I wish I didn't auto delete my toots sometimes, as I predicted this about 6 months ago...

People are injecting malware responses into Microsoft's AI, so now when you ask it questions it is serving people malware downloads. https://www.bleepingcomputer.com/news/security/bing-chat-responses-infiltrated-by-ads-pushing-malware/

Bing Chat responses infiltrated by ads pushing malware

Malicious advertisements are now being injected into Microsoft's AI-powered Bing Chat responses, promoting fake download sites that distribute malware.

BleepingComputer

From that thread (RIP), expect nation states, SEO spammers and more to be filling generative AI with crap to install malware, influence policy documents, research etc etc.

It's absolutely the next stage of enshittification (sorry, I mean increasing shareholder value) where everybody can pretend to shocked it happened in two years.

@GossiTheDog it sees the shit and is learning it. Makes sense.
@johnefrancis @GossiTheDog Doing exactly what it was made to do, learn. It can't unlearn either, unless they have backups of it to load.
@jackemled @GossiTheDog yeah, it's hard to see how anyone can claim to have undone the copyright violations they committed during training. So I guess they'll just have to license at whatever term the creator wants.

@johnefrancis @GossiTheDog "ooh it's not stored intact, the ai shreds it", so you admit it's not intelligent, & that it's just an idea blender?
"nooo it's original it makes new things, inspired by what it remembers", so it does involve stealing copyrighted material?

I wish they would at least make up their minds & be consistent with their bullshit.

@jackemled @GossiTheDog I guess we'll find out when it starts spitting out mouse ears and Like Skywalkish and the AI companies eat Disney's lunch.
@johnefrancis @GossiTheDog I hope it's soon!
@jackemled @johnefrancis @GossiTheDog somebody needs to develop a robust multistage ML poisoning scene. Single stage to make it respond with desired responses to targeted keywords already exists but seems too easy to revert, but if you can slowly plant the malicious responses over time and "activate" them by publishing another final set of seemingly irrelevant samples then you can plant all kinds of malicious responses that are VERY hard to delete from the model
@GossiTheDog Note to Self: Work on “surprised” face.
@GossiTheDog I've been going out of my way to avoid "AI generated content," which is usually stale and often incorrect. I don't like how Microsoft (Bing, Edge) and others are shoving it down everyone's throats.
@GossiTheDog surprised? Nope. I was aware about nature of "Innovative capitalism" for some 8 years now. The more I learn the more I realize how dumb and opportunistic it is by nature. And tbh I do not blame them. I blame the media and gov basically following their lead. They have power, but they did not care. All they cared about was steak at the CEO summer house party.
But some of us (well, I feel personally myself) also share the blame for not always being vigilant about this.

@GossiTheDog When you’re right you’re right.

Just curious, why do people auto-delete posts?

@earthlingusa @GossiTheDog Search engines crawling sites, sometimes even when told not to. Techbros doing the same thing to train LLMs.
@GossiTheDog just wait until AI starts getting applied to discovering exploits.

@GossiTheDog dude it’s a complete shit show. I tried to get a bounty for jailbreaking the model through bings GPT4 interface. Microsoft sent me to openAI. OpenAI just kept saying it was fixed regardless of the screenshots and videos I was sending them. Literally just refusing to accept it.

Let’s just bury our heads in the sand and maybe the problem with go away. So this isn’t the least bit surprising.

@GossiTheDog AI is the future that can replace humans they say.
@GossiTheDog Real intelligence knows to ignore anything marked as an ad. Their consumption of ads shows how far we are from real AI.
@GossiTheDog That's not quite how it works. People aren't "injecting malware responses into Microsoft AI". Somebody has hacked an ad-producing company and has generated malicious ads. BingChat simply displays ads - and happens to display those too. They would be displayed by any ad-serving application; the AI isn't exactly the problem here. The AI problem comes only from the fact that people are more likely to trust ads displayed by what seems like an intelligent conversation.

@bontchev @GossiTheDog

The bad actors don't need to hack the ad companies.

Remember that one of the categories in the advertising profiles is the device OS version.

The bad actors just pay the ad distributors to display the ads to vulnerable machines.

@BillySmith @GossiTheDog I am just saying that this is what has happened here. Please read the article.

@bontchev @GossiTheDog

I did and while it was a bad actor acting against the ad agency this time, the really effective bad actors don't need to do that.

They are some of the 3d-party ad-distributors most profitable customers.

No one should browse the web without an ad-blocker and a script-blocker.

@GossiTheDog Microsoft has always been ahead of the game with security. First to give us email viruses, first to give us self replicating sql viruses, and now the first AI virus. Innovation!
@GossiTheDog Next stop, teaching ChatGPT to write the trojan horse crap in response to someone asking for some source code that does a particular function…
@GossiTheDog
Literal example of “Garbage in garbage out.”
@GossiTheDog
It's like Abraham Lincoln said. "The problem with the Internet is you can never verify your sources"
@GossiTheDog I went into my registry and deactivated that little shit the INSTANT it showed up on my toolbar.
@GossiTheDog tech bros consider the ways that adversarial parties could absue the technology before rushing it to market challenge (IMPOSSIBLE)
@smn @GossiTheDog techbros ARE the adversarial parties!
@GossiTheDog And now it's built into the Windows 11 taskbar as Windows CoPilot. What could possibly go wrong?!!!!
@GossiTheDog that says "ad," i don't think you could describe it as being related to the ai, that's just malicious ads like they all have been profiting from for decades.
@GossiTheDog If you use AI tools you deserve everything that happens next.
ChatGPT is allowed to browse the internet once again

ChatGPT can once again browse the internet to provide users with real-time updates.

Engadget
@GossiTheDog Previous iterations of Microsoft AIs were spouting Nazi propaganda. They really should learn.
@GossiTheDog manual delete always better
@GossiTheDog garbage in, garbage out
@GossiTheDog @jurjen_heeck yeeeh. #ai is now serving you malware
#infosec
Looks like #ai #chatgpt is becoming as vile as the humans it is mimicking.
@GossiTheDog This does not happen in Bing Chat Enterprise FYI.
But it still sucks that bing chat does this
😕
@GossiTheDog Also a hint: you can redirect bing.com to nochat.bing.com which effectively disables bing chat.
@GossiTheDog you weren't the only one predicting it, but I would probably have expected it to take longer 🤷‍♂️
@GossiTheDog very interesting, i’m not sure if you’ve written about fake versions of advanced ip scanner but recently at my security analyst job in the past two weeks i have noticed multiple instances of fake ip scanners wreaking havoc on machines. in particular creating scheduled tasks to enable backdoor ssh and a variety of other encoded powrshell commands to download further payloads . i wonder if there been an uptick in these ?