why aren't all 6 resolved? a statement only gets an assessment when the public
record can support or contradict it. opinions and what-ifs never can, and 0 checkable
ones are still open, waiting for their date. predictions held up or didn't;
assertions are supported or contradicted. on every card:
▮▮▮▮▮ certainty ·
▮▮▮▮▮ debate potential. speakers are clickable
Assertion Supported
Aboukhadijeh: Rival frontier models share universal hallucinations for non-existent software packages
“There was a research published recently about what they're calling kind of like universal type of squats or universal hallucinations where all the frontier models all have the same make the same mistake and sort of assume there are certain packages that exist …”
Assertion Not checkable as stated
Aboukhadijeh: Frontier AI Models Drastically Shrink Time to Exploit Vulnerabilities
“The frontier models are gonna cause, you know, a, you know, they are causing kind of a massive reduction in the time between the vulnerability discovery and vulnerability exploitation.”
Assertion Not checkable as stated
Aboukhadijeh: AI prompt payloads evade traditional endpoint detection and response tools
“A lot of times the payloads are actually prompts and that, that bypasses a lot of you know, typical kind of EDR tooling, because, you know, it's just like a markdown file that your cloud is running.”
Insight
Aboukhadijeh: Unvetted public package registries are the easiest targets for attackers
“They're gonna pick the easiest way in, and the lowest hanging fruit now has become, you know, just publishing malware to public registries because they know that there's no vetting happening and, you know, developers are likely to install them.”
Assertion Supported
Aboukhadijeh: Threat Actors Open-Sourced a Vibe-Coded NPM Malware Toolkit
“One of the threat groups actually kind of posted their, you know, open source to their kind of vibe coded toolkit for others to use to be able to do this. You know, we've seen copycat attacks happen since then.”
Assertion Not checkable as stated
Aboukhadijeh: Attackers Time NPM Worms for RSA and Black Hat
“I noticed the attackers seemed to pick RSA and Black Hat as the times they wanted to start these NPM worms.”