neil

@nsw7.bsky.social

1. LLM-generated code tries to run code from online software packages. Which is normal but 2. The packages don’t exist. Which would normally cause an error but 3. Nefarious people have made malware under the package names that LLMs make up most often. So 4. Now the LLM code points to malware.

David D. Levine@daviddlevine.com · last yr.

LLMs hallucinating nonexistent software packages with plausible names leads to a new malware vulnerability: "slopsquatting."

Hi, I'm the guy who used to oversee the federal government's agency IT telecommunications contracts. This is extremely bad. There is absolutely no need for this. Not only is it a huge security exposure, but the simplest explanation for this is that it is meant to be a security exposure.

Elon Musk’s Starlink Expands Across White House Complex

Trump administration officials said the company donated the internet service, saying the gift had been vetted by the lawyer overseeing ethics issues in the White House Counsel’s Office.

nytimes.com