{"id":20374,"date":"2023-07-27T06:51:45","date_gmt":"2023-07-27T06:51:45","guid":{"rendered":"https:\/\/web3unplugged.io\/blog\/?p=20374"},"modified":"2023-07-27T06:51:48","modified_gmt":"2023-07-27T06:51:48","slug":"netskope-threat-labs-source-code-most-common-sensitive-data-shared-to-chatgpt","status":"publish","type":"post","link":"https:\/\/web3unplugged.io\/blog\/netskope-threat-labs-source-code-most-common-sensitive-data-shared-to-chatgpt\/","title":{"rendered":"Netskope Threat Labs: Source Code Most Common Sensitive Data Shared To ChatGPT"},"content":{"rendered":"\n<p><a href=\"https:\/\/www.netskope.com\/\">Netskope<\/a>, a leader in Secure Access Service Edge (SASE), today unveiled new research showing that for every 10,000 enterprise users, an enterprise organization is experiencing approximately 183 incidents of sensitive data being posted to the app per month. Source code accounts for the largest share of sensitive data being exposed.<\/p>\n\n\n\n<p>The findings are part of <a href=\"https:\/\/www.netskope.com\/netskope-threat-labs\/cloud-threat-report\/ai-apps-in-the-enterprise\"><em>Cloud &amp; Threat Report: AI Apps in the Enterprise<\/em><\/a>, Netskope Threat Labs\u2019 first comprehensive analysis of AI usage in the enterprise and the security risks at play. Based on data from millions of enterprise users globally, Netskope found that generative AI app usage is growing rapidly, up 22.5% over the past two months, amplifying the chances of users exposing sensitive data.<\/p>\n\n\n\n<p><strong>Growing AI App Usage<\/strong><\/p>\n\n\n\n<p>Netskope found that organizations with 10,000 users or more use an average of 5 AI apps daily, with ChatGPT seeing more than 8 times as many daily active users as any other generative AI app. At the current growth rate, the number of users accessing AI apps is expected to double within the next seven months.<\/p>\n\n\n\n<p>Over the past two months, the fastest growing AI app was Google Bard, currently adding users at a rate of 7.1% per week, compared to 1.6% for ChatGPT. At current rates, Google Bard is not poised to catch up to ChatGPT for over a year, though the generative AI app space is expected to evolve significantly before then, with many more apps in development.<\/p>\n\n\n\n<p><strong>Users Inputting Sensitive Data into ChatGPT<\/strong><\/p>\n\n\n\n<p>Netskope found that source code is posted to ChatGPT more than any other type of sensitive data, at a rate of 158 incidents per 10,000 users per month. Other sensitive data being shared in ChatGPT includes regulated data- including financial and healthcare data, personally identifiable information \u2013 along with intellectual property excluding source code, and, most concerningly, passwords and keys, usually embedded in source code.<\/p>\n\n\n\n<p>\u201cIt is inevitable that some users will upload proprietary source code or text containing sensitive data to AI tools that promise to help with programming or writing,\u201d said Ray Canzanese, Threat Research Director, Netskope Threat Labs. \u201cTherefore, it is imperative for organizations to place controls around AI to prevent sensitive data leaks. Controls that empower users to reap the benefits of AI, streamlining operations and improving efficiency, while mitigating the risks are the ultimate goal. The most effective controls that we see are a combination of DLP and interactive user coaching.\u201d<\/p>\n\n\n\n<p><strong>Blocking or Granting Access to ChatGPT<\/strong><\/p>\n\n\n\n<p>Netskope Threat Labs is currently tracking ChatGPT proxies and more than 1,000 malicious URLs and domains from opportunistic attackers seeking to capitalize on the AI hype, including multiple phishing campaigns, malware distribution campaigns, and spam and fraud websites.&nbsp;<\/p>\n\n\n\n<p>Blocking access to AI related content and AI applications is a short term solution to mitigate risk, but comes at the expense of the potential benefits AI apps offer to supplement corporate innovation and employee productivity. Netskope\u2019s data shows that in financial services and healthcare \u2013 both highly regulated industries \u2013 nearly 1 in 5 organizations have implemented a blanket ban on employee use of ChatGPT, while in the technology sector, only 1 in 20 organizations have done likewise.<\/p>\n\n\n\n<p>\u201cAs security leaders, we cannot simply decide to ban applications without impacting on user experience and productivity,\u201d said James Robinson, Deputy Chief Information Security Officer at Netskope. \u201cOrganizations should focus on evolving their workforce awareness and data policies to meet the needs of employees using AI products productively. There is a good path to safe enablement of generative AI with the right tools and the right mindset.\u201d<\/p>\n\n\n\n<p>In order for organizations to enable the safe adoption of AI apps, they must center their approach on identifying permissible apps and implementing controls that empower users to use them to their fullest potential, while safeguarding the organization from risks. Such an approach should include domain filtering, URL filtering, and content inspection to protect against attacks. Other steps to safeguard data and securely use AI tools include:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Block access to apps that do not serve <strong>any legitimate business purpose<\/strong> or that pose a <strong>disproportionate risk<\/strong> to the organization.