Secure GenAI
Secure GenAI Podcast
US AI action act, Microsoft Zero day, compromised Github, AI control matrix, selfies breach
0:00
-5:00

US AI action act, Microsoft Zero day, compromised Github, AI control matrix, selfies breach

GenAI Safety & Security | July 21 - July 27, 2025

If you enjoy this newsletter, please become our paid subscriber to help this keep going.

Notice: We have a landing page! Check out at securegenai.github.io

Secure GenAI is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.

Highlights

  • US: AI action act.

  • Microsoft Zero day.

  • Compromised Github Org.

  • AI control matrix.

  • Breach: Selfies and images.

Special!

Secure GenAI is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.


Deep Dive

US: AI Action Plan WhiteHouse

  • 28 page documentation.

  • Three pillars: Accelerate, build, lead.

  • Focus on Open source and Open weight AI.

  • Combat Synthetic Media in the legal System.

  • Promote Secure by Design for tech and app.

Microsoft Zero day SecurityWeek

  • Sharepoint, include Teams and OneDrive.

  • 400 organizations.

  • Mostly in US.

  • Include Nuclear and Health org.

  • Started on 7/7; public actack: 7/18.

Compromised a Github Org BleepingComputer

  • Publish ten malicious package on NPM.

  • Include stealing data to collect authen token.

  • July 20: Hijacked the account.

  • Immediately made public all 73 repositories.

  • Downloaded 5000 times before detected.

AI Control Matrix CSA

  • 243 control objectives, 18 security domains.

  • Including ISO 42001, ISO 27001.

  • NIST AI RMF 1.0, and BSI AIC4.

  • Consensus Assessment Initiative Questionnaire.

  • A self-assessment or an evaluation of third-party vendors.

Breach: Selfies and images CNN

  • Images used for account verification.

  • Data Goldmine for AI attack.

  • Facial recognition spoofing;

  • Bio metric by passing and deepfake.

  • Possibly used for fraud and others.

Thanks for reading Secure GenAI ! This post is public so feel free to share it.

Share

Available: Q2 2025 Report

·
Jul 1
Available: Q2 2025 Report

Here are some top highlights

Notice: Y2 GenAI Safety and Security is on GumRoad and Amazon with paperback.

Discussion about this episode

User's avatar