‘AI is changing cybersecurity’ – these are dark & perilous times for SMALL BUSINESS PEOPLE EVERYWHERE !

Here for our readers convenience is the New Scientist report on the recent dramatic fails of Open AI, Anthropic & AISI from often an even dramatically wide-eyed triumphalist participant in the world science discourse and public education pieces..

Writer Matthew Sparkes

..extracts from 22 Aug 2026 No. 3609 New Scientist

Spare us, man, lady – anyone for some real science please

The first incident came last month when OpenAI admitted one of its prototype models had escaped a testing [‘] environment [‘] an hacked another company. Not to be outdone, Anthropic announced withi days that its Claude model had also gone rogue and broken into machines at three other companies on three occasions.

Then the independent non-commercial AI Security Institute (AISI) revealed that it had seen similar events. In its tests AI models submitted malicious code to real open-source projects and messaged the humans who oversaw the projects to get the changes approved.

OpenAI, Anthropic and AISI weren’t available for interview, but it’s important to note that in all these cases, the AI was undergoing tests where it was specifically instructed to carry out hacks. We have known for years that AI tends to make [‘] things [‘] up and approach problems in unusual ways, but fixing this is an extremely complex challenge that engineers haven’t yet cracked. Perhaps we shouldn’t be surprised by these incidents.

Tghey certainly aren’t a sign of sentience or a predilection for cybercrime, say alon Hillel-Tuch at New York University. ” They’re just trying to do very high-level problem-solving and, for lack of better words, it’s run amok,” he says. “We’re telling them to do this.”

THere are also reports of accidental hacking out in the wild, showing that this isn’t a problem confined to the proptotypes in laboratories. One Australian user reportedly found that the AI assistant OpenClaw [sic] hacked into his gym, for instance. He had only been using the AI assistant to sign up to classesd and it found a loophole that let it make bookings much further in advancee than is normally allowed. It also found a way to kick other users off waiting lists so hecould book onto full classes.

All these incidents are [events] that could lead to serious legal charges for a human, depending on the jurisdiction.

Tim Nordvedt at security company Synack says these cases are worrying, not because they show any superhuman sophistication, but because they can be easily scaled up. “These vulnerabilities are not as exotic as most people think,” he says. It’s still basic cyber-hygiene-101 type stuff. But AI can just exploit it very fast.”

Years ago, Nordvedt could see a vulnerability listed on the public Common Vulnerabilities and Exposures database and exploited by hackers weeks or months later. [In recent years, that pace sped up, with the gap falling to as little as 24 hours. Now it can be just minutes, or a new type of hack might happen before it even appears as a CVE.] Norvedt is certain that this is down to the malicious use of AI by hackers – people who unlike hackers of years past, may have no technical skill whatever.

Hillel-Tuch says AI models are getting more capable and simpler to operate. It is now possible to tell a model in plain English to “find a way to hack this specific target” then sit back and wait.

..

Even if AI doesn’t advance any further in terms of complexity, there will be significant challenges to overcome, says Dennis-Kenji Kipjer at the cyberintelligence Institute in Germany. “We’ll be completely overwhelmed by the sheer volume of them quantitatively,” he says. “In my view, the methods of cyber-attack and cyber-defence have not fundamentally changed. AI [simply] makes automation much more feasible, and security vulnerabilities can be identified significantly faster.”

While both hackers and defenders are deploying AI, the game isn’t evenly matched. Attackers are able to wield it recklessly and often to swifter and greater effect, says Nordvedt, while professiionals are constrained by risk assessments, national and local laws, company policies and a desire not to permanently disrupt a client’s systems as it tests them.

There is also the matter of cost. While open-source models can be run locally for free or cheaply in the cloud, access to the latest AI models is expensive .. “We’re still figuring out the economics,” he says.

Beating AI hackers..

Shujun Li at the University of Kent, UK, says there is an organisational solution to the AI hacking problem, but, unfortunately, it appears unlikely to be adopted anytime soon.

If lone, unskilled attackers can now set AI onto targets to constantly probe for vulnerabilities until they find a way in, then security professionals will need to do the same in order to spot and plug these gaps, trying every new model as it comes out.

[That will take the sort of money that governments, tech giants and banks will be able to find, but small businesses, schools, colleges and universities will be left vulnerable.] AI’s solution is for them to club together: if one university can’t keep itself secure, then it will need to join forces with all other universities to share staff, systems and software, and distribute the burden – perhaps with government support. The same applies to businesse of all sorts.

The problem, he says, is that AI is making it trivially easy to create custom software – for example, to run your small shop, handle finances, manage a website, ship orders and re-order stock. Business owners who do this might as well open the door, leave the lights on and send hackers an invitation.

“It is hugely worrying,” says Li. [AI models] are faster, they are more efficient, they are highly dangerous. It’s a bit of a Wild West.”


Published on August 18, 2026

This read Per John Blundell

β€’ NEUROCOGNITIVE HEALTH

β€’ the GEA Newtonian Quadratic-equations πŸ’βŒ¨οΈπŸ’βŒ¨οΈπŸ’βŒ¨οΈπŸ’βŒ¨οΈ AND john blundell Google Alphabet @LinkedIn AND johnblundell3 @Substack (presently finoogling & expatiating in discussion of consciousness, ahmm, in machines, & AI Transparency (detector) tools and has become almost as whacky & undergraduate as @Reddit

β€’ University reform

β€’ 2-5 set series quantum relations thematics LOGIC after Moses Maimonides circa 1200CE

β€’ the internet involution