March 2025 News & Tips | AI, Apple, and Security Patches

March 2025 News & Tips | AI, Apple, and Security Patches
View this email in your browser
The mission of this publication is to cut through the clutter of cybersecurity news stories and provide you with the most important, relevant and actionable cybersecurity information.

If this newsletter adds value, fantastic! That is the goal. Please forward it on to friends/colleagues. If not, no hard feelings. Please look to the bottom for an easy to click "unsubscribe" button.
Subscribe
In this issue:
Month's News in Review
Upcoming Speaking Events
TCE Strategy in the News
Must Read Articles This Month
Cybersecurity Tip of the Month
Enjoy this month's newsletter? You can use this link to post on social media or send to friends! Thanks for sharing!
This Month's News in Review

Welcome back to the monthly TCE Strategy newsletter! From AI to Apple to the privacy of your data, March definitely came in like a lion. Time will tell if it goes out like a lamb. Let’s see how this month’s cybersecurity news can help us make better decisions about what is Secure Enough for us, our families, and the companies we work for.


How Does AI Really Work?

The truth is that we don’t have a firm grip on how AI works, or more importantly the Large Language Models (LLMs) which are the underpinnings of AI. Sure, we can describe the engineering and implementation of them, but comprehending why they come up with the answers they come up with is not well understood. Predicting the output isn’t easy. It’s not as if we have no clue, but I think of our understanding of LLMs as similar to our ability to predict the weather. We have a lot of good ideas and models, but predicting what the weather will be a month from today is anybody’s guess.

This leads to some rather terrifying considerations when it comes to cybersecurity, and frankly to morality. As LLMs are used for triaging patients in hospitals, grading student assignments, and drafting legislation, our inability to understand what is really “going on under the hood” of AI will definitely lead to unintended consequences. Here are a couple of recent examples:

Several AI models were taught to play chess, and they were then put up against the best chess computer in the world. The AI engines cheated up to 37% of the time by rearranging the pieces in their favor (in effect, making illegal moves).

An AI engine was used to write computer code. The designer of the AI engine taught it to purposely write “back doors” into its code and not tell the person using the AI engine about it, so a cybercriminal could gain unauthorized access to the systems that used the code.

AI engines have been asked to explain their reasoning on how they arrived at an answer. They have been caught deliberately misleading their users about their “thought process”.

Takeaway: AI is very useful, but it is in its infancy, and like essentially all technology, it is morally agnostic. Take the answers you receive from AI with a serious grain of salt.


The UK Government Seeks to Strip Citizens’ Right to Privacy

Apple has long touted privacy as a feature of its products, going at least as far back as 2015, when the FBI demanded that Apple reverse-engineer a feature of their phones, the feature that would wipe all data from an iPhone when the wrong password was entered 10 times. The FBI had good reason to ask: A terrorist killed 14 people and injured 22 others in San Bernadino, CA, and the FBI wanted to search the terrorist’s phone to see if other attacks were planned. Apple refused, stating that if they did this, they couldn’t uninvent it, and it would be a slippery slope into people’s privacy. It went to court, and then 

quietly disappeared because the FBI found another way into the phone. An identical scenario played out in 2020 regarding a shooting at the Naval Air Station in Pensacola, FL.

Fast forward 9 years. In a rather stunning move, the UK government sent a demand letter to Apple in early February regarding its “Advanced Data Protection” or ADP. ADP stores the data in users’ iCloud accounts using a special type of encryption where only the user can unencrypt their data. Apple literally can’t do it. The UK government demanded that Apple build a back door into the ADP product so that they can crack the encryption when the UK government wants them to. While Apple refused to implement a back door into ADP, on February 21st, Apple removed access to ADP from all British iCloud accounts, effectively giving the UK government what they asked for. Then on March 5th, Apple challenged the UK govt’s data access order in court. However, any hearings on this are being kept confidential, so on March 14th, the US government sent a bipartisan letter to the Lord Justice overseeing the case demanding that the hearings be made public

Takeaway: If you are an iPhone user and live in a country that allows ADP, turn it on. If you live in a country where the feature isn’t available, petition your government to allow it. Privacy is a fundamental human right.


Patch Early, Patch Often

March has had a rash of patches for cybersecurity vulnerabilities that are particularly serious. Microsoft Windows’ “Patch Tuesday” fixed six vulnerabilities that are being actively exploited in the wild. VMWare’s server virtualization product has three actively exploited vulns that patches came out for on March 4th, including  one that allows escape from a virtual computer to the physical computer that it is running on, which is the “nuclear option” of virtualization vulnerabilities. Patches were released on March 18th for websites running Apache Tomcat. This fixes a vulnerability where a remote, unauthenticated attacker can run arbitrary code (read: take your website over). That’s just about as bad as website vulnerabilities get.

Takeaway: Cybersecurity is a process, not an event. Computers need patching to fix vulnerabilities, and it’s up to us as users to set our devices to auto-patch.

 

Until next month, stay safe!

Upcoming Speaking Events

Here is a list of the cities that I will be in over the next several months. Please reach out if you have an event in mind!


