← Back
Policy & LegalCyberScoop·4 hours ago

Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities

Former child sexual abuse material (CSAM) victims have filed a lawsuit alleging that Grok was trained on their images and videos to develop deepfake capabilities, contradicting Elon Musk's claim of awareness of "literally zero" CSAM content created through the model. The lawsuit represents thousands of real victims whose abuse material was allegedly used without consent in the AI system's training process. This case highlights significant concerns about the sourcing of training data for generative AI models and their potential to perpetuate harm against vulnerable populations.

Read full article at CyberScoop

Related Articles

Policy & LegalThe Record·1 hour ago

White House bans foreign-made equipment for power generation over cyber backdoor concerns

The Trump administration has issued a ban on acquiring foreign-made equipment and components used for power generation and electricity management, citing concerns that adversaries are deliberately creating and exploiting vulnerabilities in these systems. The move reflects growing national security concerns about potential cyber backdoors in critical infrastructure that could be leveraged by foreign actors to disrupt energy systems.

Policy & LegalCyberScoop·2 hours ago

100-plus companies call for ‘global surge’ in AI-powered cyber defense

Over 100 companies including OpenAI, Anthropic, Google, and Microsoft are calling for a coordinated global effort to strengthen AI-powered cyber defenses, warning that there is a limited "defenders' window" before threat actors develop more sophisticated AI-enabled attacks. The coalition emphasizes the urgency of advancing defensive capabilities now while the opportunity exists to outpace evolving threats.

Policy & LegalQualys·3 hours ago

PCI DSS 4.0.1: Application Requirements You’re Being Assessed On in 2026

As of March 31, 2025, all 51 previously optional "best practice" requirements in PCI DSS 4.0 are now mandatory and will be fully assessed in 2026 evaluations. A significant portion of the new assessment weight focuses on application-level controls under Requirements 6 and 11, including inventory management of custom applications and APIs along with continuous protection measures. Organizations must prepare for stricter compliance scrutiny on these application security requirements in upcoming PCI DSS assessments.