Google Unveils Enhanced Privacy Measures for Gemini AI
This week, Google introduced new hardware and updates to its Gemini AI platform. A highlight is the Gemini Nano model, designed for offline-only processing of various AI tasks, such as generating smart keyboard responses, taking call notes, detecting scams, and summarizing content. For certain functions, however, processing will be shifted to Google’s cloud infrastructure. The company assures that in these instances, it will not involve third-party AI providers. All sensitive data will be handled within a secure cloud environment, offering users control and transparency over any cloud-based interactions. Google plans to release a detailed white paper outlining the end-to-end security measures of its cloud AI services soon.
MIT Launches Comprehensive AI Risk Database
MIT has introduced a new AI Risk Repository aimed at systematically cataloging and analyzing risks associated with emerging AI technologies. This repository provides a structured, publicly accessible database of AI-related risks, classified by factors such as origin (AI vs. Human), intent, and timing. It currently features over 700 distinct risks derived from more than 3,000 incidents involving significant harm or near misses. The creators hope this resource will assist organizations in deploying AI responsibly and foster further academic research into potential future risks. A link to the repository is available in our show notes.
Russian Intelligence Escalates Targeted Phishing Attacks
Recent research by Citizen Lab and Access Now reveals that Russian intelligence agencies, including the FSB, have intensified their efforts in highly targeted phishing attacks. These attacks, tailored to specific individuals and organizations, have affected entities such as the Russian rights group First Department, Proekt Media, former US ambassador Steven Pifer, and former president Donald Trump’s campaign. Two distinct groups, ColdRiver (linked to the FSB) and ColdWastrel, have been identified in these operations. Citizen Lab has shared technical insights with email providers to help mitigate future threats.
Deepfake Webcam Software Gains Popularity
GitHub’s trending repositories have recently featured Deep-Live-Cam, a software that creates deepfake videos by applying a single photo to a live webcam feed. Since its debut in late 2023, it has quickly gained traction. The tool employs the “inswapper” model to perform face swaps and uses the GFPGAN model to enhance image quality. It supports GPU acceleration on Nvidia and Apple Silicon hardware. Users are advised to establish secure code words with family members to prevent misuse of this technology.
AutoCanada Experiences Cyberattack
AutoCanada, which operates 84 car dealerships across Canada and the US, has reported a cyberattack that disrupted its IT systems over the weekend. Although it remains unclear if data was stolen, the attack affected network operations. The company has not yet identified any ransomware group claiming responsibility. This incident follows AutoCanada’s recent recovery from the CDK Global IT outage that occurred earlier this summer.
Troy Hunt Analyzes NPD Data Breach
Security researcher Troy Hunt has investigated the recent leak from the National Public Data (NPD) aggregator, which was reported to include 2.9 billion entries with social security numbers. Hunt expressed skepticism about the leak’s size, noting that it exceeds the US population. The data set contained numerous duplicates and deceased individuals. Additionally, there were fragmented leaks that did not include social security numbers but did reveal 134 million unique email addresses. Hunt has included these email addresses in the Have I Been Pwned service, clarifying that they are not directly associated with social security numbers.
India Enforces Strict Regulations on Spam Calls
India’s Telecom Regulatory Authority has mandated that service providers block all promotional calls from unregistered senders, including pre-recorded and automated calls. Providers who fail to comply face disconnection from telecom services for up to two years. Once a spammer is identified, service providers must inform other providers within 24 hours and cut off the associated phone lines. Recent reports indicate that spam calls are a daily nuisance for many people in India, often used for fraudulent schemes or social engineering.



