LIVE · cybersecurity feed
Live wire
Malware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on Host
aihigh

3 Ways AI Powers Service Desk Attacks and How to Prevent Them

Artificial intelligence is increasingly being used by attackers to enhance service desk attacks, particularly during employee onboarding. AI tools can create more convincing impersonations, accelerate reconnaissance for personalized attacks, and scale malicious campaigns. To counter these threats, organizations need to implement stronger identity verification methods, such as secure password delivery, biometric liveness detection, and multi-factor authentication before sensitive actions are approved.

zeroday.news ·

Artificial intelligence is becoming a significant tool for attackers targeting service desks, as highlighted by IBM's 2025 Cost of a Data Breach Report, which found AI used in 16% of breaches. These attacks often leverage AI for sophisticated phishing and deepfake impersonation, aiming to bypass technical security controls by manipulating service desk agents. The onboarding process is particularly vulnerable due to the inherent need for new employees to gain rapid access while their identities are not yet fully established within the organization.

Attackers are using AI to make impersonation attempts more convincing. Generative AI can quickly produce polished emails, chat messages, and call scripts that mimic legitimate communications. In more advanced scenarios, AI-generated voice or video can be used to impersonate employees, making it exceedingly difficult for service desk agents to discern real requests from fraudulent ones. This is especially problematic during onboarding, where attackers can pose as new hires and exploit the expected access issues to push through malicious requests.

AI also significantly accelerates the reconnaissance phase, enabling attackers to gather and personalize information more effectively. By scraping public sources like LinkedIn, company websites, and social media, threat actors can gather details about new employees, their roles, departments, and even the internal tools they will use. AI then helps weave this information into believable narratives, making malicious requests appear routine and increasing the likelihood of quick approval.

The scalability of service desk attacks is another area where AI provides a considerable advantage. Attackers can use AI to generate numerous variations of phishing emails and pretexts, allowing them to test and adapt their social engineering campaigns rapidly. This ability to scale and adapt makes it harder for service desks, which are designed for speed, to differentiate genuine tasks from persistent, urgent-sounding malicious requests.

To combat these AI-enabled threats, a shift from relying solely on agent judgment under pressure to implementing specialized security solutions is necessary. Securing the onboarding process, a high-risk period for service desks, is paramount. Solutions that provide robust identity verification tools empower agents to confidently validate users and protect credentials.

One key preventive measure is secure password delivery during onboarding. Instead of sending sensitive credentials via insecure channels like SMS or email, organizations can utilize secure enrollment links. This approach allows new hires to create their own strong passwords, eliminating the risk of interception during transit from the service desk.

Biometric liveness detection offers another layer of defense against impersonation. Traditional identity checks, such as answering security questions, are increasingly vulnerable to information sourced online. Liveness detection ensures that a real person is present during verification, effectively countering static images, recordings, masks, or deepfakes, which is crucial for remote onboarding scenarios.

Finally, verifying identity rigorously before sensitive service desk actions are performed is critical. Actions like resetting privileged account passwords should trigger enhanced checks, including biometric liveness detection, to provide high assurance of the request's legitimacy and its association with the correct account. This ensures agents can make trust decisions with greater confidence, moving away from assumed trust to verified identity.

aiservice desksocial engineeringidentity verificationonboarding
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Say it once: introducing Bot Preference Sync

Cloudflare's new Bot Preference Sync automatically aligns your robots.txt file with your AI bot policies for Search, Agent, and Training. Easily manage which bots access your content without maintaining static files.

security

Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments

Plus: Apple sends out an “unprecedented” number of spyware warnings, Ukraine hits a Russian ecommerce giant with cyber and drone attacks, and more.

malwarehigh

Malware Hijacks Android Car Head Units

Researchers have identified new Android malware that hijacks car head units by exploiting their official update mechanisms. The malware installs proxy software, turning vehicles into nodes for the BADBOX botnet, primarily for ad fraud and to provide anonymized internet connections. This marks the first documented instance of malware specifically targeting car head units through their native update channels.

malware

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware. The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight appeared first on SecurityWeek.

nasacritical

Critical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command Execution

A critical vulnerability has been discovered in NASA/JPL's open-source AIT-GUI software, which is used to control spacecraft instruments. The flaw allows unauthenticated attackers to execute arbitrary commands, run server-side scripts, and manipulate command sequences by exploiting a lack of authentication, session checks, and CSRF protection. Researchers confirmed the issue, which has a CVSS score of 9.4, and a fix is available in version 2.5.2.

CVE-2026-73570critical

U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog

CISA has added a critical vulnerability in Zimbra Collaboration Suite (ZCS) to its Known Exploited Vulnerabilities catalog. The flaw, CVE-2026-73570, allows unauthenticated remote code execution and is being actively exploited by threat actors. Zimbra released a patch for the vulnerability less than a month before exploitation was confirmed.