@GossiTheDog@cyberplace.social
Post #4204403
2026-07-29 16:16 UTC
Replies (22)
-
@Xavier@infosec.exchange 2026-07-29 16:19
@GossiTheDog@cyberplace.social None that's I'm involved with, but I moved out of IR and back into engineering. All the incidents I'm brought into and nothing to do with real AI threats. However, most of the busy work I have during the day are all caused by stupid humans responding to the perceived AI threat.
-
@blair@infosec.exchange 2026-07-29 16:28
@GossiTheDog@cyberplace.social Have not had any incidents run by AI, nor has anyone in my industry groups.
-
@mr@infosec.exchange 2026-07-29 16:32
@GossiTheDog@cyberplace.social phishing emails aren’t even better. Very disappointing. Was waiting for quantum AI web3 mega vulns and it’s still just emails, insider theft and Fortinet leaving the front door open. I guess the upside is the reports are 10 times more verbose and excruciating to read.
-
@badsamurai@infosec.exchange 2026-07-29 16:32
@GossiTheDog@cyberplace.social Nope.
-
@dank@jorts.horse 2026-07-29 16:21
@GossiTheDog@cyberplace.social personally: nope el reg recently talked about it, too analyzed 1,061 publicly attributed AI-assisted vulnerability discoveries from Anthropic's Project Glasswing & the Berkeley Vulnerability Research Initiative, then cross-referenced them against its Known Exploited Vulnerability database. The result: just 14, or 1.3 percent, have been confirmed as exploited in the wild, almost identical to the rate across all vulnerabilities in VulnCheck's dataset. https://www.theregister.com/security/2026/07/28/ai-found-bugs-arent-proving-any-easier-to-exploit-despite-the-hype/5279637
-
@faebudo@ioc.exchange 2026-07-29 17:13
@GossiTheDog@cyberplace.social I see a lot where the cause of the incident is the uncontrolled usage of GenAI. Not where GenAI is the adversary or used by the adversary.
-
@TindrasGrove@infosec.exchange 2026-07-29 17:38
@GossiTheDog@cyberplace.social I’m not hearing any such chatter in the insurance claims side. Mostly just social engineering getting easier to do at scale.
-
@maswan@mastodon.acc.sunet.se 2026-07-29 17:41
@GossiTheDog@cyberplace.social Only thing I'm seeing that is horrible is the DDoSes from AI crawlers leading to service outages, some of which I have to mitigate, and some where I'm a legit user of the service.
-
@w00p@infosec.exchange 2026-07-29 18:40
@GossiTheDog@cyberplace.social Nothing like this yet.
-
@RecklessPush38671@infosec.exchange 2026-07-29 19:11
@GossiTheDog@cyberplace.social I've definitely seen plenty of vibe-coded malware out in the wild. The well documented code sprinkled with emojis is a dead giveaway. I usually see it in scripts but that's mostly because scripts are plaintext. I could very well have run across compiled malware that was vibe coded and not even realized it. (If you can stomach the bad site, VX-Underground is often picking apart vibe-coded malware from out in the wild.) There's also been campaigns that I've suspected have an AI-generated component but don't have enough visibility into the attacker's operations to say for sure. Tampered Chef was maybe a good example of a threat I've come across that I suspected to have AI-generated content.
-
@thief_of_fire@infosec.exchange 2026-07-29 19:44
@GossiTheDog@cyberplace.social I see a lot of obviously llm-generated phish kits that leverage llms to rebuild unique-enough pages to bypass signature-based frequently. And a lot more of them.
-
@Spartan_1986@infosec.exchange 2026-07-29 20:34
@GossiTheDog@cyberplace.social Nope. That standard stuff works just fine. Hardest hit we’ve had in a while was pure social engineering of the user and help desk (I’m sad to say.) They just call…
-
@ADHDruid@infosec.exchange 2026-07-29 20:28
@GossiTheDog@cyberplace.social Zero.
-
@drsbaitso@infosec.exchange 2026-07-29 21:23
@GossiTheDog@cyberplace.social Infra-ops with close ties to our cybersec teams, and the closest we've had is people trying to use AI output to replace "paying attention to things" and "the kinds of skills we actually hire people for" causing minor-to-moderate outages.
-
@pmelon@infosec.exchange 2026-07-29 21:28
@GossiTheDog@cyberplace.social Nope. Just people using Codex and Claude to do things they don’t really understand in really stupid ways. Nothing malicious yet. Lots of noise generated by a subset of users, easily tuned out. Management are high on AI so we have no policy facilitating any blocking of said stupidity.
-
@Sempf@infosec.exchange 2026-07-29 21:39
@GossiTheDog@cyberplace.social I wrote a tool that generates a sentiment analysis of attacks likely from AI-built fuzzing lists and a number of them really do look AI generated.
-
@tobraha@infosec.exchange 2026-07-29 16:20
@GossiTheDog@cyberplace.social I am not. I would even say that the phishing emails have hardly gotten better in my experience 🤷♂️
-
@Crazypedia@mypocketpals.online 2026-07-29 16:21
@GossiTheDog@cyberplace.social what i am seeing is more compromised business servers sending me better crafted phishing emails, and a sharp rise in reported phone scams with little other data to tell if it's people or robots on the other end yet. We've also taken a hard limited allowance to letting our employees play with copilot or other LLMs at work, and there is already a general distrust that we(it dept) are encouraging; which is to say we're not expecting to see many people reporting that ai ate their inbox or strange supply chain package attaks. but no, not seeing thing unstoppable ai attacks in our network yet.
-
@Ratanasec@infosec.exchange 2026-07-29 22:04
@GossiTheDog@cyberplace.social Short of just slightly better phishing no we haven't seen a major uptick in AI driven attacks (15k user environment) All the standard cybersecurity 101 attacks still persist.
-
@Sikorsky78@infosec.exchange 2026-07-29 22:11
@GossiTheDog@cyberplace.social had one just this month, currently working on a write-up, ping me if you want to get some deets.
-
@jsmall@infosec.exchange 2026-07-29 22:53
@GossiTheDog@cyberplace.social All I see is an very typical phishing email and someone will say "good English, so must have had AI assistance writing" and suddenly it's an AI attack.
-
@pobice@infosec.exchange 2026-07-30 07:16
@GossiTheDog@cyberplace.social Seen some AI generated videos and possibly content to make phishing websites seem more legit but that's about it