On a good day
The Khaleej Times Jost informed me on how a good day comes to pass. Here (at https://www.khaleejtimes.com/uae/meet-the-uae-police-officer-who-uncovered-183-money-laundering-cases-in-15-years) we are introduced to Major Saad Ahmed Al Marzooqi.
The headline ‘Meet the UAE police officer who uncovered 183 money laundering cases in 15 years’. We are also given “He was recently appointed as the first Emirati member of the Financial Action Task Force’s (FATF) International Cooperation Review Team” and we can be mesmerised, or brag about his abilities, but the numbers imply that he slightly uncovered more than one case a month. There are plenty of police forces all over the world where half of these numbers would imply a stellar career. As we gawk over “exposed 183 money laundering cases that are related to drugs and financial embezzlement. He had also created a database of incidents, which contributed to an increase in convictions from a monthly average of 3 to 14” we need to realise that the increase of 3 to 14 implies that this one person achieved more than any average police station in Europe.
This is the kind of man the world needs and that will be explained in the next article, because the universe relies on balance and the imbalance we are about to see takes the cake and changes an optional day to night.
On a bad day
Yes like any hero that needs a antagonist to make things interesting, we have Microsoft in two mentions. Now this isn’t directly involving anyone at Microsoft, but the follies are a setting that makes things a lot worse.
First we get Wired (at https://www.wired.com/story/microsoft-copilot-phishing-data-extraction/) who gives us ‘Microsoft’s AI Can Be Turned Into an Automated Phishing Machine’ we get to see “Attacks on Microsoft’s Copilot AI allow for answers to be manipulated, data extracted, and security protections bypassed, new research shows” which is not good, but anything positive can me mauled into a criminal jester for organised crime. The additional “Microsoft raced to put generative AI at the heart of its systems. Ask a question about an upcoming meeting and the company’s Copilot AI system can pull answers from your emails, Teams chats, and files—a potential productivity boon. But these exact processes can also be abused by hackers.
Today at the Black Hat security conference in Las Vegas, researcher Michael Bargury is demonstrating five proof-of-concept ways that Copilot, which runs on its Microsoft 365 apps, such as Word, can be manipulated by malicious attackers, including using it to provide false references to files, exfiltrate some private data, and dodge Microsoft’s security protections.” Now, I haven’t seen this, but Wired has a solid enough level of credibility to not ignore this. And that isn’t all. Bargury gives the world “the ability to turn the AI into an automatic spear-phishing machine. Dubbed LOLCopilot, the red-teaming code Bargury created can—crucially, once a hacker has access to someone’s work email” as I speculatively see it a mediocrity solution to turn the Internet of Things into a machine serving organised crime, optionally the NSA too, well done Microsoft. As I see it, the workload of Major Al Marzooqi would increase fivefold when this hits the open world, actually it already has if I understood the words from Michael Bargury correctly. In this, we optionally an even bigger problem, or at least a lot of corporations will.
You see there is a second message, in this case from Cyber Security News (at https://cybersecuritynews.com/microsoft-entra-id-vulnerability/). They give us ‘Microsoft Entra ID (Azure AD) Vulnerability Let Attackers Gain Global Admin Access’ with the subtext “Security researchers have uncovered vulnerabilities in Microsoft’s Entra ID (formerly Azure Active Directory) dubbed “UnOAuthorized” which could allow unauthorised actions beyond expected controls” Now take these two parts together and the phishing expedition could hit every R&D system on the planet using Azure. I am certain that Microsoft will have some patch coming soon, but in the meantime the bulk of R&D (under Azure) will be vulnerable and approachable by many hacker and especially organised crime, because selling secrets to competitors tends to be a lucrative setting and most corporations aren’t that finicky in acquiring something that raises (and assures) the bonuses of the members of their boardroom. OK, this is speculative on my side, but wonder what some will do to get the upper hand in business, especially if there is a bonus raise involved.
I wish I had a solution, but my personal feeling is that Microsoft has too many holes, loops and a whole rage of other issues and switching to either AWS, IBM cloud or Google Cloud tends to be an essential first step coming to my mind. Now, if there are sceptics who think that I am anti-Microsoft here, they are probably right. Therefor the Links to the two articles were added letting you look at the stories yourself. In the meantime I remember a story in April and it should be my ‘duty’ to inform SAMI that ‘BAE Systems and Microsoft join forces to equip defence programmes with innovative cloud technology’ had a nice article and with the two articles mentioned, SAMI could lay its hands on a truckload of BAE IP. Not sure how far they will get, but free IP is the way to go I say. So when you realise that a large corporation like British Aerospace with all the civilian and military hardware can be accessed, what chances do you think that Novo Nordisk (Denmark), LVMH (France), ASML (Netherlands), SAP (Germany), Hermez (France), L’Oreal (France) have? I do not know if any uses Azure, but it is a good moment for them to select one of the other companies. They could after the event sue Microsoft for damages, but Delta Airlines is already suing CrowdStrike and I am not sure how that will go. In the end it is my personal opinion that this could potentially bite Microsoft hard and it is one of the reasons I do not let them near my IP.
As I personally see it, the companies racing the be the first to launch their (fake) AI will now have a much larger impact. There were already fake data issues, but now the phishing options that are mentioned and when that gets linked to what Cyber Security News calls “UnOAuthorized” the entire IT game changes dramatically and I have no idea how that will play out.
As my Sunday is almost over and Vancouver only just started there’s a chance we postulate that the next 72 hours will be an interesting one. Have a lovely day (when you are not on Azure).






