The new guidance actually focuses on three main areas of AI data security: data drift and potentially poisoned data, and also risks in the data supply chain. The guidance builds upon the NSA’s existing Deploying AI Systems Securely publication, but adds much more detail specific to addressing potential vulnerabilities.
A significant data breach at Legal Aid Agency exposed over 2 million records, including criminal records and financial information of people who applied for legal assistance since 2010.
A major threat actor has been crippled by an international law enforcement action, as the Lumma infostealer malware operation saw its control panel seized along with infrastructure dwelling in Europe and Japan. This was supplemented by Microsoft seizing some 2,300 domains belonging to the group, which has infected over 394,000 Windows computers globally.
Victims that interacted with the fake KeePass ads would get a maliciously modified version of the password manager called "KeeLoader" designed to exfiltrate passwords and provide a backdoor for further malware delivery and ransomware attacks.
The Federal Bureau of Investigation (FBI) warns about AI-generated phishing text or deepfake audio messages impersonating senior U.S. officials targeting current and former state and federal officials and their contacts.
The emergence of Venice.ai AI chatbot may mark the beginning of a new stage of the security race. Available for free via the "clear web," the service promises capabilities on par with ChatGPT and other popular models but with no guardrails or security restrictions in place.
Largest U.S. steel manufacturer Nucor Corporation suffered a cyber attack, forcing it to shut down certain IT systems, disrupting operations across several facilities.
French luxury giant Dior suffered a cyber attack that resulted in a data breach in numerous countries after unauthorized individuals accessed its information systems.
Temu is facing a ₩1.37 billion ($982,420) fine in South Korea over its data transfers to other countries. The privacy law violations are due to failure to adhere to the terms of the PIPA, the law of the land that saw significant amendments come into force in 2023 that put it roughly on par with the protections provided by the GDPR.
A ransomware gang that recently hit major UK retailers such as Marks & Spencer with cyber attacks is now setting its sights on US companies, according to a warning from Google's security team.










