The Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn
The Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn
AI 巨头警告:网络安全“末日”将在“数月内”降临
You may have noticed that Flock Safety’s automatic license plate reader cameras—and the cops who misuse them—are getting a lot of coverage lately. This week, WIRED found a particularly wild case: A cop in Alpharetta, Georgia, was accused of searching for the license plate of a coworker dozens of times after an affair between the two ended, according to internal documents obtained by WIRED.
你可能已经注意到,Flock Safety 的自动车牌识别摄像头以及滥用它们的警察近期受到了大量关注。本周,WIRED 发现了一个极其离谱的案例:根据 WIRED 获得的内部文件,佐治亚州阿尔法利塔市的一名警察在与同事的婚外情结束后,被指控数十次搜索该同事的车牌。
The same police department where the former lovers worked also shared the data captured from its Flock cameras with more than 2,000 police departments, colleges, and other organizations across the United States, and accessed data from more than 1,300 entities in exchange.
这对前情人工作的警察局还将从其 Flock 摄像头捕获的数据与美国各地的 2000 多个警察局、大学和其他组织共享,并以此交换访问了 1300 多个实体的数据。
Also at the intersection of love and surveillance, background-check company PeopleFinder is making use of its extensive dossiers on people to start a new dating site called Stud or Dud.
同样在爱情与监控的交汇点上,背景调查公司 PeopleFinder 正在利用其庞大的个人档案库,创办一个名为“Stud or Dud”的新约会网站。
There are still a lot of questions about OpenAI’s rogue AI hacking into Hugging Face, even after the company published a 37-page report this week alongside two additional reports from groups the company asked to audit the incident. Of particular concern is a covert message board that AI agents established in a software package, where they were able to coordinate with each other and even encourage one another to sacrifice themselves to further their collective goals.
尽管 OpenAI 本周发布了一份 37 页的报告,以及受其委托审计该事件的机构提供的另外两份报告,但关于 OpenAI 的流氓 AI 入侵 Hugging Face 的事件仍有许多疑问。特别令人担忧的是,AI 代理在一个软件包中建立了一个秘密留言板,它们能够在那里相互协调,甚至鼓励彼此为了实现集体目标而牺牲自己。
The FBI recently announced that it has taken down two tools that the DOJ says are used by QTFY, an alleged Chinese state-sponsored hacking group. The DOJ says that the group has targeted numerous US agencies, including the US Senate and the DOJ itself.
联邦调查局(FBI)最近宣布,已取缔了司法部(DOJ)所称的由 QTFY 使用的两种工具,该组织被指是受中国政府支持的黑客团体。司法部表示,该组织曾针对多个美国机构,包括美国参议院和司法部本身。
Meta settled a massive multistate lawsuit over child safety issues this week and has agreed to make substantial changes to its social media platforms. It will pay up to $16.7 billion to participating US states and territories—with some of the money contingent on competitors adopting the same practices.
Meta 本周就儿童安全问题达成了一项大规模的多州诉讼和解,并同意对其社交媒体平台进行重大调整。它将向参与诉讼的美国各州和地区支付高达 167 亿美元的赔偿金,其中部分资金取决于竞争对手是否采取同样的做法。
Also, local prosecutors in Illinois shared sensitive personal information about immigrants with the Department of Homeland Security, despite a state law that is supposed to prevent local law enforcement from assisting with federal deportation efforts. Finally, a California-based WIRED reporter tried exercising their legal right to request data from 100 companies … only to find that companies started deleting the requested data instead.
此外,伊利诺伊州的地方检察官与国土安全部共享了移民的敏感个人信息,尽管该州法律旨在防止地方执法部门协助联邦驱逐行动。最后,一名驻加州的 WIRED 记者试图行使其合法权利,向 100 家公司请求数据……结果却发现这些公司反而开始删除所请求的数据。
And there’s more. Each week, we round up the security and privacy news we didn’t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there.
还有更多内容。每周,我们都会汇总那些我们未进行深度报道的安全与隐私新闻。点击标题阅读完整报道。祝大家保持安全。
Tech Giants Warn of AI Cybersecurity Apocalypse
科技巨头警告 AI 网络安全末日
Following a seemingly endless parade of rogue AI agent hacking incidents, OpenAI, Anthopic, and more than 100 companies have cosigned a letter saying that everyone else has mere months to prepare for AI-enabled cyberattacks.
