BitsnBytes-Winter2024-2025
Bits & bytes Winter 2024-2025 8 AI Impacts Cybersecurity I t is important to be aware that as the use of generative artificial intelligence (AI) solutions increases, the risk of AI attacks also grows. The U.S. Department of Health and Human Services, alongside its Health Sector Cybersecurity Coordination Center (HC3), released a briefing on AI and its impacts on cybersecurity in health care, as reported by Healthcare IT News ( July 19, 2023). The briefing aims to help hospitals and healthcare organizations stay secure against AI-enhanced cyber threats. The report highlights risks posed by large language models (LLMs) such as ChatGPT, which can create convincing phishing emails and automate attacks. For instance, ChatGPT can generate emails with correct grammar and persuasive content, making the scams more believable and challenging to detect. The briefing also highlights an example of malware code that leverages Microsoft Teams for data theft and developer tools to infiltrate networks. HC3 recommends penetration testing, automated threat detection, continuous monitoring, cyber threat analysis, and AI training for cybersecurity staff. AI can also help detect and prevent cyberattacks by scanning emails and automating security tasks. According to Netskope’s Cloud and Threat Report 2024 , users’ adoption of generative AI solutions has seen rapid growth from 2% prior to 2023 to 10% as of November 2023. The notable increase in the use of ChatGPT, Grammarly, and Google Bard (now called Gemini) underscores the urgent need to address potential risks associated with these technologies, according to KnowBe4 ( January 24, 2024). Cyberhaven, a data security services company, detected confidential data input into ChatGPT from 4.7% of 1.6 million workers at its client organizations, as the company reported in a blog (February 28, 2023). Examples include an executive who copied and pasted the company’s 2023 strategy document into ChatGPT to generate a PowerPoint presentation and a doctor who input sensitive information into a letter that was sent to the patient’s insurance company. Employees are entering sensitive business and privacy-protected data into LLMs, risking that AI services might incorporate this information into their model training. Without proper data security, this data could be retrieved later, which can lead to potentially severe consequences such as financial loss, reputation damage and legal implications. Continued on page 9
Made with FlippingBook
RkJQdWJsaXNoZXIy OTU2NTU4