AI isnt an invisibility cloak.
Attacks still touch real systems and leave evidence.
But detecting malicious activity and proving an LLM orchestrated it are different claims.
Be precise about what the telemetry proves.
if you ran an LLM to attack stuff.. there is evidence... this is how forensics works, this is how Cyber Security Monitoring (OPS) works....
computers are not MAGIC!
#AI#Insanity
Alleged SmartSearch leak.
18.05M records claimed to be leaked
Does that mean unique people or just database rows?
Are the SSNs readable or are they only field names?
Does the claim cover one customer or all of them?
imo verify these details before sharing
๐บ๐ธ SMARTSEARCH DATABASE ALLEGEDLY LEAKED โ 18.05 MILLION RECORDS
A newly registered threat actor on a dark-web forum claims to have obtained the full database associated with SmartSearch (https://t.co/e1WmyRJaMO), totaling approximately 18.05 million records.
The sample displayed by the actor appears to contain extensive applicant and employment-screening information, with fields including:
* Full names and applicant identifiers
* Dates of birth, age and sex
* Social Security Number-related fields
* Residential addresses
* Employment and recruiter information
* Security-clearance information and clearance codes
* Branch, site and legal-entity information
* Additional background-screening/application metadata
โ ๏ธ Analyst Note:
If authentic, this could be a particularly sensitive exposure because the dataset appears to combine identity information with employment and security-clearance-related records. Such information could enable highly targeted identity fraud, phishing and social-engineering campaigns.
At this stage, the 18.05 million-record figure, provenance of the database and authenticity of the sample remain threat-actor claims and have not been independently verified.
#DDW #DarkWeb #DataBreach #ThreatIntelligence
Starting from 0 on X is painful! but here I am documenting the journey.
47 years old watching the birth of the AI era.
I hope to be jumping on the bandwagon at the right time to help Check Point and myself push the frontier of cyberdefense.
Follow along!
@FelipeFr1702 Pro is AGI to me. It has produced some crazy results for me today. Completely wrote a plan, presentation, and implementation instructions for a project I'm working on that's probably around 200 pages with slide deck without any noticeable ai slop.
GitSpawn research shows how malicious Git settings in a shared project folder can trigger code execution in affected agents.
Make sure you secure the tooling around the model as well as the prompts.
@mattshumer_ It made a prototype plan for me, over a 100 page PDF with directions to implement it, 30 slide deck for me to present to my management, deployment plan, and more in one prompt. It is actually banger too without ai slop. It is insanely good.
A CAPTCHA should never ask you to run PowerShell.
Our research here at Check Point links these fake verification prompts by StopAndProtect to data theft and ransomware.
Check Point has it covered through Harmony Endpoint and Threat Emulation.
Dont paste commands!
Report em!