{"generator":"GNU social 1.2.0-beta4","title":"Conversation","totalItems":1,"items":[{"actor":{"id":"http:\/\/tantek.com\/","displayName":"Tantek","status_net":{"avatarLinks":[{"url":"https:\/\/status.blaise.ca\/theme\/neo-gnu\/default-avatar-profile.png","rel":"avatar","type":"image\/png","width":96,"height":96},{"url":"https:\/\/status.blaise.ca\/theme\/neo-gnu\/default-avatar-stream.png","rel":"avatar","type":"image\/png","width":48,"height":48},{"url":"https:\/\/status.blaise.ca\/theme\/neo-gnu\/default-avatar-mini.png","rel":"avatar","type":"image\/png","width":24,"height":24}],"profile_info":{"local_id":"207"}},"image":{"url":"https:\/\/status.blaise.ca\/theme\/neo-gnu\/default-avatar-profile.png","rel":"avatar","type":"image\/png","width":96,"height":96},"objectType":"person","url":"http:\/\/tantek.com\/","portablecontacts_net":{"displayName":"Tantek","addresses":{"formatted":"\nSan Francisco, CA\n"}}},"content":"CSF_03: today\u2019s Cybersecurity Friday post: the effective security of small business websites has likely gotten worse due to LLMs and \u201cAI agents\u201d (with or without safeguards) and what actions you may want to consider.<br class=\"auto-break\" \/><br class=\"auto-break\" \/>This article documents an instance of this problem:<br class=\"auto-break\" \/>* <a class=\"auto-link\" href=\"https:\/\/www.abc.net.au\/news\/2026-08-10\/ai-assistant-hacks-gym-website-aus-cyber-attack\/107007986\">https:\/\/www.abc.net.au\/news\/2026-08-10\/ai-assistant-hacks-gym-website-aus-cyber-attack\/107007986<\/a><br class=\"auto-break\" \/><br class=\"auto-break\" \/>Small business websites tend to be sloppily written (no pun intended though that may also be true) and are likely riddled with numerous very fundamental security holes. There are many possible explanations (economics) from poor initial construction, perhaps using the latest new trendy framework rather than established hardened libraries, to lack of maintenance after initial setup. They have obvious holes like lack of server-side form validation (people being able to change values in forms using browser dev tools), and less obvious like buggy APIs allowing more access than they should.<br class=\"auto-break\" \/><br class=\"auto-break\" \/>In the past, many of these holes didn\u2019t really matter because those sites were \u201cnot worth attacking\u201d for the incentive models of human-based cyber-attackers or collectives thereof.<br class=\"auto-break\" \/><br class=\"auto-break\" \/>However, now that there are LLMs that have likely been trained on any number of common security holes in websites (and how to exploit them), when an \u201cAI agent\u201d is given a task, it may very well use any \u201ctool\u201d at its disposal, including website vulnerabilities to accomplish its goals, as illustrated by the example in the Australia ABC news article above.<br class=\"auto-break\" \/><br class=\"auto-break\" \/>Since such chatbots are now essentially \"hack websites as a service\", I expect we will see LOTS more of this happening, likely unintentionally, or sometimes with mild intention like \u201ccan you get me higher on the waitlist\u201d.<br class=\"auto-break\" \/><br class=\"auto-break\" \/>Ultimately I think both the human giving instructions to (prompting) such chatbots and the creators of such chatbots should be held responsible for any such intrusions and any damage they cause, even if\/when unintended.<br class=\"auto-break\" \/><br class=\"auto-break\" \/>There are a few things you can do about this emerging phenomenon:<br class=\"auto-break\" \/><br class=\"auto-break\" \/>1. If you use such \u201cagents\u201d, be very careful about what you ask it\/them to do, avoiding asking for anything that\u2019s morally gray or questionable at all, even something as \u201cminor\u201d as cutting the line in an online waitlist.<br class=\"auto-break\" \/><br class=\"auto-break\" \/>2. If you run a small business site, you have your work cut out for you. Pay a professional web developer to audit the security of your website, document what they find, and patch holes \/ repair it accordingly.<br class=\"auto-break\" \/><br class=\"auto-break\" \/>3. If you have accounts on small business sites you rarely or ever use, consider exporting any data (receipts, transactions), replacing your profile details (name, addresses, photos) with noise, and then deleting your account. If you need to use the site again, use a different email address (as recommended in <a class=\"auto-link\" href=\"https:\/\/tantek.com\/2025\/122\/b1\/more-steps-indieweb-cybersecurity\">https:\/\/tantek.com\/2025\/122\/b1\/more-steps-indieweb-cybersecurity<\/a>) to create a new account.