News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

CERT-In issues security guidelines for Indian firms over AI risks
Cyber Law (India)

CERT-In issues security guidelines for Indian firms over AI risks

India's Computer Emergency Response Team (CERT-In) has released protective measures for organizations and small-to-medium enterprises (MSMEs) following emerging cybersecurity concerns related to Mythos AI. The advisory addresses potential vulnerabilities that could affect Indian businesses relying on artificial intelligence systems. CERT-In recommends implementing robust security protocols, regular system audits, and employee awareness training to mitigate risks. MSMEs are advised to adopt industry-standard safeguards and maintain updated security frameworks. The guidance aims to strengthen India's cyber defense posture amid growing AI-related threats in the digital landscape.

via GoogleNews: CERT-In advisoryRead source
India Seeks Access to AI Model for Cybersecurity Ahead of Public Release
Cyber Law (India)

India Seeks Access to AI Model for Cybersecurity Ahead of Public Release

Anthropic, an AI firm, is in discussions with various governments, including India, about enhancing cybersecurity measures before the public launch of its Claude Mythos AI model. This model is expected to reveal major vulnerabilities that could pose risks to critical infrastructure. As the Indian tech industry, represented by Nasscom, pushes for early access to the model, the government aims to better prepare for potential cyber threats. The collaboration is seen as vital for strengthening India's defenses against evolving cyber risks. Source: [publication name].

via Economic Times TechRead source
US Accuses China of Theft of AI Technology from American Labs
Cyber Law (India)

US Accuses China of Theft of AI Technology from American Labs

The White House has publicly accused China of engaging in large-scale theft of artificial intelligence technology from US labs. This practice is said to undermine American innovation and disrupt international technology relations. The US government plans to take steps to address this issue, reflecting escalating tensions over intellectual property rights in the technology sector. This development could have significant implications for global tech collaborations and economic policies. Observers see this as a pivotal moment in US-China relations regarding technology and innovation. Source: Financial Times.

via Economic Times TechRead source
Meta Faces Lawsuit for Alleged Profits from Scam Advertisements
Cyber Law (India)

Meta Faces Lawsuit for Alleged Profits from Scam Advertisements

The Consumer Federation of America has filed a lawsuit against Meta, claiming that the company has profited from advertisements promoting scams while misleading users about its commitment to safety. Internal documents indicate that Meta generates significant revenue from these scam ads, which raises concerns about its efforts to combat fraudulent activities. In response to these allegations, Meta has asserted that it plans to challenge the lawsuit, maintaining its stance on fighting fraud. This case highlights growing scrutiny over how social media platforms manage advertisements and user safety. Source: Consumer Federation of America.

via Economic Times TechRead source
US to Reassess Previous Green Card Approvals for Fraud Risks
Cyber Law (India)

US to Reassess Previous Green Card Approvals for Fraud Risks

The U.S. Citizenship and Immigration Services (USCIS) plans to review older green card cases from the Biden administration to investigate potential fraud. USCIS Director Joseph B. Edlow announced this initiative to implement more stringent oversight regarding green card issuance, coinciding with an increase in denial rates. The move aims at strengthening the integrity of the immigration process amid growing concerns about fraudulent applications. Individuals who have recently received green cards during this period might face additional scrutiny as part of this review. These changes highlight the ongoing challenges within the U.S. immigration system and reflect a shift towards more rigorous assessment practices. Source: [publication name].

via Economic Times TechRead source
Improving MTTR: Key Strategies for Effective Security Operations Centers
Cyber Law (India)

Improving MTTR: Key Strategies for Effective Security Operations Centers

In the realm of cybersecurity, Mean Time to Recovery (MTTR) is a vital metric for measuring how quickly a security team responds to threats. For organizational leaders, each moment a threat exists poses risks of data theft, service interruptions, and harm to the company's reputation. Interestingly, slow MTTR often isn't due to a shortage of analysts but rather structural issues within the team, particularly regarding the effectiveness of threat intelligence. Establishing a robust threat intelligence framework is crucial for expediting response times and ensuring better protection against cyber threats. Organizations should focus on optimizing their security operations to enhance responsiveness and minimize potential damages. Source: [publication name].

via The Hacker NewsRead source
Elon Musk Fails to Attend French Inquiry on X and AI Chatbot
Cyber Law (India)

