
How one researcher used ChatGPT to fool a hacker
The release of GPT-4 back in March has changed enterprise security forever. While hackers have the ability to jailbreak these tools and generate malicious code, security teams vendors have also begun experimenting with generative AI’s detection capabilities. However, one security researcher has quietly developed an innovative new use case for ChatGPT: deception.

Checks joins Google with LLM-driven mobile app compliance scanner
Today, Checks, a privacy platform for mobile app developers, released a new blog post announcing it is now a fully integrated Google product after being launched as part of Google’s in-house incubator in 2022.

Google says goodbye to passwords with passkeys launch
Today, Google announced that it is rolling out support for passkeys across Google accounts on all major platforms. As of today, users can now use passkeys for a passwordless sign-in experience on apps and websites with fingerprinting, facial recognition or a local pin without the need to enter a password or complete 2-step verification (2SV).

GitLab turns to Google Cloud and generative AI to accelerate DevSecOps
Today, DevSecOps platform GitLab and Google Cloud announced an extension of their strategic partnership to deliver new privacy-first AI offerings to enterprise customers.

Report shows 92% of orgs experienced an API security incident last year
Today, application security provider Data Theorem, announced the release of a new report in partnership with TechTarget's Enterprise Strategy Group (ESG). ESG surveyed 397 respondents on cloud-native applications and API security and found that 92% of organizations experienced at least one API-related security incident in the last 12 months.

Private AI's PrivateGPT aims to combat ChatGPT privacy concerns
Today, data privacy provider Private AI, announced the launch of PrivateGPT, a “privacy layer” for large language models (LLMs) such as OpenAI’s ChatGPT. The new tool is designed to automatically redact sensitive information and personally identifiable information (PII) from user prompts.

3CX data breach shows organizations can’t afford to overlook software supply chain attacks
Last month, VoIP provider 3CX experienced a data breach after an employee downloaded a trojanized version of Trading Technologies’ X_Trader software. After breaking into the vendor’s environment, North Korean threat actors then used an exploit to ship malicious versions of the 3CX desktop app to downstream customers as part of a software supply chain attack.

Q1 marked lowest VC funding for security in a decade, but there’s a silver lining
Today, DataTribe released a new report showing venture capital activity in the cybersecurity industry dropped significantly in Q1 2023.

Tenable report shows how generative AI is changing security research
Today, vulnerability management provider Tenable published a new report demonstrating how its research team is experimenting with large language models (LLMs) and generative AI to enhance security research.

US senator open letter calls for AI security at ‘forefront’ of development
Today, Sen. Mark Warner (D-VA), chairman of the Senate Intelligence Committee, sent a series of open letters to the CEOs of AI companies, including OpenAI, Google, Meta, Microsoft and Anthropic, calling on them to put security at the “forefront” of AI development.

RSAC 2023: SecurityScorecard launches ‘first’ GPT-4 security ratings platform
Today, at the RSA Conference (RSAC) 2023 in the Moscone Center in San Francisco, cybersecurity and risk management vendor SecurityScorecard announced the launch of the “first” GPT-4 security ratings platform.

BigID launches BigAI, a ‘privacy-by-design’ LLM designed to discover data
Today, data discovery and classification provider BigID announced the launch of BigAI, a new large language model (LLM) designed to scan and classify enterprises’ data to optimize their security and enhance risk management initiatives.