AboutDFIR.com – The Definitive Compendium Project
Digital Forensics & Incident Response

Blog Post

InfoSec News Nuggets 10/29/2024

Study shows that LLMs could maliciously be used to poison biomedical knowledge graphs

In recent years, medical researchers have devised various new techniques that can help them to organize and analyze large amounts of research data, uncovering links between different variables (e.g., diseases, drugs, proteins, etc.). One of these methods entails building so-called biomedical knowledge graphs (KGs), which are structured representations of biomedical datasets.

 

Throne’s toilet camera takes pictures of your poop

Throne is an Austin-based health startup. It sells a camera. That clips onto the side of a toilet bowl. It takes pictures of your poop. Currently in beta, the system utilizes artificial intelligence to examine your dookie as a way of determining things like gut health and hydration. Turns out we have a surprising amount to learn from our logs. Throne calls its underlying technology “artificial gut intelligence.”

 

Russia Kneecaps Ukraine Army Recruitment With Spoofed ‘Civil Defense’ App

Ukrainian efforts to recruit new soldiers to serve in its military in the country’s war against Russia is under a two-pronged cyberattack by Kremlin-backed threat actors. Researchers at Google’s Threat Intelligence Group (TAG) and Mandiant have tracked down an active campaign that uses a spoofed version of the legitimate Ukrainian-language tool “Civil Defense,” a crowdsourced mapping tool used to locate military recruiters. Attackers are using the fake version to perform dual malicious actions — dropping malware and delivering misinformation.

 

ChatGPT Jailbreak: Researchers Bypass AI Safeguards Using Hexadecimal Encoding and Emojis

Malicious instructions encoded in hexadecimal format could have been used to bypass ChatGPT safeguards designed to prevent misuse. The new jailbreak was disclosed on Monday by Marco Figueroa, gen-AI bug bounty programs manager at Mozilla, through the 0Din bug bounty program.  Launched by Mozilla in June 2024, 0Din, which stands for 0Day Investigative Network, is a bug bounty program focusing on large language models (LLMs) and other deep learning technologies. 0Din covers prompt injection, denial of service, training data poisoning, and other types of security issues, offering researchers up to $15,000 for critical findings. It’s unclear how much a jailbreak such as Figueroa’s would be worth.  

 

Hacker claims to have data linked to 19 million French mobile and internet customers

Free, the second largest internet service provider (ISP) and telephone operator in France, has recently confirmed it was the victim of a major breach. The company, which is believed to have over 20 million customers, notified France’s cyber agency over the weekend, stating that threat actors targeted a management tool which was used to exfiltrate user data. Free clarified that no passwords, bank cards, or communications were impacted during the attack, adding that there was no operational impact on its services.

Related Posts