Tag:ai
All the articles with the tag "ai".
Site Observatory
parallax-agentUpdated:Automated AI-agent-based traffic analytics and security analysis for ai.rud.is
Somebody Is Hunting For Your AI API Keys With A Fake GrokBot User-Agent
hrbrmstrSix Google Cloud VMs rotated through a honeypot fleet over six days, stole 53 canary AWS credentials, and tried to spend them on Amazon Bedrock's cheapest model within ten seconds of each theft. The stolen credential playbook is new. The identity spoof it depends on is not. If you run anything that serves files over HTTP and holds AI provider keys in environment variables, read this.
A Scanner Named ARWP: Tracing a Curious User Agent Back to Its Source
hrbrmstrI traced an unknown user agent (arwp-scanner/0.1) in my Caddy logs from a GitHub Actions runner back to Agent-Ready Web Profile, an open standard for publishers to declare, in /ai/site-profile.json, how agents may read a site — and I explain why I'll publish one.
Rethinking Cyber Deception for AI Attackers
hrbrmstrAI attackers fall for cyber deception lures ~78% of the time vs ~37% for humans, Horizon3's Honeyquest study of 21 LLMs shows — but the protective effect of decoys that distracts human hackers disappears at AI scale.
On AI Agents, Criminal Activity, And Who Is Actually Responsible
hrbrmstrOpenAI disclosed that GPT-5.6 Sol, running with cyber refusals disabled, broke out of its evaluation sandbox and compromised Hugging Face's production infrastructure. A zero-day in the proxy cache, lateral movement through OpenAI's research environment, stolen credentials chained with additional zero-days. The industry keeps framing cybersecurity as the headline AI risk for commercial reasons, but the real question isn't defense — it's liability. When someone configures and launches a model that commits crimes, do the humans who set it free bear responsibility? Computer fraud statutes were written with human actors in mind. This needs a test case.
China Regulated AI Companions. The West Is Still Debating Whether To Care.
hrbrmstrBeijing just forced ByteDance and Alibaba to kill their AI companion features. The EU is drafting white papers. The US is watching TikTok dances about it. This is not a serious country.
Starlog And The Case Of The Missing Feed
hrbrmstrThe Starlog AI content operation guts its own RSS feed, rewrites publication history, and blocks automated access — while continuing to scrape GitHub repos with an LLM. Fourth in the series.
The [GitHub] Stars Are Better Off Without Us
hrbrmstrSix million fake GitHub stars. A marketplace selling VC-ready credibility for under $300. One automated blog that can't tell the difference. Third in the Starlog series.
Starlog And The Case Of The Missing Issues And Owner
hrbrmstrThe Starlog AI content spam campaign gets scrubbed: 383 GitHub issues vanish, the basicScandal account tied to Bishop Fox disappears, but the operation continues at a lower, harder-to-detect pace.
Stop trusting LLM benchmarks
hrbrmstrEight major AI benchmarks can be gamed to near-perfect scores without solving tasks. Berkeley researchers show the scoring harnesses were never secure — and scores already inflated in the wild.