One person does it, they get bullied by the government into suicide, a company worth trillions does it and they get government contracts?
“…during a UK government cybersecurity evaluation.”
https:/github.com/w1b/aisi-mythos-inc-2026-07-28-01-recovered-pr
It’s not great social engineering. The AI is immediately caught with malware and then tries to build social proof to get out of the issue? I think that social engineering is still for humans.
I’m not sure how GitHub accounts agreeing with each other that I’ve never seen before would result in my merging a PR without at least looking for malware. Also code review agents should really not be fooled by invisible text tricks, I would hope so at least. The bar is very low for agent harnesses right now.
Or perhaps they are already doing something like that.
Well, uh, how and why is this possible on the GitHub website? This reminds me of invisible ASCII characters, but those at least serve some purpose
Seems like they might want to do something about that just for comments.
You don't say "a car ran over someone" - it was the driver. Here's similar.
I'm really disgusted by this language of lack of responsibility
Of course they still have to be careful with their runs.
If you're testing a gun, you don't point it at random people on the street and threaten them. You go to a shooting range.
How to tell the public you didn't bother to read the article, or the linked AISI report.
Oh that's sneaky