, I used it for things I was bad at. There was a 16 year old browser-based RPG that I was playing again, but some of the old extensions another player made didn't run in my browser. I didn't know how to program in that language, so I just copy-pasted the code and the error message I was getting to ChatGPT. This was GPT-3.5 in 2022 December. After days of copy-paste back and forth, I managed to get one extension going! Then I paused using it, because I...
Hey Reader, Entrepreneurs don't need more AI trainings and courses. You need help implementing AI into their business the right way. You are busy. You don't have the time to learn everything, and then figure out how to implement it. You want to take quick action and get AI running in your business right now. But you are not technical, so you can't integrate it. You are still stuck at prompting ChatGPT back and forth (with mixed or good results), and using all kinds of AI tools with fancy...