Preloader Image 1

Timely injection attacks threaten AI chatbots and other cybersecurity news to know this month

  • This newsletter roundup brings you important cybersecurity stories from the past month.
  • Top cybersecurity news: UK’s cybersecurity agency warns of timely AI injection attacks; Data breaches continue to increase in 2023; Japan’s cybersecurity agency breached, report shows

1. UK Cyber ​​Security Agency warns of attacks targeting AI chatbots

The UK’s National Cyber ​​Security Center (NCSC) has highlighted the growing risk of chatbots being manipulated by hackers through “injection” attacks. This is when a user creates input that causes the model to behave in an unexpected way, such as creating offensive content or revealing confidential information.

The agency said the current generation of large language models (LLMs) are vulnerable to these types of inputs, which could have worrying consequences. As LLM is increasingly used to pass information to other services and applications, the risk of immediate injection attacks increases.

NCSC has also announced that Ollie Whitehouse will become its new Chief Technology Officer.

To accelerate public-private responses to address the global cybersecurity talent and skills gap, the World Economic Forum’s Cybersecurity Center launched the “Closing the Gap” initiative Network skills”. The initiative builds on the Forum’s extensive research into the future of work and approaches to reskilling across sectors.

This initiative brings together a multi-stakeholder group including industry leaders, government agencies, civil society and academia to create a strategic cybersecurity talent framework and deliver actions helps individuals enter and thrive in the cybersecurity workforce.

Among other things, this initiative aims to:

Raise awareness and share knowledge among C-Suite executives and decision makers about the cybersecurity skills shortage and its economic and security impacts. Identify strategic methods and processes that will help build a sustainable pipeline of cyber talent within organizations, across industries and geographies

The Forum has also partnered with Salesforce, Fortinet and the Global Cyber ​​Alliance to provide free and globally accessible cybersecurity training through its Program Cybersecurity learning center. The platform aims to democratize access to cybersecurity career paths and training 1.16 million individuals spread across continents.

World Economic Forum partner Absa, in collaboration with the Maharishi Institute, has also developed the Absa Cyber ​​Security Academy to target some of the most disadvantaged groups in South Africa.

Read more about our impact

Countries with the most data breaches in Q2 2023

The United States saw more data breaches than any other country in the second quarter of 2023.

Image: Surfshark

2. Data breaches continue to soar in 2023

According to new figures from VPN provider Surfshark, the number of data breaches worldwide increased by 156% from Q1 to Q2 2023.

A total of 110.8 million accounts were leaked in the second quarter of this year, equivalent to 855 accounts every minute.

Nearly half of these breaches were from accounts originating from the US, while Russia, Spain, France and Turkey made up the remainder of the top five most breached countries.

According to a new report from IBM, the global average cost of a data breach has increased 15% over the past three years. Data costs due to 2023 breach revealed that 51% of organizations plan to improve their cybersecurity as a result of a breach.

3. News Brief: Top cybersecurity stories this month

Japan’s National Cyber ​​Defense Agency has been breached by hackers who may have accessed information for up to nine months. Financial Times report. The attack on Japan’s National Cybersecurity Incident Readiness and Strategy Center began last fall, with Chinese state-backed hackers believed to be behind the attack This.

Microsoft says basic cyber hygiene still protects against 98% of attacks. The minimum standards that every organization should adopt are: requiring anti-phishing multi-factor authentication; apply the principle of zero trust; use up-to-date anti-malware tools; stay up to date with system and software updates; and data protection.

The bonuses of top corporate executives are increasingly tied to cybersecurity metrics. It’s part of a trend toward cybersecurity as a top concern, with companies including Johnson & Johnson and the London Stock Exchange Group among those attaching a portion of their bonuses to the goal. network in 2022.

The Five Eyes intelligence alliance has detailed how Russian state-sponsored Sandworm hackers are using Android malware called Infamous Chisel to attack Ukrainian soldiers’ devices, scan files, monitor traffic Access and steal sensitive information.

Microsoft has identified seven emerging hybrid warfare trends from Russia’s cyber war with Ukraine. These include weaponizing pacifism by amplifying discontent about war and stoking fears of World War III. Other tactics include demonizing refugees and mobilizing nationalism.

A cybercriminal couple has pleaded guilty to trying to launder $4.5 billion in Bitcoin stolen in a hack in 2016. Heather Morgan and Ilya Lichtenstein were arrested last year after police sought the money . Before his arrest, Morgan released a series of rap videos under the name Razzlekhan.

4. More information on cybersecurity in the Agenda

The World Economic Forum’s Global Alliance for Digital Safety has created a foundational language to identify online harms. The goal is to create a common language to describe online harm so that regulators and technology companies can better collaborate to tackle it.

Consolidating cybersecurity tools, testing, and strengthening resilience measures are among seven steps companies can take to control cybersecurity spending without compromising its effectiveness.

Paul Swartz and Francois Candelon of the BCG Henderson Institute argue that we need to be realistic about the impact of general AI. They say the impact of technology on productivity growth has been consistently overstated and that analysts may repeat that mistake with generative AI.

#Timely #injection #attacks #threaten #chatbots #cybersecurity #news #month

Written By

Leave a Reply

Leave a Reply

Your email address will not be published. Required fields are marked *