• Shadow AI
  • Posts
  • šŸ¦¾ Shadow AI - 7 December 2023

šŸ¦¾ Shadow AI - 7 December 2023

Arming Security And IT Leaders For The Future

Forwarded this newsletter? Sign up for Shadow AI here.

Hello,

Sometimes I wonder if I should scale back Shadow AI, but thereā€™s so much happening in AI that Iā€™m finding it useful to hold me accountable to stay on top of the biggest happenings and what it means for security and IT. Iā€™d love to hear your ideas on how to continue to mature this newsletter in 2024 so it adds value amongst the slew of other newsletters out there.

This week we cover:

šŸ„ø An SEO Heist and What it Means for Security

šŸƒšŸ½ Geminiā€™s Release and Capabilities

šŸ¤šŸ» IBM and Metaā€™s AI Alliance

šŸ’£ AI Insight Forum Update

šŸ“ˆ Spear Investmentā€™s AI Value Chain

šŸ› ChatGPT vs Snyk Code

Letā€™s dive in!

Demystifying AI - An SEO Heist and What it Means for Security

AI isnā€™t only going to amplify existing threat vectors, itā€™s going to create new ones security and business professionals arenā€™t prepared to defend.  In this Twitter thread, Jake Ward describes how he used AI to "steal" 3.6M in total web traffic from competitors. The process involved identifying a competitor, exporting their sitemap, and using this data to generate article ideas. AI was then used to rapidly create and publish 1,800 articles in a few hours which quickly diverted traffic to his site. The results were notable:

  • 490K in monthly traffic

  • 3.6M in total traffic since publishing

  • 13K keywords on page 1 of Google

Security teams need to be prepared to help business teams, including marketing in this case, reduce the risk of being negatively impacted by the efficiency and scalability of AI. If youā€™re a Business Information Security Officer, start understanding all the different practical ways AI can impact your business units today. For example, new channels of threat intelligence may need to be established to monitor for SEO manipulation or attack tactics against a companyā€™s web properties. Incident playbooks may need to be expanded in many new ways, including how to swiftly respond to SEO-related incidents, attribute the bad actors, and take action.

At the same time, critical algorithms like SEO are going to need an overhaul to account for AIā€™s impact. The measurements of today are not going to work tomorrow. Ironically, higher quality, unique content (not AI driven) may need to be weighted more. Bad actors also will need to face strong penalties for engaging in this type of behavior.

AI News to Know

  • Geminiā€™s Release and Capabilities: Google released Gemini, a flexible three tiered, multimodal model for building and scaling AI at various complexities. Google claims that Gemini Ultra, its most advance model, outperforms GPT-4 across a range of text and multimodal benchmarks. How quickly will OpenAI counterpunch with GPT-5, or will that be slowed down with the recent governance changes?

  • AI Alliance: IBM and Meta launched the AI Alliance, a group of 50 organizations with an international reach across industry, startup, academia, research and government, to support open innovation and open science in AI. The alliance is focused on six areas, including AI benchmarking, regulation, and safety and aims to counterbalance the growth of closed AI models like OpenAI.

  • AI Insight Forum Update: Senator Schumerā€™s AI Insight Forum wrapped up its eighth and ninth closed door sessions yesterday covering ā€œdoomsday scenariosā€ and national security. As we head into 2024, Congress will hopefully find common ground in developing a legislative framework that balances short-term AI risk with doomsday scenarios and the risk of China outcompeting the U.S.

AI on the Market

  • AI Value Chain: Ivana Delevska and Spear Investments published a great deep dive on the AI value chain. Itā€™s focused on three main areas: hardware, data infrastructure, and AI applications. Securing the AI value chain will be increasingly important as AI usage expands and Spear sees the hardware and data infrastructure layers as areas with the most opportunities to capture value.

  • ChatGPT vs Snyk Code: James Berthoty, an application security guru and founder of Latio Tech, was impressed with ChatGPTā€™s performance as a security scanner compared to Snyk Code on straightforward python code. In a quick proof of concept with a general model, ChatGPT returned better results than Synk, one of the industry leaders in this space. Jamesā€™ proof of concept highlights how the static scanning market is at risk of getting upended with the emergence of a well trained application security focused LLM.

AI Prompt of the Week

I really like this output which provides a concrete 3 year plan for someone to gradually build their cybersecurity and AI expertise. I think the one area it should more clearly emphasize is networking in parallel to building oneā€™s skills. What else would you suggest for the training plan?

Have a favorite, funny, or doomsday security or IT prompt to share with the Shadow AI community? Submit it here and you could make the newsletter.

Reply directly to this email with any feedback, including your thoughts on the AI Prompt of the Week. I look forward to hearing from you.

If you enjoyed this newsletter and know someone else who might like Shadow AI, please share it!

Until next Thursday, humans.

-Andrew Heighington