Posts

Showing posts with the label AIsecurity

ChatGPhish Follow-Up - OpenAI Still Hasn’t Confirmed a Fix

Image
https://youtu.be/FtQIWChP5is OpenAI responded to my question about the publicly reported ChatGPhish issue — but the answer leaves everyday users with something important to think about. In this Bob The Cyber-Guy follow-up, I break down what this means in plain English, without panic, hype, or tech confusion. If you use ChatGPT or any AI tool to summarize web pages, this is one of those “better know it before you need it” safety lessons. The big question is simple: When an AI tool shows you a link, QR code, image, warning, or login prompt… should you trust it? The answer may surprise you — and it could save you from clicking the wrong thing at the wrong time. Created by Norbert “Bob” Gostischa, Bob The Cyber-Guy, with help from ChatGPT and NotebookLM Slide Deck. All videos featuring Cyber-Bob are available here: https://youtube.com/playlist?list=PL1_9cbkt8g23Y9OlMqTZElR_JO20E0AGy&si=vb75DBhUg_ZJarby Stay safe, stay secure, stay curious, and remember my friends—you’re never too old t...

AI Convenience vs Personal Security - Should AI Know Your Passwords?

Image
https://youtu.be/GHCleH9Iouk 🤖In this episode, Bob the Cyber-Guy takes a closer look at a new Windows 11 Copilot feature that could allow AI assistants to interact with websites and potentially sync login credentials. Sounds convenient, right? But convenience and security don’t always travel together. In this short, easy-to-understand presentation, Bob explains: 🔹 What the new Copilot feature is designed to do 🔹 Why tech companies want AI to help with browsing and logins 🔹 The hidden cybersecurity risks many people never consider 🔹 Why sharing personal information with AI can be dangerous 🔹 The simple rule everyone should follow to stay safe online AI can be an amazing tool for learning, productivity, and creativity—but when it comes to passwords, financial data, and personal identity, a little caution goes a long way. Because in cybersecurity… Just because you can share something with AI doesn’t mean you should. Stay curious. Stay cautious. Stay secure. (ChatGPT, NotebookLM'...

One Click, Many Risks - Prompt Injection in Comet and Other AI-Powered Tools

Image
This information is also available on my  YouTube Channel  at:  https://youtu.be/1eGE8cTSwAY If you prefer, you can also listen to this information on  my  Podcast  at:  https://open.spotify.com/episode/7EXmsWfOK5eaVGLatIQGfx?si=cuEeU1PeQCypYJBk60elNw https://open.spotify.com/episode/2J23JX0aa0ci27OdN5B3CB?si=lOXtRMEoQ_i64hjxr_tJ7w   Security researchers have uncovered a new exploit dubbed CometJacking that turns a single malicious click into a silent data leak. While it was demonstrated on the Comet Browser’s built-in AI agent, the bigger story is that this type of attack could hit any AI-enabled browser or tool that mixes untrusted content with privileged access. How CometJacking Works: Comet is marketed as an “AI-native” browser. Instead of just displaying websites, it runs a built-in assistant that can read your email, calendar, documents, and other connected services to help you work. A malicious link can hide a prompt-injection payload that ...