Latest / Tech Talks With Kinsoft / Last Week in Tech – Anthropic's Exploit-Writing Model, Meta Goes Closed-Source, and a Critical Notebook RCE
Transcript
- 0:00Picture your digital life right now. You know,
- 0:03like every app you use, the corporate databases
- 0:05you access, even the cloud storage holding years
- 0:08of your work. Yeah, pretty much your entire digital
- 0:11footprint. Right, exactly. Up until recently,
- 0:13we basically relied on human beings to build
- 0:16the invisible walls, protecting all that data.
- 0:19And we relied on humans to rush in and fix them
- 0:20when a crack appeared, too. Yeah, but a new tech
- 0:23update crossing our desk from Kinsoft, along
- 0:26with this... honestly shocking internal test
- 0:29from the AI giant Anthropic Well, it basically
- 0:32proves that era is over. It really is over. So
- 0:35today's deep dive is all about the machine speed
- 0:37threat landscape. We're looking at why human
- 0:40speed IT responses are officially dead and why
- 0:43a 10 -hour window is now essentially a worst
- 0:45-case scenario. So, okay, let's unpack this.
- 0:48Yeah, because the stakes here, I mean, they go
- 0:50far beyond just a standard software update or
- 0:52a routine patch. The Kinsarf briefing and the
- 0:55anthropic data we have today represent a fundamental
- 0:57shift in how the global infrastructure defends
- 0:59its data. A total paradigm shift. Completely.
- 1:02We are moving away from a reactive, human -driven
- 1:05security model right into an automated machine
- 1:09speed arms race. Well, let's start with what
- 1:11I can only really describe as an absolute bombshell
- 1:14from Anthropic. They unveiled the details of
- 1:17a program called Project Glasswing. Ah, yeah,
- 1:20the internal tests. Right. And now this was designed
- 1:23from the ground up to be a defensive -only initiative.
- 1:26They took an unreleased frontier AI. So like
- 1:30the absolute bleeding edge of their technology
- 1:32and granted early access to about 50 security
- 1:35partners. Which, you know, is a pretty standard
- 1:37industry practice, historically speaking. Really?
- 1:39Yeah. I mean, you give your defenders the most
- 1:41powerful lens possible to inspect the code, right?
- 1:44Hoping they find the cracks before anyone else
- 1:46does. Well, the testing phase produced results
- 1:47that completely upended that whole plan. Because
- 1:50during this closed test, that unreleased AI model
- 1:53autonomously produced 181 working exploits for
- 1:57Firefox. Oh, wow. And that's not a typo. 181.
- 2:01And Firefox isn't some beta app coded over a
- 2:04weekend by a college student. No, not at all.
- 2:06It's a mature, heavily scrutinized web browser
- 2:09that's been around for decades. Exactly. Finding
- 2:12a single working exploit in a program like that
- 2:15usually takes a dedicated human researcher. weeks,
- 2:19if not months, of painstaking analysis. And Anthropic's
- 2:22model just spun up 181 of them autonomously.
- 2:26Completely autonomously. It was so intense that
- 2:29they actually judged the model to be too dangerous
- 2:32for broad release. You know, what's fascinating
- 2:34here is the underlying mechanics of the dual
- 2:37use dilemma in artificial intelligence. Yeah,
- 2:39dual use dilemma. Right. Because the exact same
- 2:41computational power and deep pattern recognition
- 2:44required to defend a complex system at scale
- 2:47is precisely what makes the AI a devastatingly
- 2:50fast attacker. That makes sense. Yeah, because
- 2:53to patch a vulnerability, an AI first has to
- 2:56deeply understand how to break the software,
- 2:58right? It has to ingest millions of lines of
- 3:00code, spot the logical flaw, and understand precisely
- 3:03how an unexpected input could, say, cause the
- 3:06system to behave abnormally or leak memory. Right,
- 3:09because it doesn't read code line by line like
- 3:11a human trying to read a novel. It reads it structurally.
- 3:14It maps the entire architecture simultaneously.
- 3:17So it spots a variable input over here and immediately
- 3:20calculates how it might overflow a buffer like
- 3:2310 modules away. And if you ask it to generate
- 3:26a patch, it uses that architectural map to block
- 3:29the bad input. Okay. But if you tweak the prompt
- 3:32slightly or, you know, if the model is operating
- 3:34autonomously without a strict ethical governor,
- 3:36it uses that exact same structural understanding
- 3:39to generate the attack payload. So it's two sides
- 3:42of the same coin. Exactly. The capability to
- 3:45secure and the capability to destroy are structurally
- 3:48identical in these models. Because it is a machine,
- 3:52it analyzes a billion lines of code in the time
- 3:54it takes a human analyst to basically open their
- 3:57laptop. So it's like inventing a highly advanced
- 3:59lock -picking robot to test the security of bank
- 4:03vaults, only to realize your robot is so efficient
- 4:05it could autonomously empty every bank in the
- 4:08city before lunch. That's a perfect way to put
- 4:10it. You can't build a robot that only knows how
- 4:12to pick the lock. for the bank manager. If it
- 4:14knows how the pins align, it knows how to defeat
- 4:17them. And this is exactly why Anthropic had to
- 4:20slam the brakes on releasing Project Glasswing.
- 4:23Because the risk was just too high. Yeah, the
- 4:25defensive benefits were enormous, sure. But dropping
- 4:29that uninhibited capability into the open internet,
- 4:32it was deemed catastrophic. Which really forces
- 4:35us to look at the internet you and I are using
- 4:37right now. Like we can theorize about unreleased
- 4:40frontier models in a lab all day, but the Kinsoft
- 4:43brief grounds this in current reality. It really
- 4:46does. We know AI can attack at machine speed.
- 4:48So how fast are the criminals actually moving
- 4:52today against the systems we currently rely on?
- 4:55Well, the Kinsoft brief highlights a really critical
- 4:57flaw discovered in a popular open source Python
- 5:00notebook tool called Merimo. OK, Merimo. Yeah.
- 5:03Tools like Merimo are foundational in data science,
- 5:06AI development, corporate analytics. And the
- 5:08flaw they found was a pre -authentication remote
- 5:11code execution vulnerability. Pre -auth RCE.
- 5:15Right. A pre -AUC RCE. So just to be clear, we
- 5:18aren't talking about phishing emails or tricking
- 5:20an employee into clicking a malicious link here.
- 5:22No, not at all. This is a zero interaction takeover.
- 5:26If the software is running on a server, a hacker
- 5:29can basically reach across the internet, send
- 5:31a specific command, and completely own the machine.
- 5:34They can run whatever code they want without
- 5:36ever needing a password. Exactly. A systemic
- 5:39vulnerability like this is like... It's like
- 5:42a building's intercom system being wired directly
- 5:44into the elevator controls. Oh, wow. Yeah. Anyone
- 5:47on the street can just press a button and send
- 5:49the elevator straight to the penthouse without
- 5:51ever stepping foot inside or scanning a security
- 5:54badge. And here is the metric from the brief
- 5:56that should send a chill down the spine of literally
- 6:01every IT professional listening. Yeah, this is
- 6:04the scary part. From the moment that flaw in
- 6:07Murumo was publicly disclosed, it took only about
- 6:0910 hours for it to be exploited in the wild to
- 6:12drop malware. Just 10 hours. 10 hours from public
- 6:16disclosure to global infection. I mean, 10 hours
- 6:18is a blink of an eye in corporate IT infrastructure.
- 6:21Okay, so I get the 10 -hour panic, but wait.
- 6:23I had to play devil's advocate for a second.
- 6:25Sure, go ahead. 10 hours sounds fast, but I mean,
- 6:27isn't that basically a full workday? If a flaw
- 6:30drops at 8 a .m., why can't a company just patch
- 6:32it by 5 p .m. before they go home? Plus, aren't
- 6:35companies using AI to automate the patching process
- 6:38too? Like if the attackers have bots scanning
- 6:41for vulnerabilities and launching exploits in
- 6:4310 hours, why don't defenders have bots automatically
- 6:47applying the patches? Why are we still relying
- 6:49on human bureaucracy? It sounds simple, right?
- 6:52But it really comes down to system fragility
- 6:54and the burden of consequence. Burden of consequence.
- 6:57Yeah. See, an attacker only has to be right once
- 7:00to compromise a system. A defender has to ensure
- 7:03that applying a patch doesn't accidentally bring
- 7:05down the entire company. If you rush an automated
- 7:09patch on a core data tool like Merimo without
- 7:12human oversight, it might inadvertently change,
- 7:15say, how a Python script parses a timestamp.
- 7:18Oh, which breaks something down the line. Exactly.
- 7:21Suddenly, your logistics database rejects every
- 7:23incoming shipping order because date format is
- 7:26slightly off. So the cure just halted your global
- 7:29supply chain. That's how a well -intentioned
- 7:31automated patch causes far more financial damage
- 7:35than the hacker ever could. So defenders are
- 7:37basically forced to test everything manually.
- 7:40Yeah. Which creates a massive bottleneck. Exactly.
- 7:42Let's actually walk through those 10 hours. In
- 7:45hour one, the vulnerability is disclosed on the
- 7:48security forum. The IT team have to actually
- 7:51see the notification. thousands of other daily
- 7:55alerts. Right. And let's assume they catch it
- 7:57instantly. Hours two and three are spent just
- 7:59figuring out if the company even uses Marimo,
- 8:02where it's installed and what systems depend
- 8:04on it. Ah, shadow IT. Yeah. Which is really just
- 8:07a polite way of saying the marketing department
- 8:09bought a random software license on a corporate
- 8:11credit card and didn't bother telling the security
- 8:14team. Yeah. Shadow IT makes asset discovery an
- 8:16absolute nightmare. Security teams are hunting
- 8:19for software they don't even know they own. That's
- 8:21terrifying. It is. By hour four. you've hopefully
- 8:24tracked down the vulnerable servers. Then hours
- 8:27five through eight are spent in a staging environment,
- 8:29desperately testing that patch so your logistics
- 8:32database doesn't crash. Right. You're constantly
- 8:35balancing the demands of the security team who
- 8:37want the patch applied immediately and the ops
- 8:40team who demand 100 % uptime. And while your
- 8:43IT team is doing all this careful human speed
- 8:45work, the attackers are entirely unburdened by
- 8:49QA testing or operational uptime. Right. They
- 8:51don't care about your uptime. Exactly. The second
- 8:54the exploit went public, criminal syndicates
- 8:56fed it straight into their automated scanners.
- 8:58And those bots scan millions of IP addresses
- 9:01a second. Yeah. When they find an unpatched Marimo
- 9:03instance, the malware is dropped instantly. There
- 9:06are no staging environments, no approval meetings,
- 9:09just pure machine speed execution. The takeaway
- 9:12from the Kinsoft source here is absolute. If
- 9:14your teams run open source data tools, they must
- 9:17be on an incredibly fast patch cycle. The gap
- 9:20between public disclosure and criminal exploitation,
- 9:22it went from months to weeks to days. And now
- 9:26we are at 10 hours. Yeah. And in the very near
- 9:28future, it will be 10 minutes. Which brings up
- 9:31a massive ripple effect across the whole tech
- 9:33industry. With open source tools like Marimo
- 9:36proving so vulnerable to rapid exploitation and
- 9:39frontier models like Anthropix proving so dangerous
- 9:42if they fall into the wrong hands. Well, the
- 9:44biggest tech giants on the planet are abruptly
- 9:47changing their business strategies. Massive shifts.
- 9:50Yeah. Here's where it gets really interesting.
- 9:52Meta, you know, the company behind Facebook and
- 9:54Instagram, they just launched. MuseSpark. And
- 9:57MuseSpark is their very first proprietary closed
- 10:00AI model. Which is a complete reversal of their
- 10:03established operational strategy. Totally. Meta
- 10:06has historically been the ultimate champion of
- 10:08the open source AI movement. They built their
- 10:11entire AI reputation on the Lama models, making
- 10:14them freely available for developers to download,
- 10:16to modify, and build upon. Right. They pushed
- 10:19to democratize AI. And practically overnight,
- 10:22they are retreating into a closed, proprietary
- 10:24walled garden with MuseSpark. They are locking
- 10:27the doors. They aren't the only ones making big
- 10:30moves. The Kinsoft update also highlights some
- 10:32enormous financial numbers flashing from Amazon
- 10:35and OpenAI. Specifically, AWS Amazon Web Services
- 10:40noted their AI business has just passed a massive
- 10:44$15 billion run rate. A $15 billion run rate,
- 10:48meaning based on their current explosive monthly
- 10:50revenue, they are pacing to make $15 billion.
- 10:53billion this year purely on AI infrastructure.
- 10:57Right. And when AWS is projecting $15 billion
- 11:00in AI revenue, it proves that enterprise companies
- 11:03are completely intertwining their core logistics,
- 11:05financials, and customer data with artificial
- 11:08intelligence. They're slowly bought in. Absolutely.
- 11:10And Meta sees that corporate money on the table.
- 11:13They know enterprise clients like banks, hospitals,
- 11:15energy grids. They won't buy into an open source
- 11:17model where structural vulnerabilities are broadcast
- 11:20to hackers the exact moment they're found. Right.
