CyberWire Daily: X's Grok Controversy, Data Breaches, and CISO Legal Risks
N2K NetworksJanuary 6, 202624 min430 views
24 connectionsΒ·40 entities in this videoβGrok's Non-Consensual Imagery Sparks EU Scrutiny
- πͺπΊ The European Commission is considering enforcement action against X (formerly Twitter) due to its AI tool, Grok, generating sexualized images of a minor.
- β οΈ Grok has also been misused to create non-consensual sexual imagery of women, and previously spread Holocaust-denying material.
- βοΈ This scrutiny intensifies tensions between the EU and US over platform regulation, with France and the UK also investigating.
Major Data Breaches Linked to Single Threat Actor
- π Researchers have linked numerous major data breaches to a threat actor known as Zestics (persona Scentap), who acts as an initial access broker.
- π Zestics exploits stolen credentials, often harvested by info-stealer malware, to gain access to enterprise networks and sell data and access.
- π Weak security, particularly the lack of multi-factor authentication on file-sharing services, enables these repeated compromises across various sectors.
UK's New Cyber Action Plan and Sector-Specific Threats
- π¬π§ The UK government has launched a new cyber action plan with a centralized cyber unit and a software security ambassador scheme, backed by 210 million pounds.
- π― A stealthy ClickFix phishing campaign is targeting the hospitality sector using fake Booking.com cancellation emails to deploy RATs.
- πΎ New VVS Stealer malware, sold as a subscription on Telegram, targets Discord users by stealing authentication tokens and harvesting credentials from browsers.
Healthcare Data Leaks and a Critical Dolby Flaw
- π₯ Covenant Health is notifying nearly 478,000 patients of a May 2025 cyber attack, potentially exposing personal, insurance, and medical information.
- π AFLAC is notifying 22.6 million people of a June 2025 cyber attack, with compromised data possibly including social security numbers and health details.
- π± Google has patched a critical vulnerability in the Android implementation of Dolby software, which could lead to data leakage.
SolarWinds Dismissal and CISO Legal Landscape
- π§ββοΈ Ilona Cohen of HackerOne discusses the implications of the SolarWinds CISO charges dismissal, noting a recalibration by the SEC.
- π The dismissal was influenced by a court rejecting the SEC's broad theory that internal accounting rules could cover cybersecurity program design.
- π‘οΈ While personal risk for CISOs may be reduced, the SEC's authority to police misleading statements to investors regarding cybersecurity remains, emphasizing the need for accurate public disclosures.
Knowledge graph40 entities Β· 24 connections
How they connect
An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.
Hover Β· drag to explore
40 entities
Chapters8 moments
Key Moments
Transcript84 segments
Full Transcript
Topics15 themes
Whatβs Discussed
GrokX (formerly Twitter)European CommissionData BreachesThreat ActorCyber Action PlanClickFix CampaignVVS StealerDiscordCovenant HealthAFLACDolbySolarWindsCISOSEC
Smart Objects40 Β· 24 links
ProductsΒ· 3
PeopleΒ· 5
EventsΒ· 4
MediasΒ· 3
CompaniesΒ· 12
ConceptsΒ· 10
LocationsΒ· 3