"'LLM Hijacking' of Cloud Infrastructure Uncovered by Researchers"

"'LLM Hijacking' of Cloud Infrastructure Uncovered by Researchers"

Permiso researchers reported that attackers conducted Large Language Model (LLM) hijacking of cloud infrastructure for generative Artificial Intelligence (AI) to run rogue chatbot services. Permiso detailed attacks targeting Amazon Bedrock environments, which support access to foundational LLMs such as Anthropic's Claude. The company set up a honeypot that showed how hijackers used stolen resources to run jailbroken chatbots. Threat actors use Amazon Web Services (AWS) access keys leaked on platforms like GitHub to communicate with Application Programming Interface (API) endpoints.

Submitted by Gregory Rigby on

"US NRC Publishes Purdue Nuclear Project Report, Led by Stylianos Chatzidakis, on Advancing Nuclear Cybersecurity, as an Official NRC Technical Letter Report"

"US NRC Publishes Purdue Nuclear Project Report, Led by Stylianos Chatzidakis, on Advancing Nuclear Cybersecurity, as an Official NRC Technical Letter Report"

Assistant Professor and Associate PUR-1 Director Stylianos Chatzidakis and a team of researchers from Purdue University's School of Nuclear Engineering conducted a project titled "Characterizing Nuclear Cybersecurity States Using Artificial Intelligence/Machine Learning." Their final report, now an official US Nuclear Regulatory Commission (NRC) Technical Letter Report, delves into the feasibility of AI/ML technologies in characterizing cyber events within nuclear systems.

Submitted by Gregory Rigby on

"DHS: Cybersecurity Is a Top Priority and a Collective Effort"

"DHS: Cybersecurity Is a Top Priority and a Collective Effort"

The Science and Technology Directorate (S&T), the research and development arm of the Department of Homeland Security (DHS), launches Cybersecurity Awareness Month by highlighting its research, development, testing, and evaluation efforts and partnerships. For example, S&T recently launched the "Multi-cloud Analytic Prototyping and Lab Environment" system for the Cybersecurity and Infrastructure Security Agency (CISA). This testbed offers a secure environment where users can access multiple tools through a single login.

Submitted by Gregory Rigby on

"Highline Public Schools Confirms Ransomware Behind Shutdown"

"Highline Public Schools Confirms Ransomware Behind Shutdown"

Recently K-12 school district Highline Public Schools confirmed that a ransomware attack forced it to shut down all schools in early September.  Highline Public Schools has over 2,000 staff members and offers programs ranging from early childhood education to college preparation.  Highline's central office remained open, and staff were instructed to report for work.  The district also started investigating the attack's impact and working to restore systems with help from third-party, state, and federal partners.

Submitted by Adam Ekwall on

"Universal Music Group Admits Data Breach"

"Universal Music Group Admits Data Breach"

Universal Music Group (UMG), one of the world’s largest music corporations, has recently disclosed a data breach that occurred in mid-July 2024. According to the company, the breach may have exposed the personal information of 680 US residents. In the filing, UMG said it detected unauthorized activity in one of its internal applications on July 15, prompting an immediate investigation involving third-party cybersecurity experts.

Submitted by Adam Ekwall on

"AT&T, Verizon Reportedly Hacked to Target US Govt Wiretapping Platform"

"AT&T, Verizon Reportedly Hacked to Target US Govt Wiretapping Platform"

Multiple U.S. broadband providers, including Verizon, AT&T, and Lumen Technologies, have recently announced that they were breached by a Chinese hacking group called Salt Typhoon.  According to researchers, the purpose of the attack is for intelligence collection, as the hackers might have had access to systems used by the U.S. federal government for court-authorized network wiretapping requests.  According to researchers, "for months or longer, the hackers might have held access to network infrastructure used to cooperate with lawful U.S.

Submitted by Adam Ekwall on

ODSC West

"Since 2015, ODSC has been the essential event for AI and data science practitioners, business leaders, and those reskilling into AI. It offers cutting-edge workshops, hands-on training, strategic insights, and thought leadership. Whether deepening technical skills, transforming a business with AI, or pivoting into an AI-driven career, ODSC provides unparalleled opportunities for learning, networking, and professional growth."

ISMG Virtual Government Cybersecurity Summit

"The 2024 ISMG Virtual Government Cybersecurity Summit hosted by GovInfoSecurity will address essential themes pivotal to the future of cybersecurity across both the public and private sectors. A key focus will be the importance of partnerships between government and industry to build cyber resilience through trust-building, information sharing, and enhanced incident response. Additionally, the summit will delve into Russia’s Hybrid Cyber Warfare, analyzing how Russian state-sanctioned groups like Cozy Bear and Lockbit have targeted U.S.

Intel IT Modernization Summit

"The 8th Annual Intel IT Modernization Summit will convene senior level experts, policymakers, and innovators from across the intelligence community, Military services, U.S. government, and industry to highlight advanced technologies and strategies aimed at modernizing IT infrastructure to ensure robust intelligence capabilities. The 2024 Summit will highlight current and future strategies and collaborations to drive transformation of the DoD and the IC’s digital landscape through innovative IT solutions."

"So Far, Cybercriminals Appear to Be Just Shopping Around for a Telegram Alternative"

"So Far, Cybercriminals Appear to Be Just Shopping Around for a Telegram Alternative"

Intel 471 researchers say most cybercriminals may stay with Telegram despite the app becoming less friendly for them. According to Intel 471, several hacker seemed have had plans to switch platforms after Telegram founder Pavel Durov's arrest and pledge to fight illegal activity on the app. Due to its convenience and reach, the researchers believe most cybercriminals who use the app will stay on it.

Submitted by Gregory Rigby on
Subscribe to