<\/li><li>Employ<strong> user coaching<\/strong> to remind users of <strong>company policy <\/strong>surrounding the use of AI apps.<\/li><li>Use modern <strong>data loss prevention (DLP) technologies <\/strong>to detect posts containing potentially sensitive information.<\/li><\/ul>\n\n\n\n<p>Read the full <em>Cloud &amp; Threat Report: AI Apps in the Enterprise&nbsp;<\/em><a href=\"https:\/\/www.netskope.com\/netskope-threat-labs\/cloud-threat-report\/ai-apps-in-the-enterprise\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a>. For more information on cloud-enabled threats and the latest findings from Netskope Threat Labs, visit<a href=\"https:\/\/www.netskope.com\/netskope-threat-labs\" target=\"_blank\" rel=\"noreferrer noopener\">Netskope\u2019s Threat Research Hub<\/a>. To receive Netskope Threat Labs blog posts, <a href=\"https:\/\/www.netskope.com\/blog#subscribe\" target=\"_blank\" rel=\"noreferrer noopener\">subscribe here<\/a>.<\/p>\n\n\n\n<p>In conjunction with the report, Netskope today announced new solution offerings from SkopeAI, the Netskope suite of artificial intelligence and machine learning (AI\/ML) innovations. SkopeAI leverages the power of AI\/ML to conquer the limitations of complex legacy tools and provide protection using AI-speed techniques not found in other SASE products. Learn more about SkopeAI&nbsp;<a href=\"https:\/\/www.netskope.com\/products\/skopeai\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Netskope, a leader in Secure Access Service Edge (SASE), today unveiled new research showing that for every 10,000 enterprise users, an enterprise organization is experiencing approximately 183 incidents of sensitive data being posted to the app per month. Source code accounts for the largest share of sensitive data being exposed. The findings are part of [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":20376,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"none","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","footnotes":""},"categories":[2],"tags":[],"class_list":["post-20374","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"rttpg_featured_image_url":{"full":["https:\/\/web3unplugged.io\/blog\/wp-content\/uploads\/2023\/07\/Daily-percentage-of-users-Chat-GPT.png",6394,3514,false],"landscape":["https:\/\/web3unplugged.io\/blog\/wp-content\/uploads\/2023\/07\/Daily-percentage-of-users-Chat-GPT.png",6394,3514,false],"portraits":["https:\/\/web3unplugged.io\/blog\/wp-content\/uploads\/2023\/07\/Daily-percentage-of-users-Chat-GPT.png",6394,3514,false],"thumbnail":["https:\/\/web3unplugged.io\/blog\/wp-content\/uploads\/2023\/07\/Daily-percentage-of-users-Chat-GPT-150x150.png",150,150,true],"medium":["https:\/\/web3unplugged.io\/blog\/wp-content\/uploads\/2023\/07\/Daily-percentage-of-users-Chat-GPT-300x165.png",300,165,true],"large":["https:\/\/web3unplugged.io\/blog\/wp-content\/uploads\/2023\/07\/Daily-percentage-of-users-Chat-GPT-1024x563.png",1024,563,true],"1536x1536":["https:\/\/web3unplugged.io\/blog\/wp-content\/uploads\/2023\/07\/Daily-percentage-of-users-Chat-GPT-1536x844.png",1536,844,true],"2048x2048":["https:\/\/web3unplugged.io\/blog\/wp-content\/uploads\/2023\/07\/Daily-percentage-of-users-Chat-GPT-2048x1126.png",2048,1126,true],"post-thumbnail":["https:\/\/web3unplugged.io\/blog\/wp-content\/uploads\/2023\/07\/Daily-percentage-of-users-Chat-GPT.png",755,415,false],"graptor-sq-xs":["https:\/\/web3unplugged.io\/blog\/wp-content\/uploads\/2023\/07\/Daily-percentage-of-users-Chat-GPT.png",100,55,false]},"rttpg_author":{"display_name":"Admin CG","author_link":"https:\/\/web3unplugged.io\/blog\/author\/admin-cg\/"},"rttpg_comment":0,"rttpg_category":"<a href=\"https:\/\/web3unplugged.io\/blog\/category\/news\/\" rel=\"category tag\">news<\/a>","rttpg_excerpt":"Netskope, a leader in Secure Access Service Edge (SASE), today unveiled new research showing that for every 10,000 enterprise users, an enterprise organization is experiencing approximately 183 incidents of sensitive data being posted to the app per month. Source code accounts for the largest share of sensitive data being exposed. The findings are part of&hellip;","_links":{"self":[{"href":"https:\/\/web3unplugged.io\/blog\/wp-json\/wp\/v2\/posts\/20374","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/web3unplugged.io\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/web3unplugged.io\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/web3unplugged.io\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/web3unplugged.io\/blog\/wp-json\/wp\/v2\/comments?post=20374"}],"version-history":[{"count":1,"href":"https:\/\/web3unplugged.io\/blog\/wp-json\/wp\/v2\/posts\/20374\/revisions"}],"predecessor-version":[{"id":20377,"href":"https:\/\/web3unplugged.io\/blog\/wp-json\/wp\/v2\/posts\/20374\/revisions\/20377"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/web3unplugged.io\/blog\/wp-json\/wp\/v2\/media\/20376"}],"wp:attachment":[{"href":"https:\/\/web3unplugged.io\/blog\/wp-json\/wp\/v2\/media?parent=20374"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/web3unplugged.io\/blog\/wp-json\/wp\/v2\/categories?post=20374"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/web3unplugged.io\/blog\/wp-json\/wp\/v2\/tags?post=20374"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}