Secure GenAI
Secure GenAI Podcast
Oracle breach proof, 23andMe data, Microsoft security agents, NIST framework, US signal group chat.
0:00
-4:40

Oracle breach proof, 23andMe data, Microsoft security agents, NIST framework, US signal group chat.

GenAI Safety & Security | March 25 - March 30, 2025

Highlights

🛡️ Oracle: More proof of breach.
🧬 23andMe: Bankruptcy vs. user data.
🤖 Microsoft: Security Agents launched.
📜 NIST: AI security framework updated.
📱 US: Signal group chat leak.

Upcoming: Q1 2025 on March 31st.

Notice: New book is on GumRoad and Amazon with paperback.

Secure GenAI is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.

Deep Dive:

🛡️Oracle: more breach Bleeping computer

  • Oracle Health/ Cloud, acquired in 2022.

  • Not yet public disclosed.

  • First notice: Feb 20 2025.

  • No clear motivation.

  • Questioned by media but no answer.

Heads Up: Rotate Oracle Cloud credential.

Related: Oracle cloud breach?

🧬23andMe: user data The Record

  • Filed Chapter 11 bankruptcy.

  • Suffered 6M+ data breach.

  • Agreed $30M class action.

  • No control of data after sales.

  • Customer genetic data potentially vulnerable.

Heads Up: Delete 23andMe genetic data due to bankruptcy sale risks.

Related: 23andMe settlement.

🤖 Microsoft: Security Agents The Verge

  • Launched 6 new AI agents.

  • Preview available in 19th April.

  • Agents automate security tasks.

  • Enable third party agents.

  • Analyze breach or root cause.

Heads Up: The big next step after copilot.

📜AI security framework updated NIST

  • New AML taxonomy released.

  • Covers predictive, generative AI.

  • Addresses ML lifecycle stages.

  • Defines attacker goals, capabilities.

  • Includes mitigation methods overview.

Heads Up: Update this guideline to help your org move faster.

📱US: Signal group chat leak CBS News

  • Sensitive Israeli intelligence leaked.

  • Human source likely compromised.

  • Trump officials involved chat.

  • Debate about definition of sensitive info.

  • Concern about cybersecurity/OpSec protocols.

Heads Up: Review our sec protocol for both human and tech. Also please treat agent and chatbox as if it’s human

Bonus: All in podcast has a great conversation about this story. Please find SignalGate for more.

Related: Trump was compromised.

Bonus: Facebook data breach

  • Not public confirmed.

  • 2.6B users.

  • email, name, phone.

  • Less 24h post.

Update:

Last week, I am back to Singapore to join an open session of Dr. Li Fei-Fei. Kindly reach out if you are interest until April 2nd.

Thanks for reading Secure GenAI ! This post is public so feel free to share it.

Share

Discussion about this episode

User's avatar