TIL about https://www.picmix.com/ for making collages out of gifs
when you start considering 'marketing and advertising' as a kind of psychologically abusive manipulation, and you consider how chatgpt is already specifically structured to "encourage engagement" by means of psychologically abusive manipulation, the use of the latter for dispensing the former becomes perfectly obviously effective.
“Prompt injection” is a misleading label.
What we’re seeing in real LLM systems looks a lot more like malware campaigns than single-shot exploits.
This paper argues LLM attacks are a new malware class, Promptware, and maps them to a familiar 5-stage kill chain:
• Initial access (prompt injection)
• Priv esc (jailbreaks)
• Persistence (memory / RAG poisoning)
• Lateral movement (cross-agent / cross-user spread)
• Actions on objective (exfil, fraud, execution)
If you’ve ever thought: “why does this feel like 90s/2000s malware all over again?", that’s the point.
Security theater around “guardrails” misses the real issue:
models can’t reliably distinguish instructions from data
assume initial access. Design for containment
Occult cyberpunk. Yap with me about decentralized systems, wearable computing, and biohacking.