It’s been a busy week in cybersecurity, starting off with two notable breaches from our old friends ShinyHunters. This week, we reported that the group hacked CLOP, a ransomware group that ShinyHunters says stole a method from them to exploit a vulnerability in Oracle’s business software. ShinyHunters is demanding that the ransomware group pay a ransom itself, which I can’t help but find funny. ShinyHunters also breached the FBI this week, extracting data on, in its own words, “very sensitive data on almost ALL FBI Agents,” and people who used the FBI’s jobs portal to apply for work. Putting aside the magnitude of the breach for a moment, it should be alarming that the FBI’s security was lax enough to let this happen.
Going back to AI security, which never seems to slow down, the Australian government announced this week that an OpenAI agent breached several government systems, including Australia’s Medicare agency and some associated departments. It’s important to note that while coverage of the breach (and other AI-related breaches) often uses the word “rogue,” these agents are doing what they’re programmed to do. The actions may not have been intentional, but AI, like any electronic system, can only do what its human designers tell it to.
And speaking of core issues with AI and security, this week we published an explainer on AI prompt security and why the nature of LLMs makes it very difficult to stop every exploit. For example, security researchers at Hacktron used Anthropic’s Claude to breach OpenAI as part of a bug bounty program and earned themselves a tidy $ 6,500 payout for helping both companies see how their tools can be used to exploit (and fix) one another’s systems.
Next up in the news, Discord’s age verification is back, and while there are still more than a few legitimate concerns about it, it’s certainly better looking now than it was when it was first announced. The company says that 90% of users will be automatically and correctly grouped without needing to do anything to prove their age, and anyone who’s miscategorized will have options to prove their age without handing over personal data, like the kind that was lost in a breach last year.
Now then, let’s see what else is going on in the infosec world this week.
After Water Attacks, Congressman Proposes an AI Security Program
A couple of weeks ago, a reader asked why we can’t use AI to determine who’s responsible for the attacks on water infrastructure across the US in recent months. Well, at least one congressman, New Jersey representative Josh Gottheimer, just introduced the AI Cyber Defense Act, which would do just that: Give utilities like water and power companies access to frontier AI models to help secure and defend critical infrastructure against attacks. As CyberScoop reports, if these frontier models that AI companies claim are so powerful that they can’t be released or else malicious actors will get their hands on them, we may as well use them to protect important things like, well, the safety of our drinking water.
The bill would direct the Cybersecurity and Infrastructure Security Agency (CISA) to establish a program in which those companies, with the help of the Department of Homeland Security (of which CISA is a part), would securely access those AI models and use them to identify vulnerabilities and fend off cyberattacks. The bill would even fund the program, offering $100 million to set everything up. Of course, introducing a bill in the House of Representatives is just a start, and there’s no telling whether it will advance with midterm elections coming up, but it’s still encouraging to see.
Fake Lastpass Authenticator GitHub Installs Malware
If you’ve been around the web for a while, you might remember having to find different places to download software based on availability and download speed. Today, app stores are more common, but it’s still always smart to make sure you download software you want to try from a reputable source, since malware has definitely shown up in app stores and even reputable sites like GitHub. And speaking of GitHub, Bleeping Computer reports that fake LastPass Authenticator installers on the site have been actually installing a new infostealer called Rapuncel. The malware can steal session credentials from Discord, Steam, and Telegram, stored passwords and other data from 25 different web browsers, the contents of Windows Credential Manager, cryptocurrency wallet data, and even things like monitor screenshots, detailed system information, and any documents with names that contain the words “password,” “seed,” “wallet,” or “recovery.”
Even worse, the malware can disable antivirus software and enterprise detection and response (EDR) products. It can also bypass Google’s app protection in Chrome, Edge, and other Chromium-based browsers and install itself as a Windows service, staying active after reboots (to disable antivirus after startup). It’s pretty nasty and a good reminder to download software only from official websites and sources. The hackers behind the campaign have even gamed Google’s SEO by optimizing those malicious GitHub repositories and promoting them so they show up at the top of Google search results and in AI overviews, if you needed another reason to be skeptical about those (and you probably didn’t).
Google Fined $459 Million Over Location Data Practices
While the United States still lacks a comprehensive data privacy law, the European Union (EU) has the General Data Protection Regulation (GDPR), which is designed to protect the privacy of EU citizens and hold tech companies accountable for the misuse of their personal data. Well, Ireland’s Data Protection Commission (DPC) just fined Google €403 million (approximately $459 million) for a number of GDPR violations, including the processing of location data in the company’s Web & App Activity, Location History, and Location Activity features. The violations occurred between 2018, when the GDPR took effect, and 2020, according to Security Affairs.
