Layered AI Defenses Have Holes: Vulnerabilities and Key Recommendations — LessWrong