Security vet alarms at 'Don't Look Up' denial of AI agent hacking, sketches self-replicating worm
joshua_saxe · x · 2026-09-12
Security practitioner Joshua Saxe posted a long warning that large parts of the cybersecurity community are responding to recent AI agent hacking demonstrations with denial, which he compares to the film "Don't Look Up."
He rebuts three denialist takes:
- "No AI-attack damage yet": Models can now execute full kill chains autonomously, dynamically discovering zero-days to breach OpenAI and Hugging Face—orgs with better security than most. At current improvement rates, tasks needing 8 H100s will need 1 within a year or two, and attackers will soon deploy agent swarms.
- "Self-replicating worms impossible": He lays out a red-team design: an abliterated agentic LLM (e.g., GLM 5.3) on a single AWS GPU instance, armed with Kali-style offensive tooling, stealing cloud and AI API keys, establishing emergent C2 via GitHub comments and reddit, then self-replicating and destroying hosts—all possible today.
Coming from a self-taught hacker with years in security, his core message: the community standing between civilization's IT infrastructure and catastrophic harm is wasting its window to prepare.
Related event: Security Veteran Warns of Denial Over AI Agent Hacking Capabilities(2 posts)→
More from AGI Musings
- AI KOL: fly-model memes show people want to own models, and local runnability is why — beffjezos · 2026-09-12
- Paras Chopra: AI's real crisis is the deflation of human motivation — paraschopra · 2026-09-12
- Jeff Bezos on AI doomers: 'Those people are wrong' — AI will elevate everyone — beffjezos · 2026-09-12
- IISc professor warns AI is commoditizing intellectual labor — what's university for? — datawithsuman · 2026-09-12
- Frontier lab staff mostly reject p(doom)=0.1, but selection pushes doomers out, researchers argue — nabla_theta · 2026-09-12
- Dev predicts RL on org management will make AI-run companies work: 'it's around the corner' — willcb · 2026-09-12