Smashing Security podcast #480: This is the AI service you should never sign up to
ID: e7fcc598-a0d3-50a7-b3e4-44b5419683ad
STIX ID: report--e7fcc598-a0d3-50a7-b3e4-44b5419683ad
Feed Name: Graham Cluley
This podcast episode covers two active cybersecurity threats: "Poison Claude," a criminal service that creates large numbers of fraudulent AWS accounts to harvest free Bedrock/Anthropic credits and resells AI access while capturing users' prompts and data (researchers found exposed API endpoints); and "Greatness," a phishing-as-a-service kit that abuses Microsoft's legitimate device-code OAuth flow to trick users into approving attacker access tokens, enabling account takeover and data access. Both stories describe live abuse, privacy and confidentiality risks, and recommend controls such as disabling unused device-code flows, restricting OAuth consent, and avoiding untrusted cut-price AI services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