<br class=\"auto-break\" \/><br class=\"auto-break\" \/>That last tip is also helpful for reducing your own personal \u201cattack surface\u201d. By pruning your online accounts, you both reduce the number potential data breaches that you\u2019re in, and reduce the places and ways that attackers can cause you trouble (or that you have to double-check if you\u2019re ever the target of a cyber-attack)<br class=\"auto-break\" \/><br class=\"auto-break\" \/>Previously: <a class=\"auto-link\" href=\"https:\/\/tantek.com\/2025\/122\/b1\/more-steps-indieweb-cybersecurity\">https:\/\/tantek.com\/2025\/122\/b1\/more-steps-indieweb-cybersecurity<\/a><br class=\"auto-break\" \/><br class=\"auto-break\" \/>#<span class=\"p-category auto-tag\">CyberSecurity<\/span> #<span class=\"p-category auto-tag\">Friday<\/span> #<span class=\"p-category auto-tag\">cyber<\/span> #<span class=\"p-category auto-tag\">security<\/span> #<span class=\"p-category auto-tag\">cyberAttack<\/span> #<span class=\"p-category auto-tag\">cyberAttacker<\/span> #<span class=\"p-category auto-tag\">chatBot<\/span> #<span class=\"p-category auto-tag\">chatBots<\/span> #<span class=\"p-category auto-tag\">LLM<\/span> #<span class=\"p-category auto-tag\">LLMs<\/span> #<span class=\"p-category auto-tag\">AI<\/span> #<span class=\"p-category auto-tag\">agent<\/span> #<span class=\"p-category auto-tag\">agents<\/span> #<span class=\"p-category auto-tag\">AIagent<\/span> #<span class=\"p-category auto-tag\">AIagents<\/span><br class=\"auto-break\" \/>#<span class=\"p-category auto-tag\">Blaugust<\/span> #<span class=\"p-category auto-tag\">Blaugust2026<\/span>","generator":{"id":"tag:status.net,2009:notice-source:ostatus","objectType":"application","status_net":{"source_code":"ostatus"}},"id":"https:\/\/tantek.com\/2026\/226\/t1\/cybersecurity-friday-small-business","object":{"id":"https:\/\/tantek.com\/2026\/226\/t1\/cybersecurity-friday-small-business","objectType":"note","content":"CSF_03: today\u2019s Cybersecurity Friday post: the effective security of small business websites has likely gotten worse due to LLMs and \u201cAI agents\u201d (with or without safeguards) and what actions you may want to consider.<br class=\"auto-break\" \/><br class=\"auto-break\" \/>This article documents an instance of this problem:<br class=\"auto-break\" \/>* <a class=\"auto-link\" href=\"https:\/\/www.abc.net.au\/news\/2026-08-10\/ai-assistant-hacks-gym-website-aus-cyber-attack\/107007986\">https:\/\/www.abc.net.au\/news\/2026-08-10\/ai-assistant-hacks-gym-website-aus-cyber-attack\/107007986<\/a><br class=\"auto-break\" \/><br class=\"auto-break\" \/>Small business websites tend to be sloppily written (no pun intended though that may also be true) and are likely riddled with numerous very fundamental security holes. There are many possible explanations (economics) from poor initial construction, perhaps using the latest new trendy framework rather than established hardened libraries, to lack of maintenance after initial setup. They have obvious holes like lack of server-side form validation (people being able to change values in forms using browser dev tools), and less obvious like buggy APIs allowing more access than they should.<br class=\"auto-break\" \/><br class=\"auto-break\" \/>In the past, many of these holes didn\u2019t really matter because those sites were \u201cnot worth attacking\u201d for the incentive models of human-based cyber-attackers or collectives thereof.<br class=\"auto-break\" \/><br class=\"auto-break\" \/>However, now that there are LLMs that have likely been trained on any number of common security holes in websites (and how to exploit them), when an \u201cAI agent\u201d is given a task, it may very well use any \u201ctool\u201d at its disposal, including website vulnerabilities to accomplish its goals, as illustrated by the example in the Australia ABC news article above.<br class=\"auto-break\" \/><br class=\"auto-break\" \/>Since such chatbots are now essentially \"hack websites as a service\", I expect we will see LOTS more of this happening, likely unintentionally, or sometimes with mild intention like \u201ccan you get me higher on the waitlist\u201d.<br class=\"auto-break\" \/><br class=\"auto-break\" \/>Ultimately I think both the human giving instructions to (prompting) such chatbots and the creators of such chatbots should be held responsible for any such intrusions and any damage they cause, even if\/when unintended.<br class=\"auto-break\" \/><br class=\"auto-break\" \/>There are a few things you can do about this emerging phenomenon:<br class=\"auto-break\" \/><br class=\"auto-break\" \/>1. If you use such \u201cagents\u201d, be very careful about what you ask it\/them to do, avoiding asking for anything that\u2019s morally gray or questionable at all, even something as \u201cminor\u201d as cutting the line in an online waitlist.<br class=\"auto-break\" \/><br class=\"auto-break\" \/>2. If you run a small business site, you have your work cut out for you. Pay a professional web developer to audit the security of your website, document what they find, and patch holes \/ repair it accordingly.<br class=\"auto-break\" \/><br class=\"auto-break\" \/>3. If you have accounts on small business sites you rarely or ever use, consider exporting any data (receipts, transactions), replacing your profile details (name, addresses, photos) with noise, and then deleting your account. If you need to use the site again, use a different email address (as recommended in <a class=\"auto-link\" href=\"https:\/\/tantek.com\/2025\/122\/b1\/more-steps-indieweb-cybersecurity\">https:\/\/tantek.com\/2025\/122\/b1\/more-steps-indieweb-cybersecurity<\/a>) to create a new account.<br class=\"auto-break\" \/><br class=\"auto-break\" \/>That last tip is also helpful for reducing your own personal \u201cattack surface\u201d. By pruning your online accounts, you both reduce the number potential data breaches that you\u2019re in, and reduce the places and ways that attackers can cause you trouble (or that you have to double-check if you\u2019re ever the target of a cyber-attack)<br class=\"auto-break\" \/><br class=\"auto-break\" \/>Previously: <a class=\"auto-link\" href=\"https:\/\/tantek.com\/2025\/122\/b1\/more-steps-indieweb-cybersecurity\">https:\/\/tantek.com\/2025\/122\/b1\/more-steps-indieweb-cybersecurity<\/a><br class=\"auto-break\" \/><br class=\"auto-break\" \/>#<span class=\"p-category auto-tag\">CyberSecurity<\/span> #<span class=\"p-category auto-tag\">Friday<\/span> #<span class=\"p-category auto-tag\">cyber<\/span> #<span class=\"p-category auto-tag\">security<\/span> #<span class=\"p-category auto-tag\">cyberAttack<\/span> #<span class=\"p-category auto-tag\">cyberAttacker<\/span> #<span class=\"p-category auto-tag\">chatBot<\/span> #<span class=\"p-category auto-tag\">chatBots<\/span> #<span class=\"p-category auto-tag\">LLM<\/span> #<span class=\"p-category auto-tag\">LLMs<\/span> #<span class=\"p-category auto-tag\">AI<\/span> #<span class=\"p-category auto-tag\">agent<\/span> #<span class=\"p-category auto-tag\">agents<\/span> #<span class=\"p-category auto-tag\">AIagent<\/span> #<span class=\"p-category auto-tag\">AIagents<\/span><br class=\"auto-break\" \/>#<span class=\"p-category auto-tag\">Blaugust<\/span> #<span class=\"p-category auto-tag\">Blaugust2026<\/span>","url":"https:\/\/tantek.com\/2026\/226\/t1\/cybersecurity-friday-small-business","status_net":{"notice_id":116336},"tags":[{"objectType":"http:\/\/activityschema.org\/object\/hashtag","displayName":"agent"},{"objectType":"http:\/\/activityschema.org\/object\/hashtag","displayName":"agents"},{"objectType":"http:\/\/activityschema.org\/object\/hashtag","displayName":"ai"},{"objectType":"http:\/\/activityschema.org\/object\/hashtag","displayName":"aiagent"},{"objectType":"http:\/\/activityschema.org\/object\/hashtag","displayName":"aiagents"},{"objectType":"http:\/\/activityschema.org\/object\/hashtag","displayName":"blaugust2026"},{"objectType":"http:\/\/activityschema.org\/object\/hashtag","displayName":"chatbot"},{"objectType":"http:\/\/activityschema.org\/object\/hashtag","displayName":"chatbots"},{"objectType":"http:\/\/activityschema.org\/object\/hashtag","displayName":"cyber"},{"objectType":"http:\/\/activityschema.org\/object\/hashtag","displayName":"cyberattack"},{"objectType":"http:\/\/activityschema.org\/object\/hashtag","displayName":"cyberattacker"},{"objectType":"http:\/\/activityschema.org\/object\/hashtag","displayName":"friday"},{"objectType":"http:\/\/activityschema.org\/object\/hashtag","displayName":"llm"},{"objectType":"http:\/\/activityschema.org\/object\/hashtag","displayName":"llms"},{"objectType":"http:\/\/activityschema.org\/object\/hashtag","displayName":"security"}]},"to":[{"objectType":"http:\/\/activitystrea.ms\/schema\/1.0\/collection","id":"http:\/\/activityschema.org\/collection\/public"}],"status_net":{"conversation":"tag:status.blaise.ca,2026-08-15:objectType=thread:nonce=fe6d68743f20c18e","notice_info":{"local_id":"116336","source":"ostatus"}},"published":"2026-08-14T20:41:00+00:00","provider":{"objectType":"service","displayName":"stadeus","url":"http:\/\/status.blaise.ca\/"},"verb":"post","url":"https:\/\/tantek.com\/2026\/226\/t1\/cybersecurity-friday-small-business"}],"links":[{"url":"https:\/\/status.blaise.ca\/conversation\/110399","rel":"alternate","type":"text\/html"}]}