About Members News Events Trainings Career Catalog Log In Join TR

STM Announced the Cyber Threat Status Report Covering the Second Quarter of 2023

STM Announced the Cyber Threat Status Report Covering the Second Quarter of 2023

In its newly announced Cyber Threat Status Report, STM stated that as a result of an outage in the artificial intelligence tool ChatGPT, some users; He pointed out that his personal information and credit card information were leaked. In the report, STM also examined the cyber security competency model in critical energy facilities and the precautions that should be taken in cyber-physical systems.

STM, which has undertaken important projects and domestic products in the field of cyber security in Turkey, is known as the Technological Thought Center.ThinkTech” announced the new Cyber Threat Status Report covering April-June 2023. The report prepared by STM's cyber security experts has 8 different topics. The report includes many current and interesting topics such as outages and vulnerabilities in the artificial intelligence tool ChatGPT, the cyber security competency model in the energy sector, the security of cyber-physical systems, and the countries that carry out the most cyber attacks.

Information of Some Users Leaked on ChatGPT

While "ChatGPT Plus", the paid subscription version of ChatGPT, which is one of the most popular artificial intelligence applications of recent times and exceeded the 100 million user threshold in its first months of release, was launched in February, ChatGPT experienced a few hours of outage in the last week of March. According to STM's report, an open source library used by ChatGPT caused this outage and there were vulnerabilities in this library that allowed users to see each other's chat histories. In its statement, OpenAI pointed out that if 1.2 percent of users with ChatGPT Plus membership actively used the platform in a certain time period, data disclosure in payment information came to the fore. In the report, active users in that time period; It was determined that data such as name, surname, e-mail address, billing address, credit card type, last four digits of the credit card and expiration date of the credit card were displayed.

In another investigation, it was revealed that users' accounts were compromised when they clicked on this link, thanks to a file placed on CHATGPT. It was stated that attackers were able to access users' account information, chat history and billing information in this way, and it was noted that OpenAI closed this vulnerability in a short time.

“If Precautions Are Not Taken in Cyber-Physical Systems, Data Loss May Occur”

Another issue discussed in STM's report was CPS (Cyber-Physical System). The use of CPS, which are real-time embedded systems where physical and digital components work together, is becoming increasingly common in daily life. Working together of automatic machines and robots in a factory, data sharing of medical devices in the healthcare sector, or real-time data sharing in many civil-military systems are examples of CPS. However, this digitalization brings with it some risks. The report pointed out that CPSs may be exposed to cyber attacks by malicious individuals, and as a result of these attacks, systems may experience downtime, data loss, malfunction and even physical damage to users. To protect from these threats; It was stated that necessary precautions should be taken in data security, network security and software security, and warnings were included: "Security experts should constantly evaluate CPS systems, make updates and detect security vulnerabilities."

Cyber Security of Critical Energy Facilities

In the report, STM also discussed in detail the "Cyber Security Competence Model Regulation in the Energy Sector", which came into force in Turkey on June 6, 2023 and aims to improve the cyber security of industrial control systems used in the energy sector. The classification of cyber security applications, competency model and steps to be taken in critical energy facilities, from electricity distribution companies to the natural gas distribution sector, were included in the report.

Most Cyber Attacks Come from the USA

Data from STM's own Honeypot sensors; It also revealed the countries with the most cyber attacks worldwide. A total of 3 million 304 thousand attacks were recorded on STM's honeypot servers during April, May and June 2023. The country that made the most attacks was the United States of America (USA) with 194 thousand attacks, while Russia ranked second with 185 thousand attacks. These countries are respectively; India, France, Netherlands, Germany, China, Vietnam, Poland and Türkiye followed.

You can access the report here

Gallery

STM Announced the Cyber Threat Status Report Covering the Second Quarter of 2023 - 1