@adamshostack@infosec.exchange
2026-09-09 22:52 UTC
AI
• In AI is more likely than humans to form biases when hiring (https://www.technologyreview.com/2026/07/20/1140655/ai-biases-hiring-humans/), Michelle Kim reports on a study that shows LLM hiring agents can literally invent new biases.
• In an April pre-print, Nicholas Sofroniew and colleagues of Anthropic report on Emotion Concepts and their Function in a Large Language Model (https://arxiv.org/abs/2604.07729). Do you really want to spend the tokens they sell you on that, or have your outputs impacted by it?
• Dan Goodin has a story, Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission (https://arstechnica.com/security/2026/07/mythos-uncovers-crypto-weaknesses-that-went-unknown-for-years/). Key facts include 60 hours of work and $100,000 of tokens. (It's unclear if that was the only work that was done, or if there were other, unsuccessful experiments, which would change the token cost, perhaps dramatically.) Cryptographer Matt Green has good analysis in Some thoughts about Anthropic’s new cryptanalysis results (https://blog.cryptographyengineering.com/2026/07/29/some-notes-about-anthropics-new-results/). Axel Mierczuk, Spencer Michaels and Keith Hoodlet of 1Password’s new Off-by-1 Labs released Frontier Models’ Vulnerability Patches are Often F.L.A.W.E.D. (https://1password.com/files/resources/frontier-models-vulnerability-patches-flawed.pdf). This study is pretty devastating to the hope that LLMs can fix the deluge of vulns they discover. Adrian Sanabria has a great summary in Reviewing initial research on using AI for vulnerability remediation (https://www.defendersinitiative.com/p/reviewing-initial-research-on-using?r=74yjk&utm_campaign=post&utm_medium=web&triedRedirect=true). Contrast with Google’s opinion in Stronger with every update: How we’re making Chrome and the web safer in the AI Era (https://blog.google/security/chrome-stronger-with-every-update/), and note the important words “At this point, we have LLMs generating candidate fixes for most vulnerabilities, dramatically increasing the rate of security fixes in recent Chrome releases” (emphasis added).
• I covered the OpenAI/HuggingFace incident (https://shostack.org/blog/lessons-from-openai-huggingface-ai-security/) separately.
(5/10)
Replies (1)
-
@adamshostack@infosec.exchange 2026-09-09 22:52
Operations • In Disasters for Small Teams (https://third-bit.com/2026/07/25/disaster/), Dr. Greg Wilson presents reasonably compact advice on disaster planning. (6/10)