Goto

Collaborating Authors

 information security


Muse Creates Detailed Profiles of All Your Friends and Family

WIRED

Millions have downloaded Meta's AI agent Muse. But getting it to do your bidding comes with privacy costs. Meta's new personal assistant, Muse, has become a viral hit, with millions downloading the AI agent, connecting it to bank accounts, messages, or health data, and allowing it to complete tasks for them. But as Muse takes off among consumers, data from inside the app is providing insight into how it organizes and presents information to users. In recent days, multiple researchers have extracted Muse's internal files and dumped the agent's operating instructions, providing a glimpse of how the system was built and behaves. Meta has maintained that it intended for these files to be accessible in the interest of transparency, and they do provide insight into how Muse responds to prompts and questions about, for example, highly politicized or sensitive topics.


Forget the AI Slowdown--the Vulnerability Explosion Is Already Happening

WIRED

AI labs are toying with an industry-wide pact to slow development. Meanwhile, widely available AI chatbots are already helping uncover a tidal wave of security flaws. AI doomers have recently traded one worst-case scenario for another, putting aside a potential software vulnerability apocalypse to focus on the possibility of rogue AI causing mass human death in the next decade. As AI leaders consider a cooperative slowdown on frontier model development, though, one aspect of the cybersecurity sea change has already arrived thanks to existing, broadly available capabilities in mainstream AI products, including open weight models. A tidal wave of vulnerabilities uncovered using AI has only accelerated in recent months--piling more pressure on under-resourced, and very human, IT and security teams and straining volunteers who maintain crucial open source software.


Hackers Claim to Leak Stolen Madison Square Garden Data

WIRED

Plus: Gay bars in San Francisco using face scanners, France quits Palantir, Apple plans to change its private email, and more. Meta is testing face-recognition software built by the United States military and regional police department supplier Rank One, WIRED found in an investigation this week. Meta has been exploring the possibility of adding face recognition tech into its smart glasses, and WIRED previously reported that the app for the glasses contained code --now deleted--that would have enabled the company to activate face-recognition features on the devices. Anthropic is still negotiating with the Trump administration, after apparent White House concerns about the safety of new public model Claude Fable 5 resulted in Anthropic pulling the product off the market entirely. But security experts point out that AI models with advanced capabilities for discovering and exploiting software vulnerabilities--in other words, creating potentially dangerous hacking tools-- will be ubiquitous soon around the world .


Sears Exposed AI Chatbot Phone Calls and Text Chats to Anyone on the Web

WIRED

Customer conversations with chatbots can include contact information and personal details that make it easier for scammers to launch phishing attacks and commit fraud.


Iran's Digital Surveillance Machine Is Almost Complete

WIRED

Iran's Digital Surveillance Machine Is Almost Complete After more than 15 years of draconian measures, culminating in an ongoing internet shutdown, the Iranian regime seems to be staggering toward its digital surveillance endgame. Iranian protesters gather on Enghelab (Revolution) Street during a demonstration in Tehran on January 8, 2026. Over the past four weeks, the Iranian government completely shut down connections to the global internet while its forces killed thousands of anti-regime protesters around the country. The shutdown follows years of Tehran imposing connectivity filtering, digital curfews, and total blackouts as part of previous attempts to quell unrest. Over more than 15 years, the regime has developed technological and systemic mechanisms to fundamentally control connectivity in the country--including an internal Iranian intranet known as the National Information Network (NIN).


Amazon Explains How Its AWS Outage Took Down the Web

WIRED

Plus: The Jaguar Land Rover hack sets an expensive new record, OpenAI's new Atlas browser raises security fears, Starlink cuts off scam compounds, and more. The cloud giant Amazon Web Services experienced DNS resolution issues on Monday leading to cascading outages that took down wide swaths of the web . Monday's meltdown illustrated the world's fundamental reliance on so-called hyperscalers like AWS and the challenges for major cloud providers and their customers alike when things go awry . See below for more about how the outage occurred. US Justice Department indictments in a mob-fueled gambling scam reverberated through the NBA on Thursday.


Information Security Based on LLM Approaches: A Review

arXiv.org Artificial Intelligence

Information security is facing increasingly severe challenges, and traditional protection means are difficult to cope with complex and changing threats. In recent years, as an emerging intelligent technology, large language models (LLMs) have shown a broad application prospect in the field of information security. In this paper, we focus on the key role of LLM in information security, systematically review its application progress in malicious behavior prediction, network threat analysis, system vulnerability detection, malicious code identification, and cryptographic algorithm optimization, and explore its potential in enhancing security protection performance. Based on neural networks and Transformer architecture, this paper analyzes the technical basis of large language models and their advantages in natural language processing tasks. It is shown that the introduction of large language modeling helps to improve the detection accuracy and reduce the false alarm rate of security systems. Finally, this paper summarizes the current application results and points out that it still faces challenges in model transparency, interpretability, and scene adaptability, among other issues. It is necessary to explore further the optimization of the model structure and the improvement of the generalization ability to realize a more intelligent and accurate information security protection system.


Interplay of ISMS and AIMS in context of the EU AI Act

arXiv.org Artificial Intelligence

The EU AI Act (AIA) mandates the implementation of a risk management system (RMS) and a quality management system (QMS) for high-risk AI systems. The ISO/IEC 42001 standard provides a foundation for fulfilling these requirements but does not cover all EU-specific regulatory stipulations. To enhance the implementation of the AIA in Germany, the Federal Office for Information Security (BSI) could introduce the national standard BSI 200-5, which specifies AIA requirements and integrates existing ISMS standards, such as ISO/IEC 27001. This paper examines the interfaces between an information security management system (ISMS) and an AI management system (AIMS), demonstrating that incorporating existing ISMS controls with specific AI extensions presents an effective strategy for complying with Article 15 of the AIA. Four new AI modules are introduced, proposed for inclusion in the BSI IT Grundschutz framework to comprehensively ensure the security of AI systems. Additionally, an approach for adapting BSI's qualification and certification systems is outlined to ensure that expertise in secure AI handling is continuously developed. Finally, the paper discusses how the BSI could bridge international standards and the specific requirements of the AIA through the nationalization of ISO/IEC 42001, creating synergies and bolstering the competitiveness of the German AI landscape.


Generative AI Models: Opportunities and Risks for Industry and Authorities

arXiv.org Artificial Intelligence

Generative AI models are capable of performing a wide range of tasks that traditionally require creativity and human understanding. They learn patterns from existing data during training and can subsequently generate new content such as texts, images, and music that follow these patterns. Due to their versatility and generally high-quality results, they, on the one hand, represent an opportunity for digitalization. On the other hand, the use of generative AI models introduces novel IT security risks that need to be considered for a comprehensive analysis of the threat landscape in relation to IT security. In response to this risk potential, companies or authorities using them should conduct an individual risk analysis before integrating generative AI into their workflows. The same applies to developers and operators, as many risks in the context of generative AI have to be taken into account at the time of development or can only be influenced by the operating company. Based on this, existing security measures can be adjusted, and additional measures can be taken.


Dangers of AI - Blog on Information Security and other technical topics

#artificialintelligence

By now, the whole world is chattering about'ChatGPT', Bard and other AI chatbots. AI or'Artificial Intelligence' is the concept that is powering these chatbots. 'Artificial Intelligence' as the name suggests is intelligence in machines which seek to mimic human intelligence. AI in chatbot is given the super concoction of computer science knowledge and large data sets to make it give answers on any topic like a super human dictionary. One popular example of AI is the'ChatGPT' chatbot that made its appearance in November of 2022 and was adopted by all in the tech community.