When you go online, staying safe should be your priority. You watch the links that you click, you be careful of the apps that you download and where you download them from, and so on like that. Somethings might be outside your control, e.g., a rogue AI attacking your favorite platform. Nonetheless, be careful of the personal information that you post online because anyone can easily use AI to piece together information that you never thought was out there.
Attackers impersonate popular AI brands to spread malware
I believe any technically oriented person will not fall for these attacks because it involves an InstallFix attack. Then I remembered not everyone is tech savvy, or knows what this attack is all about.
From the article:
In one case, a fake Claude site walked the victim through an mshta command that pulled a payload from a lookalike domain. The download was packaged as a Windows app named “claude” or “claude.msixbundle.”
Once run, it fetched code that executed in memory and tried to hollow out browser processes. Other variants included a booby-trapped Claude Setup.zip archive and a repackaged claude.exe that functioned as a malware loader.
Frontier AI labs still won’t say how they’d contain a rogue model
After the recent events at OpenAI, Meta, and Anthropic, we all need to know how they will do this. And not just figure it out in real-time.
From the article:
To date, most of the plans in place for managing catastrophic risk are still largely left up to the companies. Guidelight’s report says the best public evidence shows that companies have “few containment protocols ready for an emergency.”
There could, of course, be containment plans that companies have in place but haven’t shared publicly.
ToxicPanda Android malware uses VPN permissions to block Google Play
It's another day to learn what malware can do to your device while trying to achieve its aim.
From the article:
The latest version of the malware supports 167 remote commands and phishing overlays for 349 banking, financial, cryptocurrency, and e-wallet applications targeting 16 countries.
It also includes a separate PIN-harvesting module that targets 140 financial and cryptocurrency apps and can dynamically update the target list.
According to the researchers, the app overlays are invisible to the victim,
Inaudible sounds used to fingerprint browsers catch AliExpress red-handed
It was discovered accidentally. The method is outdated. Still, it shows that some websites still choose to track their users without their consent.
Here is what happened:
Researcher Matthew Callaghan said he stumbled on the stealthy tracking by mistake. After loading the AliExpress homepage, audio from his phone stopped playing over his multipoint headphones, which accept connections from more than one device at a time.
He set the headphones to play sounds from his phone except when his PC was producing audio. Each time he loaded AliExpress, the phone audio stopped. Each time he closed the tab the site was loaded into, the phone was once again audible.
INTERPOL crackdown on West African crime rings uncovers troubling new trend
Work and earn your money legitimately. Say no to a life of crime.
From the article:
Interpol says the operation also surfaced a troubling trend. West African crime groups are increasingly using sextortion against minors, some as young as 14.
“Offenders typically contact minors via social media, build trust and coerce them into sharing explicit images or videos. They then threaten to distribute this material to the victim’s contacts unless a ransom is paid,” Interpol stated.
The MFA Identity Trap: When Authentication Creates a False Sense of Security
Who got in might not be the person who should. Just because they passed the MFA check does not mean you should not verify their identity at a later stage when they are in your system.
Here is why:
Suppose an attacker social-engineers a help desk into resetting an employee’s MFA and then enrolls a device under the attacker’s control. The next login may satisfy every authentication requirement. The credentials are correct, and the registered second factor is successfully completed. The authentication succeeded. The identity assurance failed.
AI-assisted reconnaissance: Why everyone could be a viable target for fraud
Be careful of what you post online. If it's not meant to be there, don't put it there. Resist the urge to join the party or feel among. It's not and will never be worth it. Where you are? Keep it private! Having an anniversary? No need to take pictures and put them online? Your kid started walking? No! You got a promotion at your job? Keep it to yourself.
From the article:
The boundary between work and home has become increasingly blurred in recent years, especially as many of us work in a hybrid setup. We might use personal devices and home addresses for corporate activities. And of course, linking our professional and personal social media accounts is a simple task for AI.
All of which means that reconnaissance efforts can have an impact on your professional life.
Credits
Cover photo by Debby Hudson on Unsplash.
That's it for this week, and I'll see you next time.
Top comments (0)