Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

Defensive Security Podcast Episode 296

Feb 9, 2025
The discussion dives into the latest ransomware tactics, revealing how attackers target employees to exploit insider threats. There’s a deep look at the rise of LLM hijackers manipulating cloud accounts, highlighting the urgent need for better security measures. The ethics of phishing simulations come under scrutiny, advocating for supportive training instead of punitive measures. Cybersecurity professionals face challenges balancing risk with effective security, especially with the implications of generative AI in the workplace, where sensitive data can be at stake.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

The $700 AWS Bill

  • One person racked up a $700 AWS bill in 24 hours from LLM hijacking.
  • He luckily had billing alerts; otherwise, it could have cost $20,000.
ADVICE

Protect Your API Keys

  • Protect API keys and credentials to prevent LLM hijacking.
  • Compromised accounts can be used for malicious purposes, including generating illegal content.
ADVICE

Ethical Phishing Simulations

  • Design phishing simulations carefully, avoiding emotionally manipulative lures.
  • Overly effective tests don't teach good security practices.
Get the Snipd Podcast app to discover more snips from this episode
Get the app