Governments look at banning ransom payments in face of increasingly sophisticated threats.
Dear Friends and Colleagues, In this issue of the Security & Tech Insights newsletter titled Predicting 2050: The Convergent Power of Emerging Technologies, I offer insights on what our world may technologically appear to be in the not-so-distant future. I compiled much of the content from my prior writings and podcasts and they are my perspectives. I would enjoy your feedback and also what you perceive will impact life as we know it in 2050. Thanks Chuck Brooks.
#tech #ai #quantum #biotech #future #space #computing #artificialintelligence #smartcities #security #cybersecurity
By Chuck Brooks
From normal maintenance to strategic resilience, cyber hygiene is changing. The AI era is incredibly promising. It can enhance government services, healthcare, education, productivity, scientific research, and economic expansion. However, those same technologies are giving cybercriminals previously unheard-of capabilities. Fear is not the answer. It is getting ready.
The easiest, cheapest, and most successful cybersecurity investment is still cyber hygiene. It serves as the cornerstone for the development of trustworthy digital societies when combined with Zero Trust architectures, AI-enabled defense, identity-centric security, ongoing education, governance, and resilience planning.
Cyber hygiene is an ongoing discipline rather than a one-time endeavor. Organizations that regularly practice excellent cyber hygiene will be much better able to protect against new threats, keep consumer trust, and build long-lasting digital resilience in an era of AI, cloud computing, quantum technologies, and hyperconnectivity.
Please check out and subscribe to my LinkedIn newsletter Security & Tech Insights. Nearing 75,000 (free) subscribers. Thanks and have a great weekend! Chuck Brooks.
Link: https://lnkd.in/dA4RbBJZ
In the last year or so, artificial intelligence companies have rolled out a spate of web browsers equipped with AI agents. A user might ask one of these agents to plan a vacation, and it will open browser tabs to research routes and restaurants, then make reservations and add events to the user’s calendar. How well it does any of this varies.
New research from the University of Washington found that the most powerful of these browsers also open users up to significant cybersecurity risks. A UW team studied seven popular agentic browsers and found that four create ways for malicious actors to bypass a fundamental cybersecurity protocol called the “same-origin policy,” which makes websites that are open in a browser unable to interact with each other’s information.
Researchers ran a successful proof-of-concept cyberattack on one browser, ChatGPT Atlas. They had a website steal information from another site embedded within it—as if an ad on an email site could snatch sensitive information from the user’s emails. Researchers also found the right conditions for similar attacks in three other browsers: Chrome with Gemini, Claude for Chrome and Perplexity Comet. The browsers that gave agents fewer permissions were generally safer.
Particles’ properties at the quantum level could one day enable faster computing and better cybersecurity.
A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password.
The malware is designed to steal cryptocurrency assets, login credentials, password-manager data, browser information, and macOS authentication data, and it can also install a persistent backdoor for ongoing remote access to infected systems.
Researchers at Group-IB analyzed the ClickLock shell script after discovering the malware on VirusTotal, where it was first submitted on June 9. At the time of the report, it remained undetected by all security vendors available on the platform.
Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit with not so successful results.
“While the AI complied with their request to generate botnet code, it included a safety disclaimer that the developer failed to remove before shipping,” Palo Alto Networks Unit 42 said. “Although the LLM clearly aided in constructing the botnet, several functions in the analyzed samples failed to work correctly.”
The cybersecurity company said a manual code review would have resolved these errors and that it’s possible more polished iterations of the malware exist out there in the wild.