March 25-31, Oklahoma City, OK

April 1-4, New Orleans, NV

April 15-18, Las Vegas, NV

May 2-4, Brainerd, MN

May 14-15, Des Moines, IA

May 26-30, Las Vegas, NV

June 3-6, Victoria, BC, Canada

July 3, Brainerd, MN

July 9-21, Dublin, Ireland

July 22-24, Orlando, FL

August 24-27, Indianapolis, IN

October 21-23, Lansing, MI

October 29-30, Worcester, MA

November 10-12, Austin, TX

TCE Strategy in the News

Thank you to the National Speaker’s Association for honoring me with a designation of Certified Speaking Professional, or CSP!

Interesting Articles

Don't lie about having reasonable cybersecurity. If you get caught (or get hacked), it can be extremely expensive. Just ask these guys (Health Net Federal Services / Centene Corporation). "According to prosecutors, between 2015 and 2018 the company — which administered the Tricare healthcare program for 22 states — 'falsely certified compliance' with certain cybersecurity controls required of federal contractors. The company allegedly failed to scan for known vulnerabilities in a timely fashion and to address security flaws on its networks."
There are very effective mitigations to this type of attack. Reach out to me if interested in more information. "Along with the claimed 300 percent surge in face swap attacks – where someone uses deepfake tech to swap out their face for another in real time to fool victims, like what was used to trick a Hong Kong-based company out of $25 million last year – iProov also claimed it tracked a 783 percent increase in injection attacks targeting mobile web apps (ie, injecting fake video camera feeds and other data into verification software to bypass [PDF] facial-recognition-based authentication checks) and a 2,665 percent spike in the use of virtual camera software to perpetrate such scams."
"The requirement that the company, Background Alert, close its doors for failing to register is unprecedented. Background Alert, which is based in California, agreed to the settlement terms ... The Delete Act requires data brokers to register with the state annually and pay a fee. Those fees are funding the construction of a tool consumers can use to compel all brokers to delete their personal data with the push of a button, according to the CPPA."



 
Sweden, this is a mistake. You can't make a backdoor just for you. The USA tried it with Clipper chip 30 years ago. It didn't work then and it won't work now.
Cybersecurity Tip of the Month
 
 
 Spring Cleaning: Safely Disposing of External Hard Drives and USB Drives

We have officially entered Spring and many of us will surely have the "spring cleaning" bug very soon. If you come across old USBs or hard drives that you decide to get rid of, please keep these things in mind before you do.

When selling, donating, or disposing of old USB drives or hard drives, many people think they can simply delete the files and they will be safe. This is not true, however. Third-party data recovery software programs can often restore these files, meaning that any sensitive documents or data on these drives could be exposed or fall into the wrong hands.
 
There are several different ways you can securely wipe these devices:
 
-Formatting an external device: Windows and Mac operating systems come with built-in format options for erasing hard drive data. You can follow a few simple steps to initiate this method which performs a write-zero pass, filling the storage space with zeros. To see more detailed step-by-steps for Windows and MacOS, 
visit this article.
 
-Erasing data on external drives using an app: There is no shortage of apps, paid and free, that will perform a data erasure service for you. Some of these are 
described more in depth here and include:
 
              -Android: Secure Eraser, Shreddit
              -Windows: CCleaner, Eassos PartitionGuru, MiniTool Drive Wipe
              -MacOS: StellarWipe Mac, Mac Washing Machine Secure X9
              -Windows and MacOS: AweEraser, Super Eraser
              -Windows, MacOS, and Linux: WipeDrive
 
-Erase hard drives using Darik’s Boot-and-Nuke (DBAN) software: DBAN is a free data destruction program used to completely erase all the files on a hard drive. This is a great free program but will erase EVERYTHING on the hard drive, including applications, personal files, and operating systems, so it needs to be used carefully and intentionally. These articles give some very helpful tips and steps for using DBAN:
 

https://www.lifewire.com/dban-dariks-boot-and-nuke-review-2619130
https://www.lifewire.com/how-to-erase-a-hard-drive-using-dban-2619148
 
-Using the cipher command: Cipher.exe is a built-in command line tool in the Windows operating system that can be used to encrypt or decrypt data on drives and can be used to securely erase the free space on a drive, meaning you must first format the drive so it is all free space. A short tutorial on using cipher can be found 
here.
 
If you are disposing of a USB or external hard drive for any reason, be sure to do your due diligence. Double check what data is on the drive, determine how sensitive it is, and decide on the best way to ensure it is erased from the drive. And if in doubt, a good old fashioned hammer will always get the job done.
LinkedIn
Twitter
Facebook
Website
Forward Forward
We want your feedback!

< On a scale of 10, how helpful was this newsletter?>

lowest 1   2   3   4   5   6   7   8   9   10   highest

Copyright © 2025 TCE Strategy, All rights reserved.
You are receiving this email because you are on Bryce Austin's contact list

Our mailing address is:
TCE Strategy
18268 Java Trl
Lakeville, MN 55044

Add us to your address book


Want to change how you receive these emails?
You can update your preferences or unsubscribe from this list

You can reach Bryce at bryce@bryceaustin.com

Email Marketing Powered by Mailchimp
Subscribe to Newsletter

Browse newsletter archives: