Connect with us

Tech

How AI Is Changing Cybersecurity

Published

on

Two weeks ago, Anthropic announced that its new model, Claude Mythos Preview, can autonomously find and weaponize software vulnerabilities, turning them into working exploits without expert guidance. These were vulnerabilities in key software like operating systems and internet infrastructure that thousands of software developers working on those systems failed to find. This capability will have major security implications, compromising the devices and services we use every day. As a result, Anthropic is not releasing the model to the general public, but instead to a limited number of companies.

The news rocked the internet security community. There were few details in Anthropic’s announcement, angering many observers. Some speculate that Anthropic doesn’t have the GPUs to run the thing, and that cybersecurity was the excuse to limit its release. Others argue Anthropic is holding to its AI safety mission. There’s hype and counterhype, reality and marketing. It’s a lot to sort out, even if you’re an expert.

We see Mythos as a real but incremental step, one in a long line of incremental steps. But even incremental steps can be important when we look at the big picture.

How AI Is Changing Cybersecurity

We’ve written about shifting baseline syndrome, a phenomenon that leads people—the public and experts alike—to discount massive long-term changes that are hidden in incremental steps. It has happened with online privacy, and it’s happening with AI. Even if the vulnerabilities found by Mythos could have been found using AI models from last month or last year, they couldn’t have been found by AI models from five years ago.

The Mythos announcement reminds us that AI has come a long way in just a few years: The baseline really has shifted. Finding vulnerabilities in source code is the type of task that today’s large language models excel at. Regardless of whether it happened last year or will happen next year, it’s been clear for a while this kind of capability was coming soon. The question is how we adapt to it.

We don’t believe that an AI that can hack autonomously will create permanent asymmetry between offense and defense; it’s likely to be more nuanced than that. Some vulnerabilities can be found, verified, and patched automatically. Some vulnerabilities will be hard to find but easy to verify and patch—consider generic cloud-hosted web applications built on standard software stacks, where updates can be deployed quickly. Still others will be easy to find (even without powerful AI) and relatively easy to verify, but harder or impossible to patch, such as IoT appliances and industrial equipment that are rarely updated or can’t be easily modified.

Then there are systems whose vulnerabilities will be easy to find in code but difficult to verify in practice. For example, complex distributed systems and cloud platforms can be composed of thousands of interacting services running in parallel, making it difficult to distinguish real vulnerabilities from false positives and to reliably reproduce them.

So we must separate the patchable from the unpatchable, and the easy to verify from the hard to verify. This taxonomy also provides us guidance for how to protect such systems in an era of powerful AI vulnerability-finding tools.

Unpatchable or hard to verify systems should be protected by wrapping them in more restrictive, tightly controlled layers. You want your fridge or thermostat or industrial control system behind a restrictive and constantly updated firewall, not freely talking to the internet.

Distributed systems that are fundamentally interconnected should be traceable and should follow the principle of least privilege, where each component has only the access it needs. These are bog-standard security ideas that we might have been tempted to throw out in the era of AI, but they’re still as relevant as ever.

Rethinking Software Security Practices

This also raises the salience of best practices in software engineering. Automated, thorough, and continuous testing was always important. Now we can take this practice a step further and use defensive AI agents to test exploits against a real stack, over and over, until the false positives have been weeded out and the real vulnerabilities and fixes are confirmed. This kind of VulnOps is likely to become a standard part of the development process.

Documentation becomes more valuable, as it can guide an AI agent on a bug-finding mission just as it does developers. And following standard practices and using standard tools and libraries allows AI and engineers alike to recognize patterns more effectively, even in a world of individual and ephemeral instant software—code that can be generated and deployed on demand.

Will this favor offense or defense? The defense eventually, probably, especially in systems that are easy to patch and verify. Fortunately, that includes our phones, web browsers, and major internet services. But today’s cars, electrical transformers, fridges, and lampposts are connected to the internet. Legacy banking and airline systems are networked.

Not all of those are going to get patched as fast as needed, and we may see a few years of constant hacks until we arrive at a new normal: where verification is paramount and software is patched continuously.

From Your Site Articles

Related Articles Around the Web

>

Continue Reading

Tech

Everything new coming to Meta’s AI agent Muse

Published

on

Meta’s personal AI agent Muse is only a few weeks old, and the social networking giant isn’t wasting any time building out what may be its biggest bet on consumer AI to date. 

CEO Mark Zuckerberg kicked off the company’s annual Connect event in Menlo Park on Wednesday with a keynote that made one thing clear: Meta is going all-in on Muse. 

The Muse agent (the physical avatar is named Jolly, according to Zuckerberg) is designed to handle everyday tasks by connecting to users’ apps and services, including email and calendars. At Connect, Zuckerberg introduced a slew of new capabilities and integrations to make Muse more useful and more deeply woven into users’ daily lives. Muse will be everywhere, if the user chooses, including on their Meta AI glasses. 

Muse, which launched in early September, interacts across a user’s devices and digital accounts. The agent is powered by Muse Spark, Meta’s multimodal AI model built for agentic work. Meta has touted it as a more accessible agent than those offered by competitors — an AI helper that, from the jump, allows users to automate the busy work in their lives. 

“The centerpiece of our vision for what we’re building is Muse,” Zuckerberg said as he kicked off a keynote donning khakis and a black T-shirt with the words “Building is My love Language” emblazoned across the front. “In the coming years, I expect that Muse is going to grow into the personal superintelligence that billions of people around the world are going to use to accomplish their goals and improve their lives.”

Zuckerberg also believes that Muse will make money for its users — and of course, eventually for Meta.

“We’re standing behind this by making Muse free for a huge number of tokens, with the expectation that over time we will profit by taking a small fee from transactions,” he said.

Here are the new features and capabilities that got our attention …

Muse gets its own digital avatar

Image Credits:Meta/screenshot /

One of the more fun announcements made Wednesday is that Muse users will soon have the ability to conjure a distinct digital avatar for their particular agent and then video chat with it in real time. A new AI model, Muse Realtime Avatar, has been developed to power the particular feature, the company says.

The idea is that Meta’s previously faceless AI software will be given a face, body, and voice, making them significantly more personable. There’s certainly a hint of Metaverse-ishness to this feature, which was demoed on stage at Connect. Users will be able to have live conversations with this avatar, giving it tasks and asking it questions. 

Muse will also be integrated with Meta’s smart glasses line, the company announced. This means that users will be able to communicate with their agent merely by speaking to their glasses. The agent activates via a wake word, the company said, adding that it will be able to guide users through a personalized workout, log meals, book an appointment, and help them buy products they see. 

Meta said Muse will work in the background and check back in when it’s done.

It’s not clear exactly when this feature will become available, although Meta says that it should launch sometime in “the coming months.” 

Soon, you’ll be able to let Muse run your Mac

Image Credits:Meta/screenshot /

Meta says it is bringing Muse computer work to Mac. The company had previously talked about Muse coming to Mac, and spent more time on Wednesday providing a few new details. This means that users will be able to delegate tasks to the agent, and — much like other popular AI agents from OpenAI and Anthropic — Muse will be able to operate any app on a user’s desktop.

“You can have it help you run your small business, or just get work done for you,” Meta’s chief AI officer Alexandr Wang said Wednesday during the keynote. “You can walk away from your computer and it keeps working for you on all the jobs you lined up.”

Muse will get its own email address

Since Muse will always be working in the background, it will naturally need its own email address. Meta’s Wang announced it is developing that feature and will make it available “soon,” without providing a more precise timeline.

Users will also be able to add Muse to an email thread or forward emails from the agent to handle on their behalf.

Meta has locked in partnerships with companies like Stripe and Shopify, illustrating that the company sees Muse as an important tool for shopping.

Muse can access the entire Shopify product catalog agentically and use Lync and now Shop Pay to buy almost anything on the internet, according to Wang, who noted that Meta has also added more support for payments with PayPal.

The company also announced a string of new partnerships with retailers, including Best Buy, Gap, Sephora, Walmart, and Wayfair. Muse will be able to connect with these retail apps as well as with Expedia and soon, Instacart. Other connectors include GitHub, Granola, and Notion.

