The Security Risks Of ChatGPT

ChatGPT, developed by the artificial intelligence lab OpenAI, is a humanoid chatbot causing a global sensation. It is now the fastest-growing app in history, hitting 100 million active users in just two months - way faster than the nine months it took previous record-holder TikTok to reach that mark.

This powerful, open-source tool can do whatever you ask, including writing school essays, drafting legal agreements and contracts, solving complex math problems, and passing the medical licensing exam. It also has the potential to revolutionise the way businesses operate.

With ChatGPT, you can generate reports quickly and handle customer service requests efficiently. The tool can even write code for your next product offering, conduct market analysis and help build your company website.
But while ChatGPT offers many benefits to businesses, it poses urgent security questions. One of the critical risks associated with this technology is the power it gives cyber criminals with no coding experience to create and deploy malicious software.

With ChatGPT, anyone with bad intentions can quickly develop and unleash malware that wreaks havoc on companies.

The research unit of security firm Check Point Software have reported that, within weeks of ChatGPT's release, individuals in cybercrime forums, including those with limited coding skills, utilized it to create software and emails for espionage, ransomware attack, and malicious spamming. Check Point said it's still too early to tell if ChatGPT will become the go-to tool among Dark Web dwellers. Still, the cybercriminal community has demonstrated a strong interest in ChatGPT and is already using it to develop malicious code.

In one example reported by Check Point, a malware creator revealed in a cybercriminal forum that they were using ChatGPT to replicate well-known malware strains and techniques. As evidence, the individual shared the code for a Python-based information stealer that they developed using ChatGPT. The stealer searches, copies, and transfers 12 common file types from a compromised system, including Office documents, PDFs, and images.

ChatGPT Increases Everyone's Exposure To Hacking

Bad actors can use ChatGPT and other AI writing tools to make phishing scams more effective. Traditional phishing messages are often easily recognizable because they are written in clumsy English. But ChatGPT can fix this. Mashable tested ChatGPT's ability by asking it to edit a phishing email. Not only did it quickly improve and refine the language, but it also went a step further and blackmailed the hypothetical recipient without being prompted to do so.

While OpenAI says it has strict policies and technical measures in place to protect user data and privacy, the truth is that these may not be enough.

ChatGPT scrapes data from the web—potentially data from your own company—which brings security risks. For instance, data scraping can result in sensitive information, such as trade secrets and financial data, being exposed to competitors. There can also be reputational damage if the information obtained through data scraping is inaccurate. Moreover, when data is scraped, it can open systems to vulnerabilities that malicious actors can exploit.

Given that the attack surface has dramatically expanded due to the advent of ChatGPT, what impact does this have on your security posture?

Previously, small and mid-sized businesses may have felt secure, thinking that they were not worth the trouble of hacking. However, with ChatGPT making it easier to create malicious code at scale, everyone's exposure to cybercrime has significantly increased.

ChatGPT demonstrates that while the number of security tools available to protect you may be increasing, these tools may not be able to keep pace with emerging AI technologies that could increase your vulnerability to security threats. Given the spiralling threat of cybercrime, every business needs to be aware of the potential risks posed by ChatGPT and other advanced AI systems—and take steps to minimise those risks.

Measures You Can Take To Protect Yourself

Your first step is to understand just how vulnerable you are. Penetration testing, also known as pen testing, can help protect your data by simulating a real-world attack on your company's systems, networks, or applications. This exercise aims to identify security vulnerabilities that malicious actors could exploit so you can close them. By exposing your weaknesses in a controlled environment, pen testing enables you to fix those weaknesses, improve your security posture and reduce the risk of a successful data breach or other cyberattacks.

In the new world of ChatGPT, penetration testing can play a crucial role in helping you safeguard your data and ensure its confidentiality, integrity, and availability.

Companies must also double down on their data resilience strategy and have a solid data protection plan. A data resilience plan outlines the steps a business should take to protect its critical data and systems and how it will restore normal operations as quickly and efficiently as possible if a data breach occurs. It also provides a roadmap for responding to cyber threats, including detailed instructions for securing systems, backing up data, and communicating with stakeholders during and after an incident.

