Businesses historically have a habit of adopting and implementing the newest tech tools in a hurry. Too often does this leave critical processes, like security reviews or comprehension of the data flow, behind in the dust.

The latest development to follow this trend is what’s known as Shadow AI – applications, extensions, coding assistants, and agents enabled by AI. Intended to improve workflow efficiency, the usual negligence has naturally created its own set of risks. For every unapproved app installed, another external, third-party provider becomes integrated into the organization’s ecosystem. Coupled with weak authorizations and access controls, these new AI tools contribute to a rapidly expanding attack surface and third-party footprint.
AI providers are, of course, not exempt from being targets themselves. Just ask Alation, a data software firm that has recently expanded into the domain of AI. According to the company, Alation serves over 500 companies globally, and around half of the Fortune 1000 largest US businesses. Now, as of last Tuesday, the company stated they opened an investigation into a cybersecurity incident involving unauthorized access to its systems and degraded availability for some of its customers. Little else is known at this time, not even whether Alation has notified customers of the attack, yet the company’s large-scale storage of large volumes of sensitive proprietary data of its customers is a substantial risk.
In other news, a mere two years after law enforcement disrupted its operations and arrested five admins, the Grandoreiro banking Trojan seems to continue its recovery. Originally developed in Brazil, Grandoreiro has established a decade-long history of targeting Latin American countries and other regions around the world. Indeed, a study in 2024 observed attacks against 1,500 banks worldwide. This malware is used to steal banking credentials and other financial data through avenues like keystroke logging, screen sharing and assuming control of compromised devices.
A current campaign is underway to utilize the malware against banking customers, primarily in Mexico. Meanwhile, the cyber criminals have upgraded this latest iteration of their malware to more strongly resist analysis and forensics attempts.
If bad actors are being forced to jump through hoops to evade security systems, they’re doing it like Simone Biles. When sensitive data remains readable when the intruders break in, the resulting breach will be exponentially worse. At NetLib Security, we advocate for strong encryption of sensitive data in all environments – physical, virtual and cloud. Encrypting the stored data ensures that even if it leaves your control, it won’t leave in an exploitable form.