- Secure AI
- Posts
- Secure AI #3: Another Huge Week in Cybersecurity AI News!
Secure AI #3: Another Huge Week in Cybersecurity AI News!
Welcome to Secure AI, where we discuss the intersection of Cybersecurity, Privacy and IT Governance, Risk & Compliance.
Another huge week in Cybersecurity AI news, including new sites for AI Incident Tracking, AI Vulnerability and AI Risk Databases!
In this newsletter…
This Weeks Article - OpenAIs “GPTBot” Risk + Real World GPT Cybersecurity Use Case
AI Security News - Latest news & news you may have missed
AI Risk & Governance News - Latest GRC-related AI news
Vendor AI Security News - AI news from the vendor world
AI Security Tool of the Week - Security tools for AI
Recommended Reading - Deeper dives into AI & Security
This Weeks Articles
OpenAIs “GPTBot” Risk + Real World GPT Cybersecurity Use Case
OpenAI has documented their web crawler User Agent “GPTBot”. You can use a disallow statement in robots.txt to stop OpenAI crawling your site’s content to train their models. This is a move to give companies the opportunity to opt out of data being used in model training but will also reduce OpenAIs exposure to future litigation about copyright infringement, as is already happening.
The hacker side of my brain went straight to having a website that returned malicious content to poison the model when it detected the GPTBot User Agent but returns legitimate content when for other User Agents like Chrome.
Separately in our Story of the Week Rahul Lobo, outlines using ChatGPT to do threat modelling. I think this has great potential, especially when ChatGPT goes multi-model and can interpret pictures such as network diagrams. I also see the potential to use Infrastructure as Code as input into the process.
Finally, here is a great visual of the OWASP LLM Top 10 overlaid on top of the LLM lifecycle by Dor Sarig
AI Security News
Story of the Week
Other News
In case you missed it…
AI Risk & Governance News
Vendor AI News
Tool of the Week
Recommended Reading
Remember AI won’t take your job, but someone that knows how to leverage AI probably willin