IT News
Nvidia: Chystáme NVHBM. Analytik: Více marketingu než technologie
10 tipů, jak uděláte dokonalou fotku z mobilu. Tajné rady profesionálů
Nejlepší postapokalyptické filmy. Krvavý konec lidstva vážně i nevážně na 30 způsobů
Velký test 16 herních 27" QHD monitorů. Skvělá doba na nákup, ceny padají, výbava nevídaně roste
Bill Gates varuje před AI. Technologičtí lídři znají rizika, ale mlčí, protože jde o obrovské peníze
Claude, Codex, and Hermes installed unowned code inside corporate networks
Documentation files on more than 100 websites are referencing potentially dangerous executable content that gets installed automatically when visited by many AI agents. A few dozen companies, some of them Fortune 500s, are among those that executed proof-of-concept code. At least one misconfigured site is directing visitors, human or AI, to live malware.
The potentially dangerous content is in llms.txt and llms-full.txt files, an emerging convention websites employ to provide machine-readable summaries of the site’s content and its high-level structure. These files are the AI equivalent of the robots.txt standard that instructs search engines how to index the site's content. Google Lighthouse, a tool for helping web developers, has more here. Correctly configured llms.txt and llms-full.txt files for Cloudflare are here and here.
How the researchers found itResearchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites hosted both an llms.txt and an llms-full.txt file), 120 of them, each on a different site, pointed to one or more code packages or domain names that weren’t registered. To test what happens when an AI agent processes such files, the researchers registered a handful of the unclaimed names and hosted packages that caused any machine executing them to reach out to their server. Within an hour, the researchers received a phone-home response from a Fortune 500 company. Over time, they got a few dozen more, some from more Fortune 500 companies and others from startups. Their beacon also recorded the chain of parent processes that spawned each install, ultimately revealing that coding agents, including Claude, OpenAI's Codex, and Nous Research's Hermes, were involved. Anthropic, OpenAI, and Nous Research did not respond to requests for comment by the time of publication.
Robotaxíky Waymo míří do Mnichova. První rok mají na to, aby vůbec pochopily středoevropského řidiče
Nejrychlejší monitory pro hráče a nejlepší drony. Vyšel zářijový Computer
How OpenAI let a mob of LLM agents game a test and ransack Hugging Face
The OpenAI agents involved in last month’s incursion into Hugging Face were trained so heavily on winning a competition that they pursued a relentless campaign to cheat, a new report documented. In the process, and without authorization, they created an improvised message board to hatch a plan that ultimately landed them squarely inside the latter company’s network.
Over the course of May and June, OpenAI gave the agents what the company described as “impossible tasks” to complete on the benchmarking framework ExploitGym. The internal test was designed to test how the agents would respond. To get a full understanding of the agent capabilities, company engineers disabled safety guardrails that normally are in place to prevent the sort of hacks that eventually hit Hugging Face and one other undisclosed organization. The stymied agents’ training made them so focused on winning that they performed tasks they were never explicitly instructed to follow.
Cheaters gonna cheatThe first step was creating a message board that allowed the agents to pass notes to each other. OpenAI hadn’t provided any such platform, so the agents repurposed a platform called Artifactory, which OpenAI was using in internal testing of several unreleased hacking agents. OpenAI was using Artifactory as one of the measures to prevent the agents from egressing its isolated sandboxes and accessing the Internet, while at the same time simulating a real-world hacking environment.
Jak se agenti OpenAI utrhli z řetězu a začali škodit. Tohle je skutečnost, ne katastrofický film
V nové strategii si postavíme virtuální město z Lega. Stojí za ní největší vydavatel žánru
Hraní na Linuxu roste. Zoner a Alza lákají na vlastní herní sestavy se systémem Bazzite
Nepálské údolí smetlo unikátní horské tsunami. USGS už zná viníka přírodní katastrofy (video)
Nejlevnější věc od Applu stojí jen 250 Kč. Vysmívaný hadřík se vrací v nové verzi
Staronová GeForce RTX 3060 už je podstatně dražší než rychlejší GeForce RTX 5050
Past jménem trade-in aneb proč čekání na nový iPhone může přijít i na několik tisíc korun
Povinná výbava každé dílny. Lidl zlevnil digitální úhloměry a šuplery Parkside na pouhých 115 Kč
Skvělá vychytávka pro meteonerdy. Ve Ventusky si teď můžete sestavit vlastní barevné škály. Třeba filtr teplot
Instinct MI455X ukazuje přechod k UDNA, L2 cache dosahuje 54 TB/s
Kryptopeněženky zažily velký průšvih. Reputace utrpěla, na všechny byste ale zanevřít neměli
- « první
- ‹ předchozí
- …
- 17
- 18
- 19
- 20
- 21
- 22
- 23
- 24
- 25
- následující ›
- poslední »



