Elektrine lite

← Feed

@c0coChannel@infosec.exchange

Post #3868081

2026-07-16 20:46 UTC

The thing about offensive LLMs is that from a defender's perspective, there's only one significant change. Inbound attacks against servers, web apps etc will still look the same whether they're done manually, by some burpsuite script, or by some contrived predictive text 'agent'. The one thing that changes is malware/post-compromise exploitation - and the detection thereof- not because it's empowered by LLMs (although they probably help write it a lot now), but rather because the presence of agents (or MCP servers) on endpoints themselves represent a whole new attack surface with its own problems, not least of all an entirely new shape of False Positives (i.e. 'legitimate' patterns that Claude et al probabilistically use for common tasks that just so happen to resemble 'classical' IoCs.

Replies (1)

  • The shock and horror threats and hype that we heard about for the last few years were all - from the very start - *obviously* trash because of exactly this. The risk isn't attackers using LLMs to make "more convincing phishing" but rather *giving LLMs to our own users* to fuck everything up with

    Open ##3868132