Elon Musk Fails to Attend French Inquiry on X and AI Chatbot

Elon Musk did not attend a scheduled questioning in France regarding an investigation into X, the platform formerly known as Twitter, and its AI chatbot Grok. The Paris prosecutor's office is probing allegations of algorithm misuse and unlawful data extraction associated with the platform. This inquiry highlights growing concerns over the influence of technology firms and their accountability in managing user data and ethical standards in AI applications. The absence of Musk from the hearing raises questions about the responsibilities of tech leaders in legal proceedings related to their companies. Source: [publication name].

via Economic Times TechRead source
Deutsche Bank CEO on AI Risks and Regulatory Review
Cyber Law (India)

Deutsche Bank CEO on AI Risks and Regulatory Review

Christian Sewing, the CEO of Deutsche Bank, stated that banks are closely engaging with European regulators concerning Anthropic's AI model, Mythos. The model is under scrutiny as global regulators assess the potential cybersecurity risks it poses. There is a growing concern about how prepared financial institutions are to handle these risks, particularly in light of the increasing capabilities of artificial intelligence. This conversation highlights the urgency for banks and regulators alike to understand and mitigate any threats that new technologies may introduce in the financial landscape. Source: [publication name].

via Economic Times TechRead source
NSA Uses Anthropic's AI Tool Despite Security Concerns
Cyber Law (India)

NSA Uses Anthropic's AI Tool Despite Security Concerns

The US National Security Agency (NSA) is reportedly utilizing Anthropic's AI tool, Mythos Preview, despite warnings from the Pentagon about potential supply-chain risks associated with the company. Mythos is recognized for its advanced capabilities in programming and automation, which experts believe could bolster the NSA's capabilities in cyber operations. The use of this AI by a major national security agency raises questions about the balance between technological advancement and cybersecurity risks. Furthermore, there have been discussions between Anthropic and US authorities regarding these issues. This situation highlights the ongoing tension between innovation and security in the field of cybersecurity. Source: Axios.

via Economic Times TechRead source
NIST to Cease Rating Lower-Priority Vulnerabilities
Cyber Law (India)

NIST to Cease Rating Lower-Priority Vulnerabilities

The National Institute of Standards and Technology (NIST) announced it will no longer assign severity scores to lower-priority vulnerabilities. This decision comes in response to an overwhelming increase in the number of submissions, which has made it challenging for the agency to assess and manage all reported flaws effectively. By focusing on higher-priority issues, NIST aims to streamline its processes and better allocate resources. This change may impact how organizations prioritize their cybersecurity measures, as they will need to independently assess these lower-priority vulnerabilities. Source: cybersecurity publication.

via BleepingComputerRead source
Regulations Shape Growth of Razorpay, Says CEO Harshil Mathur
Cyber Law (India)

Regulations Shape Growth of Razorpay, Says CEO Harshil Mathur

Harshil Mathur, CEO of Razorpay, discussed the positive impact of regulations on business growth during his talk at YC Startup School. He pointed out that despite initial hurdles, such as losing bank support, the company has thrived in India's payments sector, which has surpassed $180 billion in transaction volume. Mathur credited the startup's adaptability, particularly its adoption of the Unified Payments Interface (UPI), for its success, especially during the rise of direct-to-consumer businesses amid the pandemic. These insights emphasize the balance between regulatory challenges and the potential for significant growth in a structured market environment. Source: [publication name].

via Economic Times TechRead source
Coast Guard's Cybersecurity Guidelines Provide Insights for CISOs
Cyber Law (India)

Coast Guard's Cybersecurity Guidelines Provide Insights for CISOs

The Maritime Transportation Security Act (MTSA) outlines new cybersecurity regulations for maritime operations, focusing on the protection of Operational Technology (OT) systems. These regulations mandate that organizations create comprehensive cybersecurity plans and undergo audits by independent third parties. Additionally, the Act emphasizes the importance of a hybrid security role that combines both IT and OT security responsibilities. Indian Chief Information Security Officers (CISOs) can draw valuable lessons from these guidelines to enhance their own cybersecurity frameworks and risk management strategies. Adopting a proactive approach in safeguarding critical infrastructure is essential for combating emerging cyber threats. Source: [publication name].

via Dark ReadingRead source