I'm curious to hear what security folks think of the Anthropic's disclosure that criminals used its infrastructure to "conduct a scaled data extortion operation" compromised 17 organizations around the world. Anthropic gives the impression its AI automated the gamut of activities, from reconnaissance to initial access to malware development to data exfiltration to extortion analysis and ransom note development.
I remain skeptical that an LLMs would give extortionists much of an edge over more traditional means. Seems like the AI would introduce as many problems as it solves. Am I just being an AI curmudgeon or is my skepticism justified?
https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf