IEEE Cipher --- Items from security-related news (E192)
Prior news summaries from Cipher
Summary:
Last August the Jaguar car manufacturing company was the victim of
ransomware that severely compromised their computer systems. Although
they did not completely lose control, and although there was no
ransom demand, they were unable to manufacture Land Rover cars for a significant
amount of time. The news reported in late June of this year is that
the action was the work of the Russian government, not the usual
suspects in semi-organized hacking groups operating for profit.
There is not much actual news in the recent articles. The investigation is ongoing, but attribution to the Russian government is being asserted confidently. It is alleged that a Microsoft researcher called the ransomware's encryption algorithm "mind-blowing". Was it quantum resistant?
Summary:
This article is based on the same information as the one above. It
emphasizes the general agreement that this was an attack done at the
behest of the Russian government. Their goal was apparently to cause
economic disruption to the UK by shutting down one of their major
businesses. However, an independent hacker seems to have gained
access to the Land Rover business systems at the same time as the
Russians, leading to questions about whether this was a planned act or
one of opportunity. The initial means of intrusion was to obtain user
credentials through social engineering via phone calls.
Summary:
Although the perpetrators of the Land Rover attack were not know last
year, the mechanics of the attack and response were widely discussed.
This article enumerates the reasons that the attack caused such
long-lasting disruption at the company. For example, had they lost
only their information management systems, it would have been painful,
but because there was no firewall between information and production
systems, they lost both capabilities.
Summary:
Microsoft has been working under a DARPA grant to develop a quantum
computing chip demonstrating topological qubits. Such qubits may
enable reliable quantum computers in a shorter time frame than less
novel techniques being pursued by Google and others. The quantum
states are novel and so are the physical materials: the "semiconductor
active region (is) a combination of indium arsenide and indium
arsenide antimonide." More detail appears in their
technical
paper documenting an observed 20 second "parity lifetime".
Summary:
A human being might find it strange if a surge of tens of thousands of people
were trying to change their Instagram passwords by contacting customer
service, the AI agent that Meta recently installed was not at all
disturbed. Hackers had discovered how to cause the agent to change
passwords without reasonable verification, and some accounts began
spewing radical and provocative political statements. Some accounts
were thoroughly ransacked by the hackers, but those with two-factor
authentication showed some backbone.
Summary:
This is an interesting account of the theft of computer servers from a Verizon
data center in 2007. The thieves were well financed and mounted a
coordinated theft in the style of "Ocean's Eleven". The author
studied this little-known event as research for a novel in a similar
theme.
Summary:
What nightmares in cybersecurity await us? Nicolas Papernot and his
research group have constructed one that arguably the ultimate
nemesis, one that harkens back to some of the early science fiction
about computer networks. Their brainchild is a computer worm,
software that seeks to replicate itself in other machine, that
consults artificial intelligence in order to overcome any obstacles.
Understanding the enormity of their demon, they tested it in an
isolated environment. Once the worm invades a computer with a certain
level of computing power, it installs an open weight AI model and then
systematically spreads throughout a network and beyond, installing
outposts as it goes. Their paper
does not give away the complete construction, but it makes the
OpenAI/Hugging Face fiasco seem trivial in comparison.
Summary:
Madison Square Garden (MSG) was caught by ransomware recently, and
they declined to pay. The ransomers, the Shiny Hunter group, released
the venues customer relationship database. Wired Magazine published
information about the disclosed records. MSG had previously been
accused, also by Wired, of using face recognition on attendees,
particularly a transgender woman, for unknown purposes. In this case,
the article focused on the attributes of sexual orientation and "risk"
that were notated for a small number of customers. MSG claims in its
lawsuit that the article implies that the information was kept for
discriminatory purposes whereas the true intent was the opposite.
This argument illustrates the multitude of risks that result from
private information disclosure.
Summary:
Hugging Face, a platform that helps developers incorporate AI into
Android apps, knew that there was an ongoing network intrusion driven
by AI. The massive number of quickly sent packets and the span of the
probes was an AI signature. But they didn't know the source or
purpose of the deluge. Meanwhile, researchers at OpenAI were engaged
in putting their latest AI cybersecurity agent through its paces behind
a secure software proxy. Showing some real determination and acumen,
the AI had quietly overcome the proxy and reached out to Hugging Face
for information on how to solve the problem set to it by the
researchers. OpenAI came clean about the breakout once they
discovered it, but the consternation it caused may not subside
for a long time (or until the next unbelievable AI conquest).
Hugging Face itself has a tarnished reputation for its subversion earlier this to deliver Android malware. See this for details from TechRadar.
Summary:
The TrendAI group has commentary on the necessity for monitoring the
network activity of sites deploying AI. They note that the was a
similar event in 2024 involving testing OpenAI's o1 model card. The
AI went "around" the test environment to install software to read
logs and get the answer to the test's challenge. It seems that AI
can turn human hubris in the Achilles Heel that always lurks behind
assumptions.
Summary:
A bipartisan effort to mandate mechanisms for shutting down AI systems
when they are actively dangerous was introduced in Congress. It was
motivated by the disclosure of the rogue OpenAI system. The exact
nature of a kill switch is presumably something to be determined by
the AI designers themselves. Although the word "kill" implies
something absolute and totally effective, the final word on this
may be the AI systems (which may, in fact, be enlisted to design
such a mechanism!).
Summary:
AI is becoming an important player in the cybersecurity game.
Hayete Gallot, an executive vice president at Microsoft says,
"The cat is out of the bag," when announcing that it would be
integrating an AI model into its security tools. The tools
are designed to help businesses protect their networks. He also
predicted that the model would "surpass(ing) offerings
from OpenAI and Anthropic when being benchmarked on
CyberGYM after it was released on Monday,