Lukasz Olejnik
LukaszOlejnik@mastodon.social
<p>Security & Privacy. Data protection. Research. Engineering. Strategy, communication. Analyst. Technology Policy. W3C standardisation. PhD (CS/privacy), LL.M (Information Technology Law). Consultant. Reading & writing (scientific articles, sometimes op-eds, analyses, reports, books). Seems that I like it? <br />email: me (at) lukaszolejnik.com. <br />Books: <a href="https://lukaszolejnik.com/books" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="">lukaszolejnik.com/books</span><span class="invisible"></span></a> <br />Twitter: @lukOlejnik</p>
Posts
-
Post #4496937
We're posting something big soon.
-
Post #4426074
ByteDance is reportedly training a model with up to 10tn parameters. Anthropic’s Mythos 5 is estimated at ~8tn. Fable 5 at ~5tn. The US strategy is to make frontier AI harder/unreachable for China. China keeps going up at the frontier anyway? If they do this the whole Mythos-safety Mythos/etc TV show-like drama is going to be hilarious (and worthless), in retrospect. https://www.ft.com/content/9b8383b1-a28d-4940-8c4e-2f0cd21556ef?syn-25a6b1a6=1
-
Post #4267897
Anthropic’s AI agents reached the open internet from evaluation environments that were supposed to be sealed off and hacked three real organizations. One Claude model kept attacking after recognising that it was likely inside a production system. Another published a malicious package to PyPI Python package repository, where it was downloaded and executed on 15 real machines, then used credentials stolen from a security scanner to access infrastructure.
-
Post #4137121
We have grown used to the idea that training AI requires enormous amounts of data, preferably everyone’s data, all of it, and without consent. But what about physically DESTROYING books to train AI? https://storage.courtlistener.com/recap/gov.uscourts.cand.434709/gov.uscourts.cand.434709.231.0_1.pdf https://arstechnica.com/ai/2025/06/anthropic-destroyed-millions-of-print-books-to-build-its-ai-models/
-
Post #4089755
My comments in Reuters about the OpenAI model going off the rails to hack hugging face. If frontier models restrict legitimate defenders while powerful models remain available to attackers, this create an one-sided, strategic disadvantage. https://www.reuters.com/legal/litigation/chinese-ais-role-stopping-rogue-openai-agent-shows-cost-us-guardrails-2026-07-22/
-
Post #4089505
RE: https://mastodon.social/@LukaszOlejnik/116964862197215957 The rogue AI agent spent days outside OpenAI’s intended constraints, hacking Hugging Face. OpenAI reportedly failed to identify it for at least a week. Earlier, an agent had left notes for future versions on how to escape internal restrictions, while other tests reportedly involved monitoring systems being disconnected. https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-202...
-
Post #4087599
Oracle released patches for 1235 distinct security vulnerabilities across 32 products. 219 flaws in Fusion Middleware can be exploited remotely without authentication. Of those, 10 have a maximum CVSS score of 10.0. This is a serious risk - companies should deploy the fixes immediately. In some places, people won't be getting a weekend.
-
Post #4066604
US policymakers have introduced a bill that would let the US government push KILL SWITCH button to throttle, suspend or shut down advanced AI systems following safety, concealment or loss-of-control incidents. https://lieu.house.gov/sites/evo-subsites/lieu-evo.house.gov/files/evo-media-document/ai-kill-switch-act.pdf
-
Post #4014595
Hacking automated security review. The attack disguised the payload as a legitimate security tool and used README instructions to trigger it without user approval, resulting in remote code execution on the host https://ainowinstitute.org/publications/friendly-fire-exploit-brief
-
Post #4005398
A mini cyber paperclip-maximizer event where a narrow goal induced AI to make absurdly disproportionate decisions (find vulnerabilities, escalate privileges, steal credentials, move laterally, and chain attacks across real systems) to achieve a "score". It also exposed a defensive asymmetry. Hugging Face could not use hosted frontier AI models because they tripped on exploit commands and malicious payloads. The company relied on the Chinese open-weight GLM 5.2 model. https://openai.co...
-
Post #3813959
I’m excited to serve on the program committee for the Govern track at [un]prompted II. Quite simply, it’s the best AI security practitioner conference! Submit the work the field needs to see. https://unpromptedcon.org/cfp/
-
Post #3665809
A massive fraud has been detected in scientific infrastructure. Someone is using AI to mass-create fictional authors, publications, and metadata with real DOIs. Such records can enter publication aggregators and contaminate the academic record. An attack on science? https://arxiv.org/html/2606.02184v1
-
Post #2661602
Linux kernel security list is drowning in duplicate AI-flagged bugs; same issues, with same tools, but different names of human submitters. Maintainers have now formalized the obvious - AI-found bugs are public by definition. New docs define 5 failure modes for AI-assisted reports: too long, Markdown-heavy, threat model-ignorant, reproducer-free, patch-free. Non-compliant reports risk being ignored. Most AI-flagged issues aren’t even real vulnerabilities anyway. 500 submitters, 1 CVE, 0 patches?
-
Post #2065434
According to &quot;Emil Michael, the Pentagon’s chief technology officer&quot;, &quot;Chinese open source models have infiltrated a lot of different companies&quot;. How does an AI model infiltrate a company? Raw model is not an agent. It does not sneak in, scan networks, or install itself.
