Greg Young
1.4K posts

Greg Young
@orangeklaxon
30+ yrs cybersec VP Cybersecurity @TrendMicro Fmr Gartner analyst, CISO, army officer & Airwolf extra. Tweets are mine. Make yer stuff secure, k?


China's biggest cybersecurity company apparently just shipped an AI assistant with its own SSL private key sitting inside the installer. Qihoo 360, think Norton or McAfee, but dominant across the entire Chinese market It appears that their new AI product, 360安全龙虾 (Security Claw) bundles a wrapper on @OpenClaw. Inside the installer package - accessible to anyone who downloaded it - was a private SSL certificate key for the domain *.myclaw.360.cn. An SSL private key is essentially the master password to a website's encrypted connection. With it, an attacker can impersonate 360's servers, silently intercept user traffic, forge a login page that looks completely legitimate, or possibly take over the AI agent altogether. The cert is valid until April 2027 and covers every subdomain on the platform. It's now public. The founder launched the product with a promise it would "never leak passwords". It did that during release? 461 million users, a $10B valuation, and nobody checked the zip file before shipping. The cert expires April 2027.

China's biggest cybersecurity company apparently just shipped an AI assistant with its own SSL private key sitting inside the installer. Qihoo 360, think Norton or McAfee, but dominant across the entire Chinese market It appears that their new AI product, 360安全龙虾 (Security Claw) bundles a wrapper on @OpenClaw. Inside the installer package - accessible to anyone who downloaded it - was a private SSL certificate key for the domain *.myclaw.360.cn. An SSL private key is essentially the master password to a website's encrypted connection. With it, an attacker can impersonate 360's servers, silently intercept user traffic, forge a login page that looks completely legitimate, or possibly take over the AI agent altogether. The cert is valid until April 2027 and covers every subdomain on the platform. It's now public. The founder launched the product with a promise it would "never leak passwords". It did that during release? 461 million users, a $10B valuation, and nobody checked the zip file before shipping. The cert expires April 2027.

❗️One of the godfathers of AI Andrej Karpathy shortly released research showing which jobs are most exposed to AI. He deleted it afterwards, but a backup was found. The brutal pattern: if you work behind a screen, AI is coming for you. If you work with your hands, you’re fine. Higher education = more exposed. Higher salary = more exposed. 143 million jobs analyzed. $3.7 trillion in wages exposed. Every job in the US economy was scored for AI exposure from 0–10. Some examples: Bookkeepers: 9/10 Lawyers: 9/10 Software devs: 8/10 Roofers: 0/10 Carpenters: 2/10 Janitors: 1/10




Holy shit




Sources: Amazon's AI tools caused at least two AWS outages, including a 13-hour disruption in December after its Kiro AI deleted and recreated an environment (@rafeuddin_ / Financial Times) ft.com/content/00c282… #a260220p1" target="_blank" rel="nofollow noopener">techmeme.com/260220/p1#a260…
📥 Send tips! techmeme.com/contact

















