Mastodon Digest
for the past
scorer
threshold
Posts

De l'ombre expérimentale, rue de Bonne à Ville de Grenoble .

Joli !

Curieux de connaître l'efficacité après un été de mesures.

A priori ça semble plus efficace quand il y a du vent et le soir (soleil bas) qu'en plein midi un jour calme (tissus verticaux comme le soleil, qui passe bien donc)...

tissu

Lost amid the news cycles on OpenAI's disclosure about poorly contained AI models that went on to hack into HuggingFace and other companies was this disclosure from the German health insurer Universa, which said OpenAI scraped customer data while it was supposedly unprotected due to a misconfiguration during an IT migration.

heise.de/en/news/uniVersa-Open

I reached out to Universa to learn if they knew how many records were accessed, but they ignored that question and sent this statement:

"We can confirm that there was an IT security incident at uniVersa. During an IT migration, a security setting was accidentally omitted temporarily on one of our IT systems. As a result, access to data on a server was possible for a few hours. Once the incident was detected, the unwanted access to the affected server was shut down immediately. The relevant data protection and supervisory authorities were informed without delay. During this timeframe, data from this server was retrieved by an automated web crawler belonging to a US artificial intelligence provider (OpenAI, L.L.C.). Therefore, this was not a targeted attack by criminals, but rather an automated process that regularly occurs on the internet.

Following our immediate contact, OpenAI has already confirmed that the data retrieved by its automated web crawler was not used for training its AI models and is ensuring that this will not happen in the future either.

The incident affected a single server intended for automated data exchange with sales partners. General personal data, such as names and addresses, as well as contract data, such as insurance numbers and policy information and, in the case of some customers, bank details (IBAN and BIC), were stored there. Particularly sensitive information, such as health, login, or credit card data, as well as the central administrative and data systems and the customer portal, were not affected.

In coordination with the relevant authorities and IT security specialists, we immediately began contacting those affected in writing to inform them about the most important aspects of the incident for them. This was our top priority. To protect the individuals affected, we are not providing any further details at this time.

The misconfiguration was rectified immediately, our security measures were reviewed, and further ad-hoc measures were taken. The external IT forensic investigation into the incident has been completed. Based on the forensic findings, we will be implementing additional technical and organizational measures."

To me, this incident raises a question that is far more scary than some "rogue" AI agent creating work-once malware that doesn't even try to hide (btw, read this from Charlie Eriksen, who thinks he found the malware OpenAI agents wrote: aikido.dev/blog/anthropic-rogu)

The question is, how many times a day or week do agents working for on behalf of OpenAI, Anthropic, xAI, CoPilot, etc. ingest sensitive and protected financial and health data? My guess is quite a lot.

Je cherche à acheter quelques livres en espagnol, rien d'original. Mais je suis bien embêté en fait, comment procéder : depuis une librairie physique française c'est possible/facile/pas trop pénible pour le libraire (sur Grenoble si possible) ? Ou alors depuis une librairie en ligne espagnole ? (un conseil de librairie qui livre en France ?)

Seeing a graybeard open the pcap in tcpdump

Raw

🚨 Kyndryl Azure/Entra tenant data allegedly offered for sale

A forum actor claims to be selling an internal data dump belonging to Kyndryl, a global IT infrastructure services company operating across more than 60 countries. The actor says the data was downloaded directly from the company’s Azure/Entra environment using compromised credentials.

The listing advertises more than 170,000 records, including employee accounts, service accounts, administrative roles, display names, email addresses, and other tenant account information.

A sample containing 2,200 records was published alongside the post.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

Boosts

@hacks4pancakes that sounds dire. Sooner or later the old guard will want to retire, and all those hopeful candidates that have been facing rejection for ages will have moved on to other careers, leaving a void of experience with no one wanting to fill it.

One day, Alice was at her computer, pondering a tricky programming problem.

Seeing her, Bob remarked: "Poor Alice. If only you knew to pay subscription to AI companies, you wouldn't have to program."

Alice responded: "Poor Bob. If only you knew how to program, you wouldn't have to pay subscription to AI companies."