OWASP Beefs Up GenAI Security Guidance Amid Growing Deepfakes

November 4, 2024 at 02:40PM Generative AI attacks, including deepfakes, are increasing, with AI-generated text in emails growing to 12%. OWASP published guidance for organizations to strengthen defenses. A deepfake incident during a job interview at Exabeam highlighted vulnerabilities. Experts suggest focusing on tech solutions and robust processes rather than solely training individuals to detect … Read more

Malicious Links, AI-Enabled Tools, and Attacks on SMBs Among Top Cybersecurity Threats in H1 Mimecast Global Threat Intelligence Report

August 21, 2024 at 05:44PM Mimecast’s Global Threat Intelligence Report 2024 H1 highlights emerging cybersecurity threats, including a surge in malicious links and AI-driven attacks, predominantly affecting small businesses. The report also notes an increase in AI-enabled scams targeting both businesses and consumers. Chief Security & Resilience Officer Mick Paisley emphasizes the vital role of … Read more

Fighting AI fire with AI fire

August 7, 2024 at 11:10AM Hackers are leveraging AI to launch sophisticated attacks on unprepared organizations. Employees use generative AI without IT consent, increasing vulnerability. Palo Alto Networks offers insights on leveraging AI to strengthen cyber defense in on-demand videos. CEO Nikesh Arora emphasizes AI’s benefits and risks, while other executives discuss real-time threat combat, … Read more

How to counter adversarial AI

August 1, 2024 at 11:14AM Lee Klarich of Palo Alto Networks emphasizes the increasing threat of AI-powered cyber attacks and the importance of real-time response. The company’s Precision AI technology is integrated across platforms, enabling more efficient threat detection and prevention. Case studies show how AI helps to automate threat detection and response across large … Read more

In Other News: OSS Backdooring Attempts, Botnet Operator Charged, Automotive Firm Attack

April 19, 2024 at 09:48AM SecurityWeek’s cybersecurity news roundup offers a curated selection of significant developments, including incidents of backdooring attempts, increased funding for cybersecurity startups, and vulnerabilities in AI/ML supply chain. Additionally, it reports on legislative developments, cybercriminal activities targeting the automotive industry, and a Moldovan botnet operator’s indictment in the US. Based on … Read more

Google’s Gemini AI Vulnerable to Content Manipulation

March 12, 2024 at 06:03AM Summary: Google’s Gemini large language model (LLM) is found susceptible to attacks that can lead to the generation of harmful content,HiddenLayer researchers manipulate the AI technology to generate election misinformation,detailed instructions on hotwiring a car, and system prompt leakage.They found that Gemini, like other LLMs, is vulnerable to attacks due … Read more

Zero-Click GenAI Worm Spreads Malware, Poisoning Models

March 4, 2024 at 06:02PM A worm known as “Morris II” exploits generative AI (GenAI) apps to propagate malware, stealing information, spreading spam, and more. Israeli researchers demonstrated how adversarial self-replicating prompts can manipulate AI, infecting systems via email and images. This presents a new threat to AI security, similar to injection attacks in computing’s … Read more

A Deepfake Scammed a Bank out of $25M — Now What?

February 9, 2024 at 11:58AM Finance worker in Hong Kong was scammed out of $25 million by deepfake video conference impersonating company’s CFO. Trend Micro previously warned about this type of fraud. Increasing accessibility to deepfake technology and AI-powered fraud is heightening the risk. Organizations need to strengthen processes, collaborations, and defense technology to defend … Read more

Israeli Startup Gets $5M Seed Capital to Tackle AI Security

January 24, 2024 at 11:18AM Israeli company Prompt Security has secured $5 million in seed funding led by Hetz Ventures and backed by Four Rivers and notable CISOs. It aims to prevent sensitive data exposure in generative-AI apps, offering a product to secure AI deployments and prevent exposure of sensitive data, along with governance over … Read more

Nigerian Businesses Face Growing Ransomware-as-a-Service Trade

January 19, 2024 at 06:09AM Ransomware-as-a-service is poised to drive an increase in attacks in Nigeria, impacting both public and private sectors. A Cyber Security Experts of Nigeria (CSEAN) report highlights the impact of ransomware groups and variants in 2023, urging proactive measures such as prompt patching and stronger monitoring practices to mitigate the anticipated … Read more