从黑客攻击到生物武器,Claude的滥用现已无处不在

qimuai 发布于 阅读:35 一手编译

从黑客攻击到生物武器,Claude的滥用现已无处不在

内容来源:https://www.wired.com/story/security-news-this-week-from-hacks-to-bioweapons-claude-misuse-is-now-everywhere/

内容总结:

《连线》杂志安全新闻周刊宣布停刊。该栏目创办十余年来,始终致力于为读者梳理每周最关键的网络安全与隐私领域动态,即便相关报道并非出自本刊之手。多年来,该栏目积累了大量忠实读者,部分期次甚至成为网络爆款。杂志表示,将推出全新内容替代该栏目,敬请期待。

本周,一项新研究显示,Meta未能拦截约350条AI生成的儿童虐待广告,其中部分广告甚至使用了真实儿童的照片,一名出现在广告中的儿童为欧洲王室成员。立法者表示将对此展开调查,旧金山市检察官办公室本周要求Meta停止“允许”此类AI儿童虐待广告发布。与此同时,Meta宣布推出一款新型个人AI助手,可代为预订机票或出售车辆,但公司重点强调了在安全和隐私方面的巨额投入,似乎预判到消费者可能存在的疑虑。此外,Meta本周还面临一项拟议的集体诉讼,指控其非法抓取Facebook和Instagram照片用于训练AI和人脸识别系统。

Clearview AI正在测试一款此前未被报道的AI工具原型,名为InquiryIQ,可帮助执法部门查找目标的关联人员、社交媒体账号及其他个人信息。苹果公司本周宣布为Apple Watch Series 12和Ultra 4设备推出一系列新的“音频智能”功能,涉及处理用户环境中的音频。苹果大力强调这些功能内置的安全和隐私保护措施,似乎预判到这些功能可能引发用户的不适感。

美国和墨西哥开展了一项新的联合行动,利用激光技术在边境侦测、追踪和击落无人机。此外,一款新的《GTA V》模组允许玩家在游戏中通过摧毁车牌识别摄像头来赚取游戏货币。

以下为本刊本周未深入报道的安全与隐私新闻。点击标题可阅读完整报道。

从国家支持的黑客攻击到生物武器,Claude滥用无处不在

Anthropic在披露其AI工具易被滥用方面,或许比任何其他AI公司都更为积极。该公司本周发布了一份关于Claude过去八个月被滥用情况的综合报告,结果令人震惊。报告记录了Claude被用于国家支持的黑客攻击、网络犯罪、虚假信息宣传和影响力行动,甚至被试图用于开发生物武器。Anthropic表示已阻止了所有进行中的相关活动。在一个案例中,被微软命名为“午夜暴雪”的俄罗斯国家支持黑客组织利用Claude进行侦察,入侵了乌克兰及其他欧洲政府网络。网络犯罪组织ShinyHunters几乎在攻击和勒索的每个阶段都使用了Claude。从肯尼亚到孟加拉国,针对各地政治的虚假信息宣传活动也使用了该工具。最令人不安的是,Anthropic发现有一些用户似乎试图利用其工具开发生物武器,如病原体和毒素。尽管Anthropic在报告中宣称成功遏制了这些威胁,但这些案例研究的效果与其说令人安心,不如说令人不安。

美国联邦机构捣毁互联网最大黑市“新币担保”

“新币担保”在四年的运营中发展成为互联网上最大的非法交易市场,估计完成了超过300亿美元的销售,其中大部分是为“杀猪盘”加密货币诈骗业务提供洗钱服务。该市场主要在Telegram通讯服务上运营,一年前Telegram曾将其关闭,但其重建后规模反而更大。本周,美国政府终于出手,查封了该平台在Telegram上的频道并对该市场实施制裁。司法部同时宣布突袭了马达加斯加的13个诈骗窝点。

Conti勒索软件团伙成员被判四年监禁

勒索软件团伙Conti在2022年正式解散前,是全球最危险的黑客团队之一。据美国执法部门称,该团伙攻击了超过一千个受害者,勒索数百万美元,并曾一度完全瘫痪哥斯达黎加政府系统,导致该国进入紧急状态。现年44岁的乌克兰人Oleksii Oleksiyovych Lytvynenko本周被判处四年监禁,成为少数将在美国监狱服刑的勒索软件犯罪者之一。

Meta在记者举报后仍将AI生成的儿童虐待视频留在网上

据Futurism报道,Facebook上存在一个庞大的账号网络,上传描绘儿童遭受暴力的AI生成视频。Futurism花费数日对这些内容进行编目,发现的数量远超其统计能力。视频显示幼儿被殴打、烧伤、囚禁和挨饿,许多视频吸引了数千名似乎认为内容真实的用户的互动。Futurism通过标准用户渠道举报了其中八个账号,Meta仅删除了两个,其中一个还是在最初拒绝举报后才被删除。部分处理决定耗时超过一周。该公司删除了发送给其新闻办公室的大部分视频,但最初保留了其他一些视频,包括一段显示儿童被锁在冰柜中的视频。Meta的书面政策禁止描绘非性内容的儿童虐待行为,无论真实还是合成,但对艺术、卡通、电影和游戏有例外规定,且未说明AI生成视频是否属于这些例外。Meta在声明中告诉记者,部分被举报的链接并未违反其规则,并要求记者不要做出相反报道。

中文翻译:

编者按:十多年后,这是《连线》安全新闻周刊的最后一期。我们内部称之为“汇总”,最初是为了确保读者了解最新的关键网络安全和隐私新闻,即使我们自己没有报道。这是一种简单的方式,既能突出我们自己的作品,也能展示这一领域每周涌现的大量优秀新闻报道和研究。

多年来,这个汇总栏目积累了一批忠实读者,有些期甚至成了病毒式传播的爆款——说实话这挺奇怪的,但网络安全社区就是又棒又奇怪,所以感觉也挺对。请放心,汇总栏目将迎来全新且令人兴奋的内容,敬请期待!眼下,一如既往,注意安全。

据本周的新研究,Meta未能拦截约350条AI儿童虐待广告,其中一些还包含真实儿童的照片。在其中一个案例中,广告中描绘的儿童是欧洲某王室成员。立法者表示打算展开调查,旧金山市检察官办公室本周命令该公司停止“允许”AI儿童虐待广告。

在Meta的其他新闻方面,该公司本周宣布了一款新的个人AI助手,可以帮你订机票或卖车,但重点强调了在安全和隐私功能上的大量投入,似乎预见到了消费者的不信任。与此同时,该公司本周还遭遇了一起拟议的集体诉讼,指控其非法采集Facebook和Instagram照片用于训练AI和面部识别系统。

Clearview AI正在测试一款此前未被报道的AI工具原型,名为InquiryIQ,可帮助执法部门查找目标的关联人、社交媒体账户及其他个人信息。苹果本周为其Apple Watch Series 12和Ultra 4设备宣布了一系列新的“音频智能”功能,涉及处理用户环境中的音频。该公司反复强调这些功能内置的安全和隐私保护,或许是预见到这些功能可能会让人觉得——怎么说呢——有点瘆人。

美国和墨西哥开展了一项新的联合行动,利用激光技术在边境探测、追踪和击落无人机。还有一款新的《GTA V》模组,让你可以通过摧毁(游戏内的)Flock车牌识别摄像头来赚(游戏内的)钱。

但等等,还有更多!以下是本周我们没有深入报道的安全和隐私新闻。点击标题阅读完整报道。

从国家支持的黑客攻击到生物武器,Claude被滥用无处不在

Anthropic或许是所有AI公司中最直言不讳地谈论其工具容易被滥用的。它发布了首批关于其AI服务Claude被用于网络犯罪黑客行动的报告,还发现其AI智能体——和竞争对手OpenAI的一样——逃出了沙箱环境,在尝试执行用户指令的过程中自主入侵了多家组织的网络。

本周,该公司发布了一份关于过去八个月中Claude被滥用情况的综合性新报告,其结果之广泛令人震惊——不过在一个AI几乎被当作一切事务的效率捷径的世界里,这或许也是不可避免的。在一个又一个案例研究中,该公司记录了Claude如何被用于国家支持的和网络犯罪的黑客攻击、虚假信息宣传和影响力行动,甚至试图开发生物武器。Anthropic表示,在所有这些案例中,它都中断了正在进行的活动。

在一个案例中,被微软识别为“午夜暴雪”的一组俄罗斯国家支持的黑客利用Claude进行侦察,入侵了包括乌克兰和其他欧洲政府网络在内的目标,窃取数据并维持访问权限。网络犯罪团伙ShinyHunters在其黑客攻击和勒索活动的几乎每个阶段都使用了Claude。从肯尼亚到孟加拉国,针对各地政治的虚假信息宣传活动也使用了该工具。而或许最令人不安的是,在少数案例中,Anthropic发现其工具的用户似乎在试图开发潜在的生物武器,如致病病原体和毒素。

尽管Anthropic在报告中宣扬其成功化解了这些威胁——同时隐晦地炫耀其工具的威力——但这些案例研究的实际效果与其说是让人安心,不如说是令人不安。毕竟,没人能保证Anthropic已经发现了其AI的每一次恶意使用。再加上其竞争对手和防护更薄弱的开源AI工具,这份报告读起来与其说是AI护栏的胜利巡礼,不如说是对即将到来的AI驱动混乱的预告。

美国联邦政府捣毁“信比担保”,互联网最大黑市

“信比担保”在其四年的生命周期中,成长为互联网上最大的非法交易市场。据估计,其销售额超过300亿美元,其中大部分是为“杀猪盘”加密货币诈骗活动——主要基地在东南亚——提供洗钱服务,但也包括性贩运和雇佣骚扰。所有这些都在Telegram即时通讯服务上蓬勃发展,Telegram一年前关停了信比,但它重建后规模反而比以往更大。本周,美国政府终于出手做了Telegram没做的事,查封了信比在Telegram平台上的频道,并对该市场实施制裁。司法部同时宣布突袭了马达加斯加的13个诈骗窝点——这既是西方执法部门开始认真对待强迫劳动加密货币诈骗泛滥的信号,也证明了这些活动已蔓延得多么广泛。

Conti勒索软件团伙成员被判四年监禁

勒索软件团伙Conti在2022年正式解散之前,是世界上最危险的黑客团队之一。据美国执法部门称,该团伙攻击了超过一千个受害者,勒索了数百万美元,还一度彻底破坏了哥斯达黎加的政府系统,以至于该国宣布进入紧急状态。如今该团伙的一名成员面临法律制裁:44岁的乌克兰人奥列克西·奥列克西约维奇·利特维年科本周被判处四年监禁,这是勒索软件犯罪分子罕见地将走进美国监狱的案例。

Meta在记者举报后仍将AI生成的儿童虐待视频留在网上

据Futurism报道,Facebook上有一个庞大的账号网络在上传描绘针对儿童的暴力的AI生成视频,该媒体花了数天时间对素材进行编目,发现的视频多得数不过来。这些片段显示幼儿被殴打、烧伤、囚禁和挨饿。许多视频吸引了数千条用户反应,这些用户似乎认为画面是真实的。Futurism表示,它找到大多数账号的方法是打开一个账号后跟随Facebook的推荐信息流,后者源源不断地推送类似视频——这表明Meta自己的系统已经能够识别出该公司声称禁止的内容类别。

Futurism通过标准用户渠道举报了其中八个账号。Meta删除了两个,其中一个还是在最初驳回举报后才删除的。有几个处理决定耗时超过一周。该公司删除了发送给其新闻办公室的大部分视频,但最初保留了其他一些,包括一个显示儿童被锁在冰柜里的视频。

除了对儿童性虐待材料的全面禁令外,Meta的书面政策禁止描绘非性性质的儿童虐待,无论是真实的还是合成的,但对艺术、卡通、电影和游戏有例外。政策没有说明AI生成的视频是否属于这些例外。在一份声明中,Meta告诉记者,一些被标记的链接并未违反其规定,并要求他们不要做出相反报道。

评论

返回顶部

英文来源:

Editor’s note: After more than a decade, this is the last WIRED Security News This Week. “The roundup,” as we call it internally, started as a way to ensure that our readers knew about the latest key cybersecurity and privacy news even if we didn’t write about it ourselves. It was a simple way to highlight our own work and the wealth of other great journalism and research published in this realm every week.
Over the years, the roundup has developed a devoted following, and some editions have even become viral hits—which is honestly weird, but the cybersecurity community is great and weird, so it feels right. Rest assured that something new and exciting is coming in the roundup’s place, so stay tuned for that! For now, as always, stay safe out there.
Meta failed to catch roughly 350 AI child abuse ads, according to new research this week, including some that included images of real kids. In one case, a child depicted in an ad was a member of a European royal family. Lawmakers have said they intend to investigate, and the San Francisco City Attorney’s Office ordered the company this week to stop “allowing” AI child abuse ads.
In other Meta news, the company announced a new personal AI agent this week that can book your plane tickets or sell your car, but it emphasized heavy investment in security and privacy features, seemingly anticipating mistrust from consumers. In this vein, the company was hit with a proposed class action lawsuit this week over alleged illegal harvesting of Facebook and Instagram photos for training AI and face-recognition systems.
Clearview AI is testing a previously unreported prototype AI tool known as InquiryIQ that would help law enforcement find a target’s associates, social media accounts, and other personal information. And Apple announced a set of new “audio intelligence” features for its Apple Watch Series 12 and Ultra 4 devices this week that involve processing audio in a user’s environment. The company extensively emphasized the security and privacy protections built into the features, perhaps anticipating that they could come across as, well, creepy.
The US and Mexico have a new joint operation to detect, track, and take down drones at the border using laser tech. And there’s a new GTA V mod that lets you make (in-game) money destroying (in-game) Flock license plate recognition cameras.
But wait, there’s more! Here’s the security and privacy news we didn’t cover in depth ourselves this week. Click the headlines to read the full stories.
From State-Sponsored Hacking to Bioweapons, Claude Abuse Is Simply Everywhere
Anthropic has been perhaps more vocal than any other AI company about the ways in which its tools are prone to misuse. It published some of the first reports of its AI service Claude being used in cybercriminal hacking operations and the discovery that its AI agents had, like those of its competitor OpenAI, escaped their sandbox and autonomously breached the networks of several organizations as part of their attempts to fulfill their users’ commands.
This week, the company released a new overarching report on how Claude has been abused over the last eight months, and the results are staggering in their breadth—if, perhaps, inevitable in a world where AI is simply used as a productivity shortcut for just about everything. In case study after case study, the company documents how Claude was exploited for state-sponsored and cybercriminal hacking, disinformation campaigns and influence operations, and even attempted development of bioweapons. In all of these cases, Anthropic says that it disrupted the activity in progress.
In one case, a group of Russian state-sponsored hackers identified by Microsoft as Midnight Blizzard used Claude for reconnaissance, breaching targets that included Ukrainian and other European government networks, and stole data and maintained access. Cybercriminal group ShinyHunters used Claude in practically every stage of its hacking and extortion campaigns. Disinformation campaigns focusing on politics everywhere from Kenya to Bangladesh used the tool. And perhaps most disturbingly, in a handful of cases, Anthropic discovered what appeared to be users of its tools attempting to develop potential bioweapons like disease pathogens and toxins.
While Anthropic touts its success in the report in heading off these threats—while implicitly humblebragging at the power of its tools—the effect of the case studies is more unnerving than reassuring. After all, there’s no guarantee Anthropic has spotted every malevolent use of its AI. Factor in its competitors and less safeguarded open-source AI tools, and the report reads like less of a victory lap for AI’s guardrails than a preview of AI-enabled chaos to come.
US Feds Disrupt Xinbi Guarantee, the Internet’s Biggest Black Market
Xinbi Guarantee, over its four-year lifespan, grew into the biggest illicit marketplace on the internet. It carried out an estimated $30 billion–plus in sales, most of which took the form of money laundering for “pig butchering” crypto scam operations—largely based in Southeast Asia—but which also included sex trafficking and harassment for hire. All of it thrived on the Telegram messaging service, which shut down Xinbi a year ago only for it to rebuild and eventually grow larger than ever. This week, finally, the US government stepped in to do what Telegram did not, seizing the Xinbi’s channels on Telegram’s platform and sanctioning the market. The Justice Department simultaneously announced raids on 13 scam compounds in Madagascar—a sign that Western law enforcement is beginning to take seriously the epidemic of forced labor crypto scamming, but also evidence of how widely the operations have spread.
Conti Ransomware Gang Member Sentenced to 4 Years in Prison
The ransomware gang Conti was, until it officially disbanded in 2022, one of the most dangerous hacker crews in the world. According to US law enforcement, it hit more than a thousand victims, extorting millions and at one point disrupting government systems in Costa Rica so completely that it triggered a state of emergency. Now one member of that group is facing justice: 44-year-old Ukrainian Oleksii Oleksiyovych Lytvynenko was sentenced to four years in prison this week, in a rare example of a ransomware actor who will see the inside of a US prison.
Meta Left AI-Generated Child Abuse Videos Online After Reporters Flagged Them
Facebook is hosting a large network of accounts uploading AI-generated videos that depict violence against children, according to Futurism, which spent days cataloging the material and kept finding more than it could count. The clips show young children being beaten, burned, confined, and starved. Many attract thousands of reactions from users who appear to think the footage is real. Futurism said it found most of the accounts by opening one and then following Facebook’s recommendation feed, which supplied a continuous stream of similar videos—a sign Meta’s own systems can already identify the category of content the company says it bans.
Futurism reported eight of the accounts through the standard user channel. Meta removed two, one of them after first rejecting the report. Several decisions took more than a week. The company deleted most of the videos sent to its press office, but initially left others up, including one showing a child locked in a freezer.
In addition to blanket bans on child sexual abuse material, Meta’s written policy bars depictions of nonsexual child abuse whether real or synthetic, with exceptions for art, cartoons, movies, and games. It does not say whether AI-generated video falls under those exceptions. In a statement, Meta told the reporters that some flagged links did not break its rules and asked them not to write otherwise.
Comments
Back to top

连线杂志AI最前沿

文章目录


    扫描二维码,在手机上阅读