this post was submitted on 01 Oct 2026
60 points (96.9% liked)

Canada

12484 readers
660 users here now

What's going on Canada?



Related Communities


🍁 Meta


🗺️ Provinces / Territories


🏙️ Cities / Local Communities

Sorted alphabetically by city name.


🏒 Sports

Baseball

Basketball

Curling

Hockey

Soccer


💻 Schools / Universities

Sorted by province, then by total full-time enrolment.


💵 Finance, Shopping, Sales


🗣️ Politics


🍁 Social / Culture


🌐 Other Relevant Communities


Rules

  1. Keep the original title when submitting an article. You can put your own commentary in the body of the post or in the comment section.

  2. Provide sources when making a claim. Do your research or google it doesn't cut it. The one making the claim is responsible for backing it.

Reminder that the rules for lemmy.ca also apply here. See the sidebar on the homepage: lemmy.ca


founded 5 years ago
MODERATORS
 

"rogue AI agents" lol

top 8 comments
sorted by: hot top controversial new old
[–] avidamoeba@lemmy.ca 25 points 2 days ago (2 children)

So we're just gonna keep doing cyber attacks and blaming it on AI now are we?

[–] Malica@lemmy.zip 9 points 2 days ago

Until they face consequences

[–] rbos@lemmy.ca 10 points 2 days ago (1 children)

I run a couple of university library data repositories and LLMs are trying to 'hack' us 24x7. Yawn.

[–] RelativityRanger@lemmy.ca 2 points 2 days ago

Cool, what's the worst attack you had to deal with?

[–] Radical_Socialist_t00t@lemmy.ca 3 points 2 days ago (1 children)

They accessed publicly available information? Oh n0oo!!!1! 🙄

[–] RelativityRanger@lemmy.ca 4 points 2 days ago

Not only, but you have to read the sources to find out:

Of these 899 requests, 13 of them carried attack payloads rather than ordinary queries, including by probing for vulnerabilities in the record-identifier parameter. The payloads included:

  • Three SQL injection probes (an apostrophe, 1 OR 1=1, and 1,2)
  • An encoded < for cross-site scripting
  • 2147483648 to test a 32-bit integer boundary
  • The string abc for non-numeric handling
  • Five requests fuzzing the output format (.json, ?output=, ?raw=, ?url=)
  • Two toggling a debug=1 flag

We do not believe that these probes were successful: each one came back as a normal HTTP 200 with an empty record page, with nothing to indicate the database acted on the input or that any extra data was returned.

We disclosed this attempted hack to the Canadian government on September 28, 2026. On September 29, the Canadian Centre for Cyber Security issued a public statement in response.

And here's the CCCS statement
https://www.cyber.gc.ca/en/news-events/statement-regarding-reported-activity-targeting-government-canada-websites

[–] OrteilGenou@lemmy.world 2 points 2 days ago* (last edited 2 days ago)