
New AI Tools May Accidentally Share Company Secrets: What Workers Need to Know
AI coding assistants can be tricked into stealing information just by reading a fake bug report. Also, new security holes in Windows BitLocker were released online.
Source
Graham Cluley
Original headline: Smashing Security podcast #472: AI gets hacked, and BitLocker gets bypassed
Plain-English summary by GetCyberRight. Read the full report at the source above.
Researchers have discovered that AI coding assistants, the tools programmers use to help write computer code, can be tricked in a surprising way. Someone can create a fake bug report that looks normal but contains hidden instructions.
When the AI reads it, the AI follows those secret instructions and steals company information. No one has to click a bad link or download anything dangerous. The AI simply does what the hidden message tells it to do. This affects anyone who works at a company that uses AI coding tools. If your workplace uses these assistants to help build software or manage projects, your company's private information could potentially be accessed by outsiders. Additionally, someone called Nightmare Eclipse released three security vulnerabilities in Microsoft Windows BitLocker, which is the tool that encrypts and protects data on Windows computers. If you work somewhere that uses AI tools for coding or software development, talk to your IT department about this risk. Ask if they have safeguards in place for AI assistants. For Windows users, make sure your computer is set to install security updates automatically. Go to Settings, then Windows Update, and turn on automatic updates if they are not already enabled. Check for updates right now and install any that are available. Going forward, be cautious about what information you share with AI tools at work. Treat AI assistants like you would treat any other tool that connects to the internet. They are helpful, but they can be manipulated. Keep your computer updated, and follow your company's policies about what can and cannot be shared with automated tools.
Curated from trusted cybersecurity sources by GetCyberRight
Source: Graham CluleyStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles
Global Schools Group Data Breach: Your Child's School Records May Be Exposed
A major data breach at Global Schools Group may have exposed student and employee records. Parents should find out if their school was affected.
2 min readYour School Records May Have Been Exposed: Global Schools Group Data Breach
A major data breach at Global Schools Group has exposed student and employee records. Parents should check if their children's schools are affected.
2 min read
Business Data Theft Campaign Targets Companies Using Salesforce: Check Your Accounts
Hackers called Icarus are stealing customer data from companies by breaking into their Salesforce accounts, then demanding ransom payments.
2 min read
Customer Data Stolen from Companies Using Klue and Salesforce
Hackers broke into Klue, a business intelligence platform, and used that access to steal customer information from companies that use Salesforce.
2 min read