Secure GenAI
Secure GenAI Podcast
Palo Alto Networks, Nearest Neighbor, Microsoft, AI safety taskforce & summit.
0:00
Current time: 0:00 / Total time: -16:18
-16:18

Palo Alto Networks, Nearest Neighbor, Microsoft, AI safety taskforce & summit.

GenAI Safety & Security | Nov 18 - Nov 24, 2024

Highlights:

  • Palo Alto Networks: 2000 firewalls compromised.

  • "Nearest neighbor" WiFi attack revealed.

  • Microsoft enhances Windows security.

  • New AI safety taskforce formed.

  • International AI safety summit held.

Secure GenAI is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.

Deep Dive

1. 2,000 Palo Alto Networks Firewalls Compromised Help Net Security

  • Zero-day vulnerabilities for remote code execution.

  • Compromised devices primarily in US and India.

  • Attackers deployed webshells, exfiltrated data, & deployed cryptominers.

  • Palo Alto Networks Panorama and WildFire appliances also affected.

  • Arctic Wolf observed intrusions across various industries.

Mitigation: Apply security patches and follow remediation guidance.

2. "Nearest Neighbor" WiFi Attack Tom's Hardware

  • Russian hackers accessed a US firm's WiFi outside a physical range.

  • First heard for two different networks to compromised the third one.

  • Attackers leveraged both wired and wireless connections.

Mitigation: Limiting Wireless access point, hiding SSIDs, and mandate MFAs.

3. Microsoft Security Enhancements Cybersecurity Dive

  • Windows Resiliency Initiative allows for off-line Windows Update changes.

  • Safer deployment practices with endpoint security partners are being implemented.

  • Moving away from C++ to Rust for safer programming.

  • New capabilities to create security products outside kernel mode.

  • Available to the Windows Insider Program community starting in early 2025.

  • Initiative follows July Crowdstrike global outage affecting 8.5M devices.

Notice: Stay informed and proactively adopt MS updates.

4. New AI Safety Taskforce (TRAINS) NIST

  • TRAINS focuses on national security implications of AI.

  • Experts from Commerce, Defense, Energy, Homeland Security.

  • Will coordinate AI model research and testing.

  • Aims to maintain US leadership in safe AI development.

  • Operationalizes whole-of-government approach to AI safety.

Mitigation: Monitor progress and recommendations for best practices.

5. International AI Safety Summit TIME

  • Summit brought together experts from 9 nations and the EU.

  • Focus on synthetic content, testing models, and assessments.

  • US and UK AISIs shared findings on model vulnerabilities.

  • $11 million in funding announced for synthetic content risk mitigation.

  • Emphasizes the need for integrating safety with AI innovation.

Notice: The next summit will happen in Paris, France.


Thanks for reading Secure GenAI ! This post is public so feel free to share it.

Share

Discussion about this podcast