Worse, because all of the offenses involved location data and how it was accessed across multiple features, the commission determined that this wasn’t a technical error but a conscious decision by Google, either to use the data for its own purposes or to improve its services. In any case, a violation is still a violation, so the company earned its fine and was given six months to ensure its data processing practices comply with the GDPR. The case is the culmination of a six-year battle between Google and the Irish regulator, and it’s by no means the first timethe company has beenin hot water overits data handling practices.
Ask Our Expert: Is My VPN Blocking My Web Browsing?
Do you have a question about online privacy or security? I’m here to help! You can submit your question here, and I may answer it in an upcoming SecurityWatch column and newsletter. If you’re not subscribed to the newsletter, head here to sign up, and check back each week for the latest updates from PCMag’s security team. Now, on to this week’s question!
Recommended by Our Editors
ShinyHunters Gang: We Hacked the FBI, Stole Sensitive Data on ‘Almost All’ Agents
Hacker-on-Hacker Crime: ShinyHunters Is Trying to Extort CLOP Ransomware Group
Inside AI Prompt Security: Why Stopping Every LLM Exploit Is Impossible
Katherine J asks: “I have [REDACTED VPN] on my MacBook Pro. However, I’ve noticed that it often blocks me from accessing certain websites, and I think it also slows me down when I attempt to open multiple webpages. Is this the case? Is there a different VPN or service I could install in its place?”
Hi Katherine! Thanks so much for your question! Let me tackle them in order. First, virtually every VPN today, including the one you mentioned in your question, tries to perform some content filtering to protect your security. The sites you were trying to visit may have been blocked by the VPN because it thinks they’re potentially malicious or dangerous. Alternatively, if they’re not malicious, it’s possible that it’s not the VPN doing the blocking, and instead either the DNS service that your PC is set up to use, or the website itself refusing to connect you because you’re using a VPN.
Without getting too far into the weeds, DNS stands for Domain Name System, and is how your computer translates things like “pcmag.com” into the server addresses required to get you to the website. And depending on where your VPN is connecting you from in the world, it could be DNS that’s either blocking your request, or is just so slow that it feels that way. Luckily, DNS is easy to change, and can result in faster, safer browsing whether your VPN is on or off.
Additionally, some websites just don’t like it when you connectvia a VPN for security reasons, such as banks, other financial institutions, or any service that cares about your physical location. If your bank, for example, detects that you’re signing in with the right credentials but connecting from, let’s say, Australia when you normally connect from Canada, it may block the attempt for fear that your account has been compromised.
Anyway, all of that is to say it may not actually be the VPN’s fault here, and it’s important to remember that using any VPN will slow your connection a little, simply because your data has to be encrypted and routed through the VPN before it reaches its destination. That said, our favorite VPNs do their best to make sure that the speed difference is as minimal as possible, so if you really do think it’s your VPN that’s slowing you down, check out our list of the fastest VPNs to see what other options you have.
About Our Expert
Alan Henry
Managing Editor, Security
Experience
I’ve been writing and editing stories for almost two decades that help people use technology and productivity techniques to work better, live better, and protect their privacy and personal data. As managing editor of PCMag’s security team, it’s my responsibility to ensure that our product advice is evidence-based, lab-tested, and serves our readers.
I’ve been a technology journalist for close to 20 years, and I got my start freelancing here at PCMag before beginning a career that would lead me to become editor-in-chief of Lifehacker, a senior editor at The New York Times, and director of special projects at WIRED. I’m back at PCMag to lead our security team and renew my commitment to service journalism. I’m the author of Seen, Heard, and Paid: The New Work Rules for the Marginalized, a career and productivity book to help people of marginalized groups succeed in the workplace.
Areas of Expertise
Latest By Alan Henry
- How Did AI Send 1M Scams in 3 Days? 7 Brutal Security Stories Making Headlines This Week
- A Meta Exec’s 150-Porn-Downloads-a-Day Habit, a 23-Year Botnet Bust, and $1M Phone Unlocks
- SpaceX AI Weaponized, 153K Driver’s Licenses Leaked, and GTA 6 Subpoenas: This Week’s Security Scandals
- Don’t Click the GTA 6 Demo, Don’t Trust the Flirty DM: This Week’s Cybersecurity Survival Guide
- GTA 6 Leaks, The Odyssey Malware, and Water Grid Attacks: This Week in Cybersecurity
- More from Alan Henry
