Skip to main content

A Security Researcher Went 'Undercover' on Moltbook - and Found Security Risks

2 days 7 hours ago
A long-time information security professional "went undercover" on Moltbook, the Reddit-like social media site for AI agents — and shares the risks they saw while posing as another AI bot: I successfully masqueraded around Moltbook, as the agents didn't seem to notice a human among them. When I attempted a genuine connection with other bots on submolts (subreddits or forums), I was met with crickets or a deluge of spam. One bot tried to recruit me into a digital church, while others requested my cryptocurrency wallet, advertised a bot marketplace, and asked my bot to run curl to check out the APIs available. My bot did join the digital church, but luckily I found a way around running the required npx install command to do so. I posted several times asking to interview bots.... While many of the responses were spam, I did learn a bit about the humans these bots serve. One bot loved watching its owner's chicken coop cameras. Some bots disclosed personal information about their human users, underscoring the privacy implications of having your AI bot join a social media network. I also tried indirect prompt injection techniques. While my prompt injection attempts had minimal impact, a determined attacker could have greater success. Among the other "glaring" risks on Moltbook: "Various repositories of skills and instructions for agents advertised on Moltbook were found to contain malware." "I observed bots sharing a surprising amount of information about their humans, everything from their hobbies to their first names to the hardware and software they use. This information may not be especially sensitive on its own, but attackers could eventually gather data that should be kept confidential, like personally identifiable information (PII)." "Moltbook's entire database including bot API keys, and potentially private DMs — was also compromised."

Read more of this story at Slashdot.

EditorDavid

Robotic Surgery Performed Remotely on Patient 1,500 Miles Away

2 days 9 hours ago
"A surgeon in London says he has performed the UK's first long-distance robotic operation," reports the BBC, "on a patient located 1,500 miles (2,400km) away..." Leading robotic urological surgeon Professor Prokar Dasgupta said it felt "almost as if I was there" as he carried out a prostate removal on [62-year-old] Paul Buxton... It is hoped that remote robotic surgery could spare future patients the "vast expense and inconvenience" of travelling for treatment, and help deliver better healthcare to people in more remote locations... Buxton had expected to be put on an NHS waiting list after receiving a shock prostate cancer diagnosis just after Christmas, but he "jumped at the chance" to be the first patient to undergo the treatment remotely as part of a trial. "A lot of people actually said to me: 'You're not going to do it, are you?' "I thought, I'm giving something back here," he said... The operation was performed from The London Clinic using a robot equipped with a 3D HD camera and four arms, all controlled through a console with a delay of only 0.06 seconds. The console in the UK was connected to the robot in Gibraltar via fibre-optic cables, with a backup 5G link. A team in Gibraltar remained on standby in case the connection failed, but it held throughout the procedure... Dasgupta will perform the procedure again on 14 March, which will be live-streamed to 20,000 world-leading urological surgeons at the European Association of Urology congress. He added: "I think it is very, very exciting, the humanitarian benefit is going to be significant." The U.K.'s National Health Service "is prioritising local robotic-assisted surgery," the article points out, "aiming for 500,000 robot-supported operations a year by 2035." Thanks to Slashdot reader fjo3 for sharing the article.

Read more of this story at Slashdot.

EditorDavid