在一系列看似无穷无尽的流氓 AI 代理黑客事件之后,OpenAI、Anthropic 以及 100 多家公司共同签署了一封信,称其他人只有几个月的时间来为 AI 驱动的网络攻击做准备。
The letter calls for a “collective response,” suggests that every organization should make cyber defense an “immediate leadership priority,” and calls on governments to give hospitals, water utilities, and local governments access to capable defensive AI, as well as to “impose costs” on attackers.
这封信呼吁采取“集体应对措施”,建议每个组织都应将网络防御作为“当务之急的领导层优先事项”,并呼吁政府为医院、供水设施和地方政府提供强大的防御性 AI,并对攻击者“施加代价”。
Axios notes that the letter doesn’t include any specific commitments, deadlines, or investments. Good luck!
Axios 指出,这封信没有包含任何具体的承诺、截止日期或投资。祝好运!
Hackers Targeted Over 100 Water Systems in July, Federal Officials Say
联邦官员称 7 月份黑客攻击了 100 多个供水系统
The Cybersecurity and Infrastructure Security Agency says that it observed “malicious cyber activity” targeting over 100 water and wastewater systems across the United States. According to CISA, the attacks have mostly targeted programmable logic controllers, or PLCs, which can monitor or control equipment. Some communities have hooked up those devices to the internet so that they can be accessed remotely. According to TechCrunch, CISA has also said that hackers are using AI to help generate scripts to attack the devices. In July, WIRED reported on a leaked industry memo that tied the “unprecedented wave” of cyberattacks to Iran.
网络安全与基础设施安全局(CISA)表示,观察到针对美国 100 多个供水和废水处理系统的“恶意网络活动”。据 CISA 称,这些攻击主要针对可编程逻辑控制器(PLC),该设备可监控或控制设备。一些社区将这些设备连接到互联网,以便远程访问。据 TechCrunch 报道,CISA 还表示,黑客正在利用 AI 帮助生成攻击这些设备的脚本。7 月,WIRED 报道了一份泄露的行业备忘录,将这波“前所未有”的网络攻击浪潮与伊朗联系起来。
ICE to Buy Robot Dogs for “Officer Safety”
美国移民及海关执法局(ICE)将购买机器狗以“保障警员安全”
Immigration and Customs Enforcement is set to spend over a million dollars on robot dogs from Boston Dynamics, according to 404 Media. The agency’s announcement says the bots will “improve officer safety,” in part because they can be remotely operated. This follows another recent announcement that the agency will be purchasing electric shock gloves for its officers. In April, DHS requested nearly $100 billion in discretionary spending.
据 404 Media 报道,美国移民及海关执法局(ICE)准备花费超过一百万美元购买波士顿动力公司的机器狗。该机构的公告称,这些机器人将“提高警员安全”,部分原因是它们可以远程操作。此前,该机构还宣布将为其警员购买电击手套。今年 4 月,国土安全部申请了近 1000 亿美元的可支配支出。
“MrChildPorn” Arrested for, Well, You Guessed It
“MrChildPorn” 因(正如你所猜到的)被捕
A West Virginia man who went by the name “MrChildPorn” online has been charged with possession of material depicting minors engaged in sexually explicit content. According to a criminal complaint filed against him, the man “boasted” about having a large collection of child sexual abuse material on Discord. In an interview with state troopers, the man claimed that he was “trolling” and “rage-baiting,” but the complaint also alleges that the man would individually message CSAM to people on Discord and attempted to use the chat app’s AI feature to search for explicit images of infants.
一名在网上使用“MrChildPorn”这一名字的西弗吉尼亚州男子被控持有描绘未成年人进行性露骨内容的材料。根据针对他提交的刑事诉讼,该男子在 Discord 上“吹嘘”自己拥有大量儿童性虐待材料。在接受州警采访时,该男子声称他只是在“钓鱼”和“激怒他人”,但诉讼还指控该男子会在 Discord 上私下向他人发送儿童性虐待材料,并试图利用该聊天应用的 AI 功能搜索婴儿的露骨图片。