toad.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mastodon server operated by David Troy, a tech pioneer and investigative journalist addressing threats to democracy. Thoughtful participation and discussion welcome.

Administered by:

Server stats:

227
active users

#shadowai

0 posts0 participants0 posts today

New AI Security Risk Uncovered in Microsoft 365 Copilot

A zero-click vulnerability has been discovered in Microsoft 365 Copilot—exposing sensitive data without any user interaction. This flaw could allow attackers to silently extract corporate data using AI-integrated tools.

If your organization is adopting AI in productivity platforms, it’s time to get serious about AI risk management:
• Conduct a Copilot risk assessment
• Monitor prompt histories and output
• Limit exposure of sensitive data to AI tools
• Update your incident response plan for AI-based threats

AI can boost productivity, but it also opens new doors for attackers. Make sure your cybersecurity program keeps up. Contact our LMG Security team if you need a risk assessment or help with AI policy development.

Read the article: bleepingcomputer.com/news/secu

AI is the new attack surface—are you ready?

From shadow AI to deepfake-driven threats, attackers are finding creative ways to exploit your organization’s AI tools, often without you realizing it.

Watch our new 3-minute video, How Attackers Target Your Company’s AI Tools, for advice on:

▪️ The rise of shadow AI (yes, your team is probably using it!)
▪️ Real-world examples of AI misconfigurations and account takeovers
▪️ What to ask vendors about their AI usage
▪️ How to update your incident response plan for deepfakes
▪️ Actionable steps for AI risk assessments and inventories

Don’t let your AI deployment become your biggest security blind spot.

Watch now: youtu.be/R9z9A0eTvp0

After the great "success" of #ShadowIT: Introducing #ShadowAI — where employees will feed tons of highly sensitive and internal data and code to some LLM (Large Language Model) like #ChatGPT in the vague hope of becoming more productive or finally getting that promotion. Without any kind of review or approval. This will get people fired. Le sigh. So, so predictable.

The Next Big Thing after #ShadowIT (IT resources like Cloud capacity or using software that is not officially part of IT) — #ShadowAI. People/groups/companies using “AI” stuff without telling anyone to make life easier. This is dangerous stuff IMHO. How about your doctor or health insurance using ChatGPT to speed up diagnosis/paperwork? Ouch. inflecthealth.medium.com/im-an

Medium · I’m an ER doctor: Here’s what I found when I asked ChatGPT to diagnose my patientsBy Inflect Health