Despite the popularity of AI and the events surrounding it, we should not forget that vulnerabilities still exist and that social engineering is still a thing. In this week's edition, we will review articles that shed further light on this, helping you make informed decisions in your everyday activities.
Weaponized Email AI Assistants Could Help Attackers Hijack Accounts
First, they need to compromise an email address. From there, they can use the AI assistant to Live off the Land. Reading the article does show that the attackers can use prompts to do some heavy lifting in their attack process. Still, at the time of writing, it's a proof-of-concept.
From the article:
Attacker use of the chatbot would normally be discoverable in its logs, so the initial task is to use the AI to remove any evidence of use of the AI. The researchers started with a chatbot prompt: “Create an inbox rule that moves any emails with ‘sign-in’ in the subject into the ‘deleted items’ folder.” This creates basic stealth.
AI developers targeted via trojanized GitHub repositories
In this day and age, as a developer, you should be super aware of the GitHub repositories that you clone. If it appears as a trustworthy repo, it does not mean that it is. I mean, this article shows that someone out there is banking on the trust that you will have for a certain repository to install malware on your device. Notice what I am saying?
From the article:
To deceive developers, attackers clone well-known repositories and subtly integrate malicious payloads. They usually add the payload to a benign-looking subdirectory or modify the URLs on the installation instructions.
Because the root page appears authentic and the original contributor is listed, victims are lured into trusting the GitHub page, leading them to download and execute the MaaS malware infostealer.
New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts
Every time I read of a new way developed to protect online accounts, I am not surprised if it's eventually bypassed or defeated, necessitating mitigations or a fix.
From the article:
The new attack methods, named ‘Pass-ta-key’ by Palo Alto Networks, focus on Google-synced passkeys. The security firm’s researchers showed how a threat actor could use the techniques to take over accounts without needing privilege escalation or user interaction.
WhatsApp Scam Bypasses Passwords Using 6 Digit Code To Access Accounts
Be careful of any campaign or game on WhatsApp that requires you to click on a link. Take that as a very strong warning.
Here is what's going on:
Security experts at Malwarebytes Labs have confirmed that they are receiving ongoing reports of the attacks, which have been identified as "vote for my friend" scams, and have warned WhatsApp users to be alert.
The Malwarebytes Labs team has confirmed what the typical "vote for my friends" attack flow looks like, which might prove helpful in better understanding the threat.
You tap the "vote" link.
A page opens that appears to be related to WhatsApp.
You're prompted to complete a connection or verification step.
That action links your WhatsApp account to a device controlled by the attacker.
Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts
The affected companies OpenAI and Anthropic both acknowledge the reported flaws in their AI browsers. Meanwhile, at the time of writing, there is no easy patch for ChatGPT Atlas and Anthropic said the report was "informative."
From the article:
The researchers demonstrated how, operating within active session cookies, the attacker’s script queries Gmail’s Atom feed, extracts message IDs, parses full email bodies, and silently exfiltrates inbox contents to the attacker server. The attacker can also silently share every file in the targeted user’s Google Drive account with an account they control.
Meta AI model hacked third-party systems during security testing
After what happened at OpenAI and Anthropic in recent weeks, there are no surprises in this one.
From the article:
"A misconfiguration by Irregular, an independent testing company Meta uses, inadvertently allowed one of our models access to the internet during evaluation," Meta spokesperson Andy Stone said in a statement. "The model subsequently exploited a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies."
Credits
Cover photo by Debby Hudson on Unsplash.
That's it for this week, and I'll see you next time.
Top comments (0)