By putting a data resilience plan in place, businesses can minimise the impact of cyber threats and reduce their risk of data loss, helping to ensure their organisation's ongoing success and survival.

Another way of stopping ChatGPT-enabled script kiddies and bad guys is through immutable data storage. Immutability means data is converted to a write-once, read many times format, and can't be deleted or altered. There isn't any way to reverse the immutability, which ensures that all your backups are secure, accessible, and recoverable. Even if attackers gain full access to your network, they will still not be able to delete the immutable copies of your data or alter the state of that data.

Final Takeaway

While ChatGPT offers benefits to businesses, it also poses significant security risks. Companies must be aware of these risks and take steps to minimise them. They should invest in solid cybersecurity measures and stay informed about the latest security trends.

By putting the proper protection in place, organisations can realise the many benefits of ChatGPT while defending themselves against those who use the tool for malicious purposes.

Richard Massey is Vice President Sales, EMEA at Arcserve

You Might Also Read: 

AI Will Be Disruptive - For Both Security & Jobs:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« AI Generated Images Shake The Stock Market
Vulnerable Networks & Advanced Persistent Threats »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Clayden Law

Clayden Law

Clayden Law are experts in information technology, data privacy and cybersecurity law.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Resecurity, Inc.

Resecurity, Inc.

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Perforce Software

Perforce Software

Perforce helps companies build complex software products more collaboratively, securely, and efficiently.

Secure Identity Alliance (SIA)

Secure Identity Alliance (SIA)

The Secure Identity Alliance is dedicated to supporting sustainable worldwide economic growth and prosperity through the development of trusted digital identities and the adoption of secure eServices.

Competence Center for Applied Security Technology (CAST)

Competence Center for Applied Security Technology (CAST)

CAST offers a range of services in the field of secure modern information technology and a contact point for all questions regarding IT security.

Norwegian Business & Industry Security Council (NSR)

Norwegian Business & Industry Security Council (NSR)

NSR is a member organization serving the Norwegian business sector in an advisory capacity on matters relating to crime and security including cyber.

AnchorFree

AnchorFree

AnchorFree is a Virtual Private Network services provider offering secure encrypted access to the internet.

PT Netmarks Indonesia

PT Netmarks Indonesia

PT Netmarks Indonesia is an IT solutions provider offering services related to ICT infrastructure, digital transformation and cyber security.

Uleska

Uleska

Uleska is a scalable platform that provides automated and continuous software security testing whilst translating cyber risk.

Polish Centre for Accreditation (PCA)

Polish Centre for Accreditation (PCA)

PCA is the national accreditation body for Poland. The directory of members provides details of organisations offering certification services for ISO 27001.

Astaara

Astaara

Astaara is an integrated insurance services and risk management advisory business incorporating cyber risk advisory, underwriting and analytics.

1Kosmos

1Kosmos

1Kosmos provide Digital Identity and Passwordless Authentication for workforce and customers. Powered by advanced biometrics and blockchain technology.

Anthony Timbers LLC

Anthony Timbers LLC

Anthony Timbers is a cybersecurity consulting and penetration testing firm providing services to the Federal and Commercial sectors nationwide.

AgileBlue (Agile1)

AgileBlue (Agile1)

AgileBlue (formerly Agile1) is a managed breach detection company with an Autonomous SOC-as-a-Service for 24×7 monitoring, detection and guided response.

Cyber Security Cooperative Research Centre (CSCRC)

Cyber Security Cooperative Research Centre (CSCRC)

The CSCRC provides frank and fearless research and in-depth analysis of cyber security systems, the cyber ecosystem and cyber threats.

BlueHalo

BlueHalo

BlueHalo is purpose-built to provide industry capabilities in the domains of Space Superiority and Directed Energy, Missile Defense and C4ISR, and Cyber and Intelligence.

Votiro

Votiro

Votiro is an award-winning cybersecurity company that specializes in file sanitization, ensuring every organization is safe from zero-day and undisclosed attacks.

Krista Software

Krista Software

Krista is an intelligent automation platform that combines iPaaS and Conversational AI to automate complete business processes across your teams and apps.