RSS Amplifier

Oakseed Ventures · Feb 11, 2025

Alibaba Releases Qwen2.5 Max to Rival DeepSeek, OpenAI Rival Hit by Large-Scale Cyberattack and Change Healthcare Data Breach Doubles Victim Count to 190 Million

0
Sign in to vote or save

Katie Miri · Oakseed Ventures

Oakseed portfolio Positron AI raises $23.5M to take on Nvidia. Positron ships systems providing >3.5x performance per dollar and performance per watt advantage over NVIDIA Hopper.

(Reuters)

A lack of supply chain security has been a critical vector for cyberattacks, from misconfigurations in essential servers to compromise of third-party dependencies. While the problem of securing the supply chain is far from solved, startup Eclypsium is working to advance solutions by building a platform for managing supply chain security in IT infrastructure. Read on to learn more about Eclypsium’s recent funding round and its mission.

  • As DeepSeek’s introduction a few weeks ago came accompanied by significant popularity and news coverage, it has placed pressure both on American AI companies and other Chinese AI developers. In response, Alibaba just released Qwen2.5 Max, stating it “achieves competitive performance against the top-tier models,” including DeepSeek, ChatGPT and Ollama. Security experts in the US are still watching DeepSeek’s national security implications, as well as the recent cyberattack. (Reuters, WSJ)

  • Researchers at EvolutionaryScale, a startup working on AI for the life sciences, have created an artificial intelligence model that can accurately simulate evolution, discovering new functional proteins and organic materials “outside the space explored by evolution” so far. The model is called ESM3, and is described as “a frontier multimodal generative language model that reasons over the sequence, structure, and function of proteins.” In a paper recently published by Science, the researchers prompted ESM3 to simulate the evolution of fluorescent proteins, and the model was able to create a new functional protein estimated not to evolve for five hundred years. As ESM3 evolves, it creates limitless potential for the discovery of new proteins, which can then be used in medicine and for other applications. (Science, EvolutionaryScale, Live Science)

  • After the notorious Change Healthcare ransomware attack nearly one year ago, UHG (UnitedHealth Group) has updated their breach victim count from 100 million to 190 million, nearly doubling the impact of what was already the “largest healthcare data breach ever reported to federal regulators”. Not all victims have been notified, and UnitedHealth has not claimed this to be the final total. CEO Andrew Witty said that “the attack may have compromised the data of one third of people in the US.” Ransomware group AlphV, also known as BlackCat, claimed responsibility for the $3.1 billion cyberattack. Analysis of the attack confirmed that it originated from a failure to enable multi-factor authentication on a Citrix server. (Dark Reading, Healthcare Dive, HIPAA Journal)

  • As part of its recent Series C funding round, cybersecurity startup Eclypsium has raised $45 million, bringing its total funding up to $85 million total. Eclypsium’s focus is on “supply chain security for IT infrastructure,” and its platform is used to “scan hardware, firmware, and software components across their IT infrastructure and then flag vulnerabilities, threats, and inventory issues.” Supply chain security is particularly recognized as a goal in the wake of multiple cyberattacks, including the Volt Typhoon intrusion into the US electric grid two years ago and the Salt Typhoon intrusion into the US telecommunications network. Some of Eclypsium’s current clients include Meta, American Express, and US government agencies. (Forbes, Eclypsium, Geek Wire)

  • AI platform DeepSeek, which recently surpassed OpenAI in popularity on the Apple App Store, has announced that “due to large-scale malicious attacks on DeepSeek’s services, we are temporarily limiting registrations to ensure continued service,” right after cybersecurity firm KELA exposed vulnerabilities in the platform by jailbreaking the model and forcing it to break privacy standards. The cyberattacks are suspected to be large-scale distributed denial of service attacks (DDoS), in which a group of adversary machines shut down DeepSeek’s servers by overwhelming its systems. (KELA, Forbes, CNBC, Security Week)

  • In a newly released paper, 26 Microsoft security researchers red-teamed over 100 of Microsoft’s own generative AI products and discussed their findings, including that “the work of securing AI systems will never be complete.” Their attacks on the products sought to emulate “real-world attacks against end-to-end systems,” including a significant human component, such as by imitating a user in significant emotional distress. While the finding seems pessimistic at first, it simply mirrors the state of cybersecurity more generally; keeping systems secure is always a cat-and-mouse game between attackers and defenders. The researchers recommend that those concerned with the safety of their AI constantly update and test their defenses, particularly as the field of AI red teaming develops further. (arXiv, The Register)

Thanks for reading this week’s newsletter! If you have news of an interesting novel development, reach out and we may include your story in our next post!

Until next time,

Katie Miri
katie@oakseedvc.com

No posts

Read the original on oakseed.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.