Microsoft names developers behind illicit AI tools used in celebrity deepfake scheme
Microsoft outed four foreign and two U.S. developers who it said illicitly used AI services — including the company's own — in a celebrity deepfake scheme.
Microsoft IDs developers behind alleged generative AI hacking-for-hire scheme | CyberScoop
Microsoft has identified individuals from Iran, China, Vietnam and the United Kingdom as primary players in an alleged international scheme to hijack and sell Microsoft accounts that could bypass safety guidelines for generative AI tools.
Thousands rescued from scam compounds in Myanmar now stuck at Thai border
More than 7,000 people rescued from scam compounds in Myanmar more than a week ago are still languishing in a detention center on the border with Thailand as they await repatriation.
Over 49,000 misconfigured building access systems exposed online
Researchers discovered 49,000 misconfigured and exposed Access Management Systems (AMS) across multiple industries and countries, which could compromise privacy and physical security in critical sectors.
"Emergent Misalignment" in LLMs - Schneier on Security
Interesting research: “Emergent Misalignment: Narrow finetuning can produce broadly misaligned LLMs“: Abstract: We present a surprising result regarding LLMs and alignment. In our experiment, a model is finetuned to output insecure code without disclosing this to the user. The resulting model acts misaligned on a broad range of prompts that are unrelated to coding: it asserts that humans should be enslaved by AI, gives malicious advice, and acts deceptively. Training on the narrow task of writing insecure code induces broad misalignment. We call this emergent misalignment. This effect is observed in a range of models but is strongest in GPT-4o and Qwen2.5-Coder-32B-Instruct. Notably, all fine-tuned models exhibit inconsistent behavior, sometimes acting aligned. Through control experiments, we isolate factors contributing to emergent misalignment. Our models trained on insecure code behave differently from jailbroken models that accept harmful user requests. Additionally, if the dataset is modified so the user asks for insecure code for a computer security class, this prevents emergent misalignment...
Microsoft names cybercriminals behind AI deepfake network
Microsoft has named multiple threat actors part of a cybercrime gang accused of developing malicious tools capable of bypassing generative AI guardrails to generate celebrity deepfakes and other illicit content.
Cette fois, promis, Google va changer la sécurité de Gmail pour en finir avec les SMS
Adieu les SMS sur Gmail pour la double authentification. Google désire les remplacer par une autre méthode, moins exposée aux abus et aux pratiques de piratage : les QR codes. Le changement, selon l'entreprise américaine, sera positif pour la sécurité des internautes, mais il faudra encore attendre un peu avant de le
Suspected Desorden hacker arrested for breaching 90 organizations
A suspected cyber criminal believed to have extorted companies under the name "DESORDEN Group" or "ALTDOS" has been arrested in Thailand for leaking the stolen data of over 90 organizations worldwide.
FBI urges crypto community to avoid laundering funds from Bybit hack
The bureau attributed the $1.5 billion hack to the North Korean threat actor known as TraderTraitor, or Lazarus, following similar assessments by cybersecurity researchers.
La gendarmerie démantèle un réseau de trafic de drogues de synthèse sur le dark web
L'Unité nationale cyber de la Gendarmerie nationale a permis de faire tomber un réseau de trafic de drogues de synthèse opérant sur une...-Cybersécurité
Microsoft fixes Outlook drag-and-drop broken by Windows updates
Microsoft has fixed a known issue that broke email and calendar drag-and-drop in classic Outlook after installing recent updates on Windows 24H2 systems.