Researchers have developed a deep learning model that can steal data from keyboard keystrokes recorded using a microphone with an accuracy of 95%. The attack can be carried out through a nearby microphone, an infected phone, or a rogue participant in a Zoom call. The attack can leak passwords, discussions, messages, or other sensitive information to malicious third parties. Possible mitigations include altering typing styles, using randomized passwords, employing biometric authentication, and utilizing password managers.
A report by the Cloud Security Alliance shows a disconnect between how C-suite executives and cybersecurity workers perceive security’s role. While half of the C-level executives surveyed said security is “prioritized and strictly enforced” during cloud implementations, just 31% of security workers agreed with the statement, signaling a rift between the importance placed on cloud security across enterprises. The report suggests that communication is critical to enhancing an organization’s cybersecurity posture.
There’s such a divide here. On the one hand, we have researchers looking at incredibly sophisticated attack vectors. On the other, we have confusion about what security’s role is.
I want to point out some of the absurdities of how security is often discussed. A mitigation is “altering typing styles.” It’s suggested that some users who must protect against this attack must learn how to type differently. Let that sink in. Now consider how often statements like this are made in security. Make sure your approach doesn’t fall for unreasonableness. You’ll be easily discounted.

