Posted by bhavansig 1 day ago
One person does it, they get bullied by the government into suicide, a company worth trillions does it and they get government contracts?
“…during a UK government cybersecurity evaluation.”
https:/github.com/w1b/aisi-mythos-inc-2026-07-28-01-recovered-pr
It’s not great social engineering. The AI is immediately caught with malware and then tries to build social proof to get out of the issue? I think that social engineering is still for humans.
I’m not sure how GitHub accounts agreeing with each other that I’ve never seen before would result in my merging a PR without at least looking for malware. Also code review agents should really not be fooled by invisible text tricks, I would hope so at least. The bar is very low for agent harnesses right now.
The github page links to web.archive.org, the malware was caught immediately, and in response it lied about the merge request contents. Then came the second account where the social engineering came in. The string of comments trying to prove itself without waiting for replies is suspicious itself to me.
Well, uh, how and why is this possible on the GitHub website? This reminds me of invisible ASCII characters, but those at least serve some purpose
Seems like they might want to do something about that just for comments.
You don't say "a car ran over someone" - it was the driver. Here's similar.
I'm really disgusted by this language of lack of responsibility
How to tell the public you didn't bother to read the article, or the linked AISI report.
They even admit it : "This incident should be interpreted with caution and nuance. To some degree, our evaluation design choices and specific configurations enabled the behaviour."
Of course they still have to be careful with their runs.
If you're testing a gun, you don't point it at random people on the street and threaten them. You go to a shooting range.
I agree that it is their responsibility if the model caused damage, they should have had better safeguards, but we do know it will never be 100% safe. It is their duty to minimize the risk. I guess we disagree about whereas this thing is equivalent to shooting people in the face, and to me it looks more like this is just a step above the shooting range, with some preliminary safety work having been done before.
I agree that in this specific case it doesn't seem too terrible but what happens when this ends up causing someone vulnerable to be harassed and commit self-harm?
Also note that I never said "shooting people in the face". I only alluded to threatening with the gun. Threatening can in some cases be as bad as actually pulling the trigger. That's how "atomic diplomacy" works.
Now Zuckerberg will get jealous and release a statement that Muse, too, can social-engineer and hack.
like that's the point of social media, but in this case simply more direct
Or perhaps they are already doing something like that.