Crying Out Cloud

#9 - The collapse of LAPSUS$ and the risks of AI data poisoning


Listen Later

👀 Here's a sneak peek at today’s episode: 

🔒 Stay ahead of the game! LAPSUS$ Hackers may be making waves. Two members of this notorious group faced consequences in the UK, but shockingly, they continued their hacking activities even while under house arrest.  

🤖 Data Poisoning in AI Training is a growing concern. Hackers can manipulate the data used to train AI models, introducing risks and vulnerabilities. Validating data integrity and randomizing data ingestion times are useful mitigations against this threat.

💻 The WinRAR Vulnerability (CVE-2023-38831)! This flaw was exploited against crypto-traders to infect their devices with malware, but should be considered a low concern for cloud customers unless using virtual desktops.  


Important links:

https://gizmodo.com/hackers-lapsus-uber-nvidia-rockstar-games-microsoft-1850766324 

https://www.bbc.com/news/technology-66549159 

https://www.cisa.gov/resources-tools/resources/review-attacks-associated-lapsus-and-related-threat-groups-executive-summary 

https://www.cisa.gov/sites/default/files/2023-08/CSRB_Lapsus%24_508c.pdf 

https://duo.com/decipher/lapsususd-analysis-finds-need-for-better-iam-mfa-deployments 

https://www.youtube.com/watch?v=h9jf1ikcGyk 

https://arxiv.org/pdf/2302.10149.pdf 

https://www.blackhat.com/us-23/briefings/schedule/#poisoning-web-scale-training-datasets-is-practical-32112 

https://arstechnica.com/security/2023/08/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april/ 

...more
View all episodesView all episodes
Download on the App Store

Crying Out CloudBy Wiz

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

20 ratings


More shows like Crying Out Cloud

View all
Hacked by Hacked

Hacked

184 Listeners

Hanselminutes with Scott Hanselman by Scott Hanselman

Hanselminutes with Scott Hanselman

380 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,002 Listeners

Risky Business by Patrick Gray

Risky Business

374 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

637 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,016 Listeners

The Defender's Advantage Podcast by Mandiant

The Defender's Advantage Podcast

31 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,000 Listeners

Kubernetes Podcast from Google by Abdel Sghiouar, Kaslin Fields

Kubernetes Podcast from Google

181 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Cloud Security Podcast by Cloud Security Podcast Team

Cloud Security Podcast

57 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

134 Listeners

Cloud Security Podcast by Google by Anton Chuvakin

Cloud Security Podcast by Google

40 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

44 Listeners

AI Security Podcast by Kaizenteq Team

AI Security Podcast

4 Listeners