Cybersecurity awareness is important. The knowledge of what's out there and how to protect yourself can go a long way to ensure that you don't fall victim to data or credential theft. Also, AI is, arguably, here to stay for a long time. You should know what it can do and what can be done against it. At the end of the day, saving the day might come down to a moment where you say to yourself: Wait, this is a threat because I read about it before.
Hackers abused Claude to extract secrets from 1.8M Android apps
This is not like an attack that you should know. I included this article to let you know what's possible with Artificial Intelligence. Like, it's a good thing in the hands of anyone who intends to do good. Meaning, it's the reverse in the hands of a malicious actor. The latter is what the linked article explains.
For example:
With the help of Claude AI, it took a suspected ShinyHunters threat actor about 34 hours to extract authentication data and get more than 2,100 sets of Azure AD authentication tokens linked to over 40 separate corporate Microsoft tenants. According to Anthropic, "AI agents performed nearly all of the work."
ClickFix attacks are tricking Mac and Windows users into hacking themselves
When I see news that ClickFix attack is still a thing, I am always like: I thought everyone should know about it and not fall victim. Then I read the article, only to discover that the attackers are trying to use a convincing way to get the users to run commands on their machines.
I mean, what's this?
Security researchers now say that the latest ClickFix campaign they’ve seen involved hackers posting fake ads on Reddit, linking to a page that looks like HBO Max but contains a ClickFix lure that tricks people into hacking themselves. The hackers compromised the official HBO Max’s account on Reddit that was then used to post hundreds of fake but real-looking adverts to the news-sharing site
Android's hidden privacy tools caught things I never would have noticed on my own
Are you an Android user? This article explains some settings that can improve your privacy on the device.
For example:
Android has a Privacy dashboard that gives me a quick look at which apps have recently accessed permissions, such as the camera, microphone, and location. This offers context instead of presenting a long list of permissions hidden in Settings. If I find an app using my location too often, I can check its permissions and make changes.
A fake ChatGPT billing email is after your OpenAI password
One of the best ways to steer clear of this attack is to look at the sender's email address.
From the article:
The email arrives from a sender named ChatGPT with the subject line “Urgent: Update Your Payment Method to Avoid Service Interruption.” It carries the ChatGPT logo, a final-notice tag and an outstanding balance of $23.80. It warns that the account may be suspended if billing isn’t fixed within 48 hours, then offers a large green “Update Payment Information” button and signs off as “The OpenAI Team.”
Security Researchers Hacked Into OpenAI Using Anthropic’s Claude
Yes. It's a bug bounty program. Then what's the lesson? What AI is capable of doing and evidence that they are getting better with the release of new models.
From the article:
In their conclusion note, the researchers wrote, "Software has long benefited from a kind of security through complexity…AI is removing that protection by turning more of this scarce expertise into compute. Work that once required a well-resourced team and months of effort can now be compressed into days…Security assumptions must catch up with attacker capabilities."
Credits
Cover photo by Debby Hudson on Unsplash.
That's it for this week, and I'll see you next time.
Top comments (0)