Microsoft has disrupted EvilTokens, a phishing-as-a-service platform that was linked to more than 12,000 compromised email inboxes across more than 10,000 organizations worldwide. The service used device-code phishing to gain access to Microsoft accounts and then used AI-powered tools to analyze compromised mailboxes and help attackers identify opportunities for further fraud. The operation highlights how […]
OpenAI has released Lockdown Mode which is a potent and latest security capability for AI models. The target is to ramp down the possibility of data exfiltration by malicious prompt injection attacks. The feature is currently on offer to personal accounts, self-serve ChatGPT Business clients as well as managed enterprise spaces. Prompt injection attacks involve […]
On Sunday, popular Password Manager Dashlane reported a massive brute-force attack also known as credential stuffing. In the latter, user accounts are fed with as many username and password combinations as needed with the objective that one will be the correct one. The good news is that the company’s internal systems were not affected. However […]