- 11:22Meta closed their model because enterprise security
- 11:24and the billions of dollars attached to it absolutely
- 11:27demands it. So how does a closed proprietary
- 11:29model technically mitigate that 10 hour vulnerability
- 11:33window compared to an open source one? Like functionally.
- 11:38Well, think about the mechanics of visibility.
- 11:40Open source collaboration is wonderful for innovation
- 11:43because thousands of developers look at the code,
- 11:46improve it, find creative uses. But as we saw
- 11:49with Murimo, open source also means that when
- 11:51a structural flaw is found. Everyone sees the
- 11:54underlying code at exactly the same time. The
- 11:57criminals see the blueprints at the exact moment
- 11:59the defenders do. It's just an open book for
- 12:01anyone to read. Exactly. And when you introduce
- 12:04AI to that dynamic, the attackers can weaponize
- 12:07that open book in hours. Wow. So by pivoting
- 12:10to a closed model like MuseSpark, Meta is hiding
- 12:14the blueprints. If a vulnerability is discovered
- 12:16internally, they can patch it behind closed doors,
- 12:19push the update globally across their managed
- 12:21servers, and the public... including the attackers,
- 12:23never actually sees the raw mechanics of the
- 12:26flaw. Oh I see. It essentially removes the public
- 12:28race against the clock. That makes total sense.
- 12:31I mean, if an unreleased, closed model like Anthropix
- 12:34can autonomously generate 181 working exploits
- 12:38in a defensive test, giving bad actors open source
- 12:41access to a frontier model's underlying architecture
- 12:43is essentially handing them a machine gun in
- 12:46a glass house. Yeah, that's exactly what it is.
- 12:48Tech companies are being forced to prioritize
- 12:50heavily guarded security over collaboration.
- 12:52The financial stakes are just too high to leave
- 12:55the hood of the car open for anyone to tinker
- 12:57with the engine. A machine speed threat landscape
- 13:00basically forces you to remove human delay from
- 13:02the equation and tightly control the technology
- 13:05generating the threats. Walled gardens are kind
- 13:08of the only current viable response when your
- 13:11adversary operates in milliseconds. Okay. So
- 13:14to summarize everything we've pulled from these
- 13:15sources for you today, we are living in a brand
- 13:18new era. The anthropic test proved that artificial
- 13:21intelligence can discover and weaponize software
- 13:23vulnerabilities at a scale and speed humans simply
- 13:27cannot match. The Marimo incident proved that
- 13:29cyber criminals are already exploiting flaws
- 13:32in the wild within 10 hours of discovery. And
- 13:34the massive strategic shifts from companies like
- 13:36Meta and Amazon show the industry is reacting
- 13:39by prioritizing walled gardens and extreme security
- 13:42over open access. Because human monitoring is
- 13:45just no longer a sufficient shield for your data.
- 13:48The Kinsoft Tech Talks brief ends with a stark
- 13:51piece of advice. Stay patched. Stay skeptical.
- 13:54They note that listeners looking for help keeping
- 13:56their patching on pace with these incredibly
- 13:59fast attackers can visit www .kinsoft .com .au.
- 14:05Because if your patching isn't automated and
- 14:06immediate, you're hopelessly outgunned. It really
- 14:09makes you evaluate your own digital life, doesn't
- 14:12it? It really does. I'd ask you, the listener,
- 14:14to just reflect on your habits. When your phone
- 14:17says there's a critical security update, do you
- 14:19hit install now or do you hit remind me tomorrow
- 14:21because you're in the middle of a meeting? I
- 14:23do that all the time. We all do. But how quickly
- 14:26do you update your apps, your open source tools,
- 14:29or your operating systems? Remind me, tomorrow
- 14:31used to be harmless procrastination. But in a
- 14:34machine speed landscape, tomorrow is 14 hours
- 14:37too late. That is a sobering reality check. We
- 14:40are trusting these incredible AI tools to act
- 14:42as our ultimate shield, right? To patch the holes
- 14:45and monitor the walls faster than we ever could.
- 14:47And this raises an important question, something
- 14:48really profound to leave you with. What's that?
- 14:51Well... We know the dual use dilemma is real.
- 14:53AI can defend an attack with equal brilliance.
- 14:56If an AI can autonomously generate 181 working
- 15:00exploits in a controlled defensive test today,
- 15:03what happens tomorrow when someone designs an
- 15:06AI specifically to find the hidden flaws in the
- 15:08very AI models we are relying on to protect us?
- 15:11Wow. The ultimate lock picking robot designed
- 15:14solely to dismantle the security robot you just
- 15:16bought.