Scammers are not sleeping. Attackers are not giving up either. And of course, in the AI landscape, you should be ready to read something new every day. From models going rogue to having their guardrails removed.
Welcome to this week's review. Let's begin.
Vacation Scammers Can Locate You From A Photo—No Geotag Needed
While you are on vacation, resist the urge to post that picture even though you keep telling yourself: What's there? Or, "There is no harm in it." Trust me, there could be because even the details that you overlook might be the thing that's needed to know your location with a high degree of confidence.
The following is what I am talking about:
"What's surprising is that the clues aren't always the obvious ones," says Steve Grobman, chief technology officer for McAfee. "They can be small, everyday details most travelers would overlook, like the architectural style of an otherwise ordinary building, a regional dish on a restaurant menu, the types of plants in the landscape, or the shape of a mountain range in the distance."
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
No surprises on this one. When something is deemed a fake software installer, it's bound to cause harm to your system security.
From the article:
The installers, once launched, deploy malware that's capable of setting up persistence, weakening security protections, and communicating with attacker-controlled infrastructure. The activity has resulted in victims spanning healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.
I’ve been deepfaked: What do I do?
Don't panic. Take the necessary steps to make it difficult for people to search it and if you can contact the company hosting this stuff and tell them to take it down.
Here is how to get started:
If someone has made a deepfake of you that doesn’t qualify as NCII, first save the evidence. That means screenshotting the page or account, saving the URL and making a note of the account or username, the date and time you found it, and any accompanying text. It makes sense not to engage with the person who posted it, or they may disseminate the content even further.
How a lone attacker breached enterprise defenses at AI speed: A 10-hour play-by-play
When I say AI can increase productivity, it's a good thing. But you might not think in this sense. And, here we are. AI is increasing the productivity of attackers. I mean, this would take them weeks and now they can do it in hours. Scary.
From the article:
According to the researchers, by leveraging frontier AI models and automation, the attacker was able to leverage over 50 MITRE ATT&CK techniques in less than 10 hours — no zero-day vulnerability or novel attack method necessary.
To add insult to injury, the threat actor left a report behind, detailing the weaknesses in the organization's security.
Abliteration.ai is making a business out of removing AI guardrails
Everything has its good and bad side. One party believes that by removing guardrails from AI they can perceive the threat. While others believe it can do more harm than good.
From the article:
The company said in a recent social media post that its goal is to enable others to perform “offensive cyber, red-teaming, and agent testing work other models refuse to do.” The logic is familiar in security work: You can’t defend against a behavior you can’t reproduce, and a model that refuses to write working exploit code can’t help a red team defend against attackers. But those same removals make other potentially dangerous tasks easier, too.
Scammers have figured out the best time to text you
And it's scary if you don't already know this. But now that you know, you can protect yourself, or at least watch out.
From the article:
Scam texts peak at 12:00 pm ET, a volume that’s about 874% higher than the quietest hour, 1:00 am ET.
The rate of scam texts also builds through the week. Volume is lowest on Sunday and rises steadily until it peaks on Friday, when people get about 50% more fraudulent texts than at the start of the week. This suggests scammers time their campaigns rather than send messages at random.
'I lost my savings after a job interview scam'
One of the key things that led to the victim falling for this attack is "I don't want this opportunity to pass me by." This can be true when you're searching for a job, and out of nowhere, you get an offer that seems to be what you are looking for. Most will let their guard down, and attackers can know this when there is a report that such a thing is currently going on.
From the article:
Criminals are using the pressure and excitement of job interviews to lure people into downloading booby-trapped mobile applications like a fake Indeed Interview app or one called MyInterview.
According to cyber-security company Malwarebytes, the fake recruiters use lures such as: "Complete your interview by installing the Indeed app" or "salary agreement available after app installation".
Once downloaded the malicious apps allow hackers to access private data for extortion or to use in financial attacks.
Credits
Cover photo by Debby Hudson on Unsplash.
That's it for this week, and I'll see you next time.
Top comments (0)