Wang noted that the company wants Muse to connect with small business too. Meta recently opened its platform to allow developers to build their own “connectors.” The company received more than 1,500 applications in less than week, he said, adding “I think this could be a generational opportunity to start building for a new platform as it takes off, and the response so far has been really great.”

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Tech

Meta made a Tamagotchi-like wearable for its Muse AI agent

Published

on

The AI amulet has become a bit of a cliché in the tech industry — devices like Friend have turned the idea of physical AI into little more than an exercise in eye-rolling for many consumers.

But that hasn’t stopped Meta from jumping into the arena with its own AI wearable, called Muse Charm, which is designed to give consumers another way to stay connected to its recently launched, and already popular, personal AI agent, Muse.

The device, which CEO Mark Zuckerberg revealed in a “one more thing” moment during the company’s annual Connect event, isn’t ready to ship just yet. Zuckerberg said his team had to “finalize laying out the components” and promised the devices would be “ready to ship in time for the holidays in December.”

The Muse agent, which is now embodied by a cute digital avatar known within the company as Jolly, lives inside the palm-sized totem that users can carry in their pockets or attach to a keychain. The device comes with a tiny screen that displays the avatar representing the agent. Users can talk to the device, which can then presumably carry out tasks on their behalf.

“We packed the whole Muse experience, including the whole real-time voice and avatar stack, into something that fits on a keychain and is always available to talk to,” Zuckerberg said during Wednesday’s keynote. “You just go ahead and tap here in the fingerprint sensor in the corner, and you can start talking without having to unlock a phone or open an app.”

Zuckerberg added: “So if you’re not wearing glasses, this is going to be by far the fastest way to talk to your Muse and to show what’s going on around you.”

Appropriate for what it offers, the gadget has a quasi-Tamagotchi feel to it — a lightweight, personality-filled device designed to keep users always connected to Meta’s software. It also feels like a relatviely low-stakes way for the social media giant to experiment with AI wearables while also offering yet another way to distribute its AI agent to the masses.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Tech

Meta is trying VR glasses (again), this time with more IMAX

Published

on

Meta is renewing its quest to make virtual reality a thing. At Connect on Wednesday, the company announced Meta VR Glasses, its newest entry into the VR market. These glasses actually seem quite promising given their substantially lighter form factor and a host of new entertainment integrations — including (allegedly) IMAX compatibility.

The company says that the glasses are five times lighter than the Meta Quest 3 — and they look much more like normal glasses than the bulky headsets that Meta previously released. Made of magnesium alloy, the glasses are powered by Qualcomm’s Snapdragon Reality Elite processor. They are powered by a computing puck, which also acts as their battery. Presumably, a user can just slip the puck into their pocket, which allows the glasses to be used on the go.

The glasses are largely entertainment-focused and come with micro-OLED panels built into the lenses, which provide a 5K Infinite Display with 37 pixels per degree, as well as Dolby Vision and support for Dolby Atmos audio. Users will be able to download and watch movies.

Perhaps one of the more unique features of the glasses, however, is that Meta is pitching them as a great way to enjoy IMAX-captured films.

Indeed, the company calls the glasses the “first IMAX Enhanced certified VR device ever.” What does that mean? Meta maintains that their glasses will be one of the only ways to experience the expanded aspect ratio that defines the distinct high-resolution viewing experience.

The glasses are also compatible with 3D experiences — and even movies that integrate a user’s physical space is integrated into their viewing experience. Meta says that it has teamed up with Disney and that, in November, Disney+ users will be able to stream specific movies — including certain Marvel movies — in 3D.

Meta says that users will be able to watch specific movies and have their surroundings “transformed with immersive environments, dynamic effects, stunning 3D visuals, and spatial audio” — essentially converting the movie into a VR gaming-type experience.

The glasses will also come with Meta AI — its automated virtual assistant — built in, which means that users will be able to talk to the glasses and automate various tasks via voice command. For instance, Meta says you’ll be able to start a movie just by asking your glasses to do so. Other ways to issue commands include hand gestures.

Meta says the glasses will be available next spring with a starting price of $1299.99.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Trending

Copyright © 2017 Zox News Theme. Theme by MVP Themes, powered by WordPress.