One long sentence is all it takes to make LLMs misbehave
Security researchers from Palo Alto Networks’ Unit 42 have discovered the key to getting large language model (LLM) chatbots to ignore their guardrails, and it’s quite simple. You just have to ensure that your prompt uses terrible grammar and is one massive run-on sentence like this one which includes all the information before any full stop which would give the guardrails a chance to kick in before the jailbreak can take effect and guide the model into providing a “toxic” or otherwise verboten response the developers had hoped would be filtered out. The paper also offers a “logit-gap” analysis approach as a potential benchmark for protecting models against such attacks.
Nevada state websites, phone lines knocked offline by cyberattack
A cyberattack took down systems, websites and phone lines used by the state government of Nevada after an incident on Sunday morning. Nevada governor Joe Lombardo released a statement on Monday afternoon telling the public that emergency services are still available but the network incident “continues to impact the availability of certain state technology systems on the state network.” “Some state websites or phone lines may be slow or briefly unavailable during recovery,” he said.
A hacker used AI to automate an ‘unprecedented’ cybercrime spree, Anthropic says
A hacker has exploited a leading artificial intelligence chatbot to conduct the most comprehensive and lucrative AI cybercriminal operation known to date, using it to do everything from find targets to write ransom notes. In a report published Tuesday, Anthropic, the company behind the popular Claude chatbot, said that an unnamed hacker “used AI to what we believe is an unprecedented degree” to research, hack and extort at least 17 companies.
Detecting and countering misuse of AI: August 2025
We’ve developed sophisticated safety and security measures to prevent the misuse of our AI models. But cybercriminals and other malicious actors are actively attempting to find ways around them. Today, we’re releasing a report that details how. Our Threat Intelligence report discusses several recent examples of Claude being misused, including a large-scale extortion operation using Claude Code, a fraudulent employment scheme from North Korea, and the sale of AI-generated ransomware by a cybercriminal with only basic coding skills. We also cover the steps we’ve taken to detect and counter these abuses.
Ransomware crooks knock Swedish municipalities offline for measly sum of $168K
Sweden’s municipal governments have been knocked offline after ransomware crooks hit IT supplier Miljödata, reportedly demanding the bargain-basement sum of $168,000. Miljödata runs HR, sick leave, and incident reporting systems for approximately 80 percent of Sweden’s municipalities, making it a juicy single point of failure. Over the weekend, those systems went dark, leaving councils from Gotland and Halland to Karlstad and Skellefteå unable to access key services. Miljödata CEO Erik Hallén confirmed on August 25 that the disruption was the result of a cyberattack, stating that the intrusion had affected 200 of Sweden’s 290 municipalities, while local cosp have confirmed that the attackers responsible had demanded, er, 1.5 Bitcoin to keep the data under wraps.