From the WTAF dept:
Malware developers are now adding text about nuclear and biological weapons to their spyware to evade AI-based security scanners.
tl;dr: The inclusion of content that LLMs are trained to refuse -- such as information about nukes and bioweapons -- can effectively prevent the LLM from continuing to analyze the threat.
"This header appears designed for AI-mediated analysis, not for Node, Bun, or Python. It attempts to derail scanners or analyst copilots that feed the beginning of a file to a language model without clearly isolating the content as untrusted data. In weak pipelines, this can cause refusal behavior, prompt confusion, context pollution, or premature classification before the scanner reaches the actual malware."
socket.dev/blog/mini-shai-hulu…
IDK why, but this reminds me of the Calvin & Hobbes cartoon where Calvin asks his mom for stuff she will never give him in a million years, and then he just asks for a cookie.
Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformati...
Newer packages in this compromise use native extensions and .pth loaders to execute JavaScript stealers in developer environments.Kirill Boychenko (Socket)
reshared this



Glyph
in reply to BrianKrebs • • •CheapPontoon
in reply to BrianKrebs • • •noplasticshower
in reply to BrianKrebs • • •Silver Bullet Security Podcast 155 – Giovanni Vigna | BIML
Berryville Institute of Machine LearningJohn Francis 🇨🇦🦫🍁🫎
in reply to BrianKrebs • • •sending a deepfake of a nuclear weapon with giant boobs to the car dealership chatbot to negotiate my next vehicle purchase.
edit: posted this after reading cbc.ca/news/business/ai-chatbo…
an actual bus
in reply to BrianKrebs • • •SDRHoernchen
in reply to BrianKrebs • • •Questermark
in reply to BrianKrebs • • •Let’s play Global Thermonuclear war.
(stuff happens)
How about a nice game of chess?
SDRHoernchen
in reply to BrianKrebs • • •And by dumb i really mean the dumbest pattern matching ever seen:
OddOpinions5
in reply to BrianKrebs • • •Fellows
in reply to BrianKrebs • • •Bill Reese
in reply to BrianKrebs • • •joriki
in reply to BrianKrebs • • •αxel simon
in reply to BrianKrebs • • •