New Security Vulnerability, Cybersecurity Not Ready for AI, and More.

by | Jun 27, 2024 | Blog

This Week In Tech, we talk about a new security vulnerability called 'SnailLoad', if cybersecurity agencies are ready for generative AI, and how Meta has become the most impersonated amongst phishing scammers.

New security vulnerability ‘SnailLoad’ allows hackers to spy on people

A newly discovered security flaw, called ‘SnailLoad,’ potentially enables hackers to spy on individuals through any internet-connected device, bypassing typical security measures like firewalls and VPNs. Instead of relying on traditional malicious code, ‘SnailLoad’ operates by monitoring fluctuations in a user’s internet speed. To initiate the attack, users unknowingly download a seemingly safe small file from the attacker’s server, often embedded within a malicious website. This file does not have immediate malicious content detectable by security software, but is transferred very slowly, allowing hackers to gain specific characteristics of the user’s internet connection. This approach allows attackers to pinpoint a distinctive ‘signature’ linked to the connection, enabling full unauthorized access. According to the researchers, they successfully monitored test users watching videos with a 98% success rate. They noted higher success rates when users had slower internet connections and were streaming large videos.

Read More: Independent

Cybersecurity not ready for generative AI

Artificial intelligence (AI) in cybersecurity isn’t a novelty, many automated security tools incorporate AI and machine learning to some extent. However, the rise of generative AI has sparked widespread concern and discussion. According to a Darktrace study, AI-generated threats have already affected 75% of organizations, yet 60% acknowledge being unprepared to defend against such attacks. For the first time, AI considerations extend beyond the corporate network and threat actors to include customer interactions. As organizations increasingly deploy AI in consumer-facing tools like chatbots, security teams must reconsider their strategies for detecting threats and responding to incidents that involve interactions between AI systems and third-party users. A significant challenge lies in managing generative AI. Cybersecurity teams, as well as organizations at large, lack clear insights into the data used to train AI, who accesses these training datasets, and how AI aligns with compliance requirements.

Read More: Cybersecurity Dive

Meta is the most impersonated by phishing scammers

Meta is the most frequently impersonated brand by phishing scammers, with over ten thousand verified phishing scams reported in the past four years. These scams typically involve fraudulent messages appearing to come from a trusted source, urging users to click on links or provide personal information urgently. Such actions can lead to unintended installation of ransomware or unauthorized access to accounts by the scammers. Phishing messages targeting Meta can vary widely, from believable notifications about friend requests to extravagant claims such as winning a Facebook lottery. IT and technology brands, including Meta, account for more than a quarter of brand impersonation phishing scams, followed closely by banking and financial services. This trend may stem from the high levels of customer engagement and trust these industries enjoy, along with the value of the credentials they possess.

Read More: Forbes

Here are some more blogs from this category.
Cybersecurity Training Checklist for Businesses: A Complete Guide to Building a Human-Centric Defense System

Cybersecurity training extends beyond awareness. Complete cybersecurity includes employees trained to recognize and respond to threats in real-world scenarios.

How to Protect Against Data Breaches: A Complete Cybersecurity Guide for Businesses

Protect your business from data breaches with insights on causes, trends, prevention strategies, tools, and cybersecurity solutions from AlphaKOR.

Best Data Backup Solutions: Complete Business Guide

A complete guide to protection, recovery, and cybersecurity resilience with data backup solutions for businesses. Everything you need to know.

Business Guide to Securing Your Microsoft 365 Environment

Secure your business’ Microsoft 365 environment from cyber-threats. Learn about risks, common attacks, and best practices to secure your business, here.

Ransomware and Your Business: What You Need to Know

Explore the impact of ransomware on businesses, key trends, and effective strategies for prevention, and protection in today’s cybersecurity landscape.

Protecting Your Business from Phishing

Explore phishing risks, trends, and protection strategies to safeguard businesses from evolving cyber threats and financial loss.

Windsor Tech Companies: Building the Future of Business Today

Discover how Windsor tech companies are driving business growth and innovation, shaping a dynamic future for the region’s thriving business landscape.

How Top Tech Companies in London, ON Build Resilient IT Without Slowing Innovation

Understanding tech companies in London is essential for business leaders who want to remain competitive in today’s landscape…

Benefits of IT Outsourcing to Grow and Protect Your Business

You are likely aware that IT outsourcing is no longer a secondary consideration—it has become a primary lever for organizations intent on achieving re…

How Managed Services vs Professional Services Shape Your IT Success

Organizations are under increasing pressure to manage risk, control costs, and maintain agility, prompting careful consideration of how they source IT…