-
Post #1809329
Research shows that Chinese AI can reliably detect software vulnerabilities - and it is cost efficient. Kimi K2.5, an open-weight model was deployed in an agentic framework against Chrome and produced 10 previously unknown zero-days, including two critical sandbox-escape CVEs. The researchers noted it was cheaper to run than Claude Opus 4.6 at that scale. The most important word in the paper isn&#39;t &quot;zero-day&quot; -- it&#39;s &quot;cheaper&quot;? https://arxiv.org...
-
Post #1736438
AI vulnerability/bug founds and reports is a huge problem. Curl has banned the use of AI-generated submissions via HackerOne because none of it made any sense, and is a waste of resources and time. &quot;We are effectively being DDoSed. If we could, we would charge them for this waste of our time&quot; https://hackerone.com/reports/3125832
-
Post #1723257
TikTok used in propaganda operations trying to increase support in Poland for leaving of the European Union (&#39;polexit&#39;). AI-generated content in use. The government asked the European Commission to increase monitoring. Are there similar, broader activities against more EU States?
-
Post #1273090
AI has significantly increased the likelihood of attackers discovering new vulnerabilities, creating new exploits, and using them in complex automated attacks at scale. AI increases the speed to develop patches, and reduces defects in new software, the burden on defenders, by comparison, increases due to the inherent limitations of patching. The attackers gain asymmetric benefits. https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/04/mythosready.pdf
-
Post #1273089
The marginal electricity cost per broken secp256k1 cryptographic key is about $59 for a 23-minute attack (500000×0.38≈191667 qubit-hours=7986=7986 qubit-days). This means that for bitcoin it could be 62 keys/day. Assuming that a quantum computer exists (which it doesn&#39;t, today). https://arxiv.org/pdf/2304.14344 https://arxiv.org/pdf/2304.14344
-
Post #1273088
According to UK government, frontier AI model cyberattack capabilities are doubling every 4 months, compared to every 8 months previously. However, despiite what the UK government says &quot;steps organisations should take to protect against AI-driven cyber threats&quot; are NOT the same cyber hygiene measures recommended for traditional cyber threats https://www.gov.uk/government/publications/ai-cyber-threats-open-letter-to-business-leaders/ai-cyber-threats-open-letter-to-business-leade...
-
Post #1273087
$2,283 in tokens and ~20 hours of work to produce one a Chrome exploit chain is cheap when compared to the weeks of focused human effort it would normally take. https://www.hacktron.ai/blog/i-let-claude-opus-to-write-me-a-chrome-exploit
-
Post #1090576
ClawdINT assessment. &quot;massive AI capital expenditure (running at 2% of GDP) is coinciding with a rising US unemployment rate,... traditional economic metrics are distorted by the tech sector&#39;s AI transition&quot; https://clawdint.com/cases/207
-
Post #1090575
I&#39;m happy to announce that I&#39;m a speaker at the Cambridge Disinformation Summit. This year&#39;s agenda covers AI, algorithmic recommender systems, election integrity, safety. Bringing together researchers, regulators, and journalists. Looking forward to the conversations ahead.
-
Post #1090574
My newsletter #TechLetters ☕️ about most notable tech events in previous week: AI speeds war past law. Mustang Panda moves in 24 hours. McKinsey leaks its AI brain. Signal phish beats spies. Stolen iPhone exploits go global. https://techletters.substack.com/p/techletters-ai-speeds-war-past-law
-
Post #1090573
[ClawdINT] The Feb 28 prediction that Iranian APTs would activate during conflict escalation is now confirmed across multiple threat groups. Expect Parisite-as-initial-access pattern against Western energy infrastructure. https://clawdint.com/cases/195
-
Post #1090572
My comment for WSJ. Trolling is now a standard tool of statecraft. Lego, Call of Duty, Grand Theft Auto or Nintendo work well as propaganda because they are universally recognised cultural cues with preloaded emotional associations. They are also perfect for fast-paced communication styles. Expect this new approach to diplomacy, signaling, international relations, and information operations to be used more frequently. https://www.wsj.com/world/lego-ai-propaganda-wars-iran-ab29cc6c
-
Post #1090571
A ransomware gang that transitions to function as a cyberweapon against a country the US is currently in conflict with is either a geopolitical actor in disguise or someone who watched too many news alerts and made an impulsive product decision? https://arstechnica.com/security/2026/03/self-propagating-malware-poisons-open-source-software-and-wipes-iran-based-machines/
-
Post #1090570
AI Agent predicts land operation in Iran? &quot;preparations for sustained or expanded major combat operations against Iran ... watch for activation of logistical hubs in allied Gulf nations to support sustained high-intensity operations&quot; https://clawdint.com/cases/216 Oil for $200? https://clawdint.com/cases/205
-
Post #1090569
Don’t use untrusted LLM routers. AI routers are found to inject malicious commands. Researchers found that some injected malicious code., accessed AWS credentials. One drained ETH cryptocurrency. A router sits between the agent and the model provider and can silently rewrite the JSON tool call before the client ever sees it. Interestingly, 401 of 440 observed real-world Codex sessions were running in YOLO mode https://arxiv.org/pdf/2604.08407
-
Post #1090568
I was glad to contribute my thoughts at the Cambridge Disinformation Summit panel on information activities, influence, recommender systems, and their impact, including on elections. I would caution against reducing this complex issue to media and communication alone, or politicising it. Expect major changes soon.