Artificial intelligence is increasingly being used by attackers to enhance service desk attacks, particularly during employee onboarding. AI tools can create more convincing impersonations, accelerate reconnaissance for personalized attacks, and scale malicious campaigns. To counter these threats, organizations need to implement stronger identity verification methods, such as secure password delivery, biometric liveness detection, and multi-factor authentication before sensitive actions are approved.

Artificial intelligence is becoming a significant tool for attackers targeting service desks, as highlighted by IBM's 2025 Cost of a Data Breach Report, which found AI used in 16% of breaches. These attacks often leverage AI for sophisticated phishing and deepfake impersonation, aiming to bypass technical security controls by manipulating service desk agents. The onboarding process is particularly vulnerable due to the inherent need for new employees to gain rapid access while their identities are not yet fully established within the organization.
Attackers are using AI to make impersonation attempts more convincing. Generative AI can quickly produce polished emails, chat messages, and call scripts that mimic legitimate communications. In more advanced scenarios, AI-generated voice or video can be used to impersonate employees, making it exceedingly difficult for service desk agents to discern real requests from fraudulent ones. This is especially problematic during onboarding, where attackers can pose as new hires and exploit the expected access issues to push through malicious requests.
AI also significantly accelerates the reconnaissance phase, enabling attackers to gather and personalize information more effectively. By scraping public sources like LinkedIn, company websites, and social media, threat actors can gather details about new employees, their roles, departments, and even the internal tools they will use. AI then helps weave this information into believable narratives, making malicious requests appear routine and increasing the likelihood of quick approval.
The scalability of service desk attacks is another area where AI provides a considerable advantage. Attackers can use AI to generate numerous variations of phishing emails and pretexts, allowing them to test and adapt their social engineering campaigns rapidly. This ability to scale and adapt makes it harder for service desks, which are designed for speed, to differentiate genuine tasks from persistent, urgent-sounding malicious requests.
To combat these AI-enabled threats, a shift from relying solely on agent judgment under pressure to implementing specialized security solutions is necessary. Securing the onboarding process, a high-risk period for service desks, is paramount. Solutions that provide robust identity verification tools empower agents to confidently validate users and protect credentials.
One key preventive measure is secure password delivery during onboarding. Instead of sending sensitive credentials via insecure channels like SMS or email, organizations can utilize secure enrollment links. This approach allows new hires to create their own strong passwords, eliminating the risk of interception during transit from the service desk.
Biometric liveness detection offers another layer of defense against impersonation. Traditional identity checks, such as answering security questions, are increasingly vulnerable to information sourced online. Liveness detection ensures that a real person is present during verification, effectively countering static images, recordings, masks, or deepfakes, which is crucial for remote onboarding scenarios.
Finally, verifying identity rigorously before sensitive service desk actions are performed is critical. Actions like resetting privileged account passwords should trigger enhanced checks, including biometric liveness detection, to provide high assurance of the request's legitimacy and its association with the correct account. This ensures agents can make trust decisions with greater confidence, moving away from assumed trust to verified identity.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed