https://berryvilleiml.com/2025/11/14/houston-we-have-a-problem-anthropic-rides-an-artificial-wave/ [bball_site] * BLOG * TEAM * RESULTS * BIBLIOGRAPHY * SEARCH MLSEC Musings * 14 November 2025 Houston, we have a problem: Anthropic Rides an Artificial Wave * 08 October 2025 BIML granted official non-profit status * 22 September 2025 BIML in Brazil: mind the sec keynote * 18 September 2025 BIML in Sao Paulo * 16 July 2025 BIML Introduction Video BIML Results * 24 January 2024 Architectural Risk Analysis of Large Language Models * 20 January 2020 Architectural Risk Analysis of Machine Learning Systems * * 15 May 2019 Deep Learning Attack Taxonomy Houston, we have a problem: Anthropic Rides an Artificial Wave 14 November 2025 gem I'll tip my hat to the new Constitution Take a bow for the new revolution Smile and grin at the change all around Pick up my guitar and play Just like yesterday Then I'll get on my knees and pray We don't get fooled again Out there in the smoking rubble of the fourth estate, it is hard enough to cover cyber cyber. Imagine, then, piling on the AI bullshit. Can anybody cut through the haze? Apparently for the WSJ and the NY Times, the answer is no. Yeah, it's Anthropic again. This time writing a blog-post level document titled "Disrupting the first reported AI-orchestrated cyber espionage campaign" and getting the major tech press all wound around the axle about it. The root of the problem here is that expertise in cyber cyber is rare AND expertise in AI/ML is rare...but expertise in both fields? Not only is it rare, but like hydrogen-7, which has a half-life of about 10^ -24 seconds, it disappears pretty fast as both fields progress. Even superstar tech reporters can't keep everything straight. Lets start with the end. What question should the press have asked Anthropic about their latest security story? How about, "which parts of these attacks could ONLY be accomplished with agentic AI?" From our little perch at BIML, it looks like the answer is a resounding none. Now that we know the ending, lets look at both sides of the beginning. Security first. Unfortunately, brute force, cloud-scale, turnkey software exploit is what has been driving the ransomware cybercrime wave for at least a decade now. All of the offensive security tool technology used by the attackers Anthropic describes is available as open source frameworks, leading experts like Kevin Beaumont to label the whole thing, "vibe usage of open source attack frameworks." Would existing controls work against this? Apparently not for "a handful" of the thirty companies Anthropic claims were successfully attacked. LOL. By now those of us old enough to know better than to call ourselves security experts have learned how to approach claims like the ones Anthropic is making skeptically. "Show me the logs," we yell as we shake our canes in the air. Seriously. Where is the actual evidence? Who has seen it. Do we credulously repeat whatever security vendors tell us as it it is the gods' honest truth? No we do not. Who was successfully attacked? Did the reporters chase them down? Who was on the list of 30? AI second. It is all too easy to exaggerate claims in today's superheated AI universe. One of the most trivial (and intellectually lazy) ways to do this is to use anthropomorphic language when we are describing what LLMs do. LLMs don't "think" or "believe" or "have intentionality" like humans do. (FWIW, Anthropic is very much guilty of this and they are not getting any better.) LLMs do do a great job of role playing though. So dressing one up as a black hat nation state hacker and sending it lumbering off into the klieg lights is easy. So who did it? How do we prove that beyond a reasonable doubt? Hilariously, the real attacks here appear to be asking an LLM to pretend to be a white hat red team member dressed in a Where's Waldo shirt and weilding a SSRF attack. Wake me up when it's over. Ultimately, is this really the "first documented case of a cyberattack largely executed without human intervention at scale"...no, that was the script kiddies in the '90s. Lets be extremely clear here. Machine Learning Security is absolutely critical. We have lots of work to do. So lets ground ourselves in reality and get to it. 2 Comments 1. [4414] gem Commented on November 14, 2025 Dan Goodin at Ars Technica is an important outlier in the tech press who really understands security. He wrote about the Anthropic story too: https://arstechnica.com/security/2025/11/ researchers-question-anthropic-claim-that-ai-assisted-attack-was-90-autonomous / Reply 2. [4414] gem Commented on November 14, 2025 Rob Gula sent us this. We love it. https://youtu.be/R2g84NQVb-Q?si=ywdl6HDs5NHhi9Vq Reply Leave a Reply Click here to cancel reply. [ ] [ ] [ ] [ ] XHTML: You can use these tags:
[Submit Comment] [BIML_foote]