720-891-1663

11.07.25 Security News Bites

Brooke Schinault called St. Petersburg police on October 7th to report a stranger breaking into her house. While she didn’t know the person, she provided a photo of the suspect sitting on her couch. As the investigation continued, she remembered that the suspect sexually assaulted her. But the cops figured out that the picture was generated by ChatGPT. Ooops. She has been charged and arrested. Multiple police departments are reporting similar incidents. Credit: Cybernews

Claimpix is a vendor to the insurance and automaker industries (among others) to automate processing. Except they leaked 5 million files which includes vehicle registrations, customers’ private information, VINs and other sensitive information. They did shut it down once contacted, but that doesn’t mean that others didn’t download it first. Who would get sued in a breach is their customer (you) since the end user does not have a legal relationship with Claimpix. If you need assistance setting up a vendor risk management program, contact us. Credit: Hackread

Want to use their in car navigation system – pay $15 a month. Want to use their music streaming service? That is another $15. Or $25 a month for the two. This is not as bad as BMW’s cancelled idea to charge you a monthly fee to turn on the heated seats already in your car. In fairness, at least this are information services that they have to run. Want to see the oil level and tire pressure? That will be $8 a month. But it is convenient to do all of this through the screen already in your car instead of your phone (I don’t think you can get your oil level on your phone, but navigation, sure). Another source of revenue since fewer people are buying cars. Credit: Axle Addict

The president allowed Microsoft to ship 60,400 Nvidia A100 GPUs to the UAE as part of a massive AI data center project in spite of the UAE being a “complex partner” because they are not particularly democratic. Microsoft is not alone. Cisco, Nvidia, OpenAI, Oracle and Softbank announced plans and started building a 5 gigawatt AI campus in the UAE. One gigawatt can host a data center with a million GPUs. Microsoft plans to invest $15 billion in the UAE by 2029. Whether the UAE will stop China from getting access to US tech and data center capacity is unclear and the controls have not been publicly released, so who knows. Credit: Dark Reading

A ClickFix attack is one that tricks a user into installing malware on their computer under the guise of “fixing” a problem by installing a “fix”. This technique defeats most security checks because the user is interactively installing the malware. Until recently, it was a Windows only trick but now we are seeing very sophisticated Mac versions of the technique and it seems to work as well there. Don’t be fooled. More details at the link. Credit: Security Week

Facebooktwitterredditlinkedinmailby feather

Leave a Reply

Your email address will not be published. Required fields are marked *