Connecting IT and OT needs to be strictly monitored
"Organizations should focus on maintaining clear security boundaries as these environments become increasingly connected: segmenting networks, limiting communications between systems, ensuring applications can only perform approved actions, and applying least privilege consistently across both operational and corporate environments. Physical systems may now share data with cloud services and AI platforms, but they shouldn’t automatically share trust. " - Danny Jenkins
From the ThreatLocker blog
What the EU AI Act means for your security team
High-risk AI systems face new cybersecurity requirements
The EU AI Act introduces cybersecurity requirements that vary based on how AI is used and an organization's role. For high-risk systems, requirements include risk management, access controls, logging and traceability, human oversight, monitoring, and incident response, and rules begin applying December 2027. The Act applies to deployers located in the EU and where the system's output is used in the EU.
Don't wait for the deadline. Inventory your AI systems, map their permissions, control what they can access and execute, and make sure you can prove those safeguards work.
Policy defines what should happen—controls determine what is actually allowed
Policies do not enforce themselves, and vague rules such as "use AI responsibly" give security teams little to technically enforce. To close the gap between policy and execution, organizations need to translate expectations into specific, enforceable controls.
Effective policies should specify the system, data, user, action, and conditions involved. This way, they can be tested, monitored, and enforced while preventing AI tools from operating outside their intended boundaries.
Ransomware does not need unlimited power if the environment gives it unlimited access
Remote encryption is often a workstation issue that becomes a file server problem. If a compromised workstation can reach a share and write to the files, ransomware may be able to encrypt them remotely. Write access can be enough to cause a problem.
Access should come with an expiration date. Instead of leaving access continuously available, organizations should limit when devices can reach sensitive files and remove access when it is no longer needed.
On demand · Debunking the cybersecurity myths that leave you exposed
Will the AI kill switch work how we think? Do more controls equal stronger security? And are longer, more complex passwords enhancing account security?
AI coding agents exposed internal company data on GitHub
More than 13,000 images from 300+ organizations were reportedly exposed
What's happening: Researchers found that AI coding agents asked to share code changes for review uploaded internal company images to public GitHub repositories, including screenshots of unreleased features and customer billing records. Most images appeared under developers' personal accounts, putting them outside their organization's visibility.
What defenders need to know: Don't rely on individual developers to configure AI agents safely. Centrally control what agents can publish externally, and require human approval before an agent creates a public repository or changes a private repository to public.
Attackers abuse custom GPTs to deliver RAT via ClickFix lures
Victims reportedly interacted with attacker-created Custom GPT
What's happening: Researchers observed users interacting with a malicious custom GPT hosted on the legitimate ChaptGPT website. The GPT was reportedly programmed to respond to prompts with a Google Sites link that initiated a ClickFix-style attack and ultimately delivered a remote access trojan (RAT).
What defenders need to know: The attack reportedly began with sponsored search results for "chatgpt" on Google. Users should avoid sponsored links when accessing AI tools and use caution when given instructions asking them to copy, paste, or run commands. Consider restricting command interpreters and scripting tools to users and applications that actually need them.
Upcoming events
Meet the ThreatLocker team next week in:
Munich·Barcelona·Charlotte· San Diego· Buenos Aires · Atlanta