According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence. Read more in my article on the Fortra blog.

A recent study indicates a significant increase in the financial impact and sophistication of phishing and social engineering attacks, with artificial intelligence playing a growing role in their augmentation. The research suggests that the costs associated with recovering from these incidents are rising, and the attacks themselves are becoming more difficult for organizations to detect.
The study highlights how AI is being leveraged to enhance various aspects of phishing campaigns. This could include the generation of more convincing and grammatically correct phishing emails, making them harder to distinguish from legitimate communications. AI might also be used to craft highly personalized messages by analyzing publicly available information about targets, thereby increasing the likelihood of a successful social engineering attempt. Furthermore, AI could potentially automate the scaling of these attacks, allowing threat actors to target a larger number of individuals or organizations with tailored content.
Phishing attacks typically rely on deceiving users into revealing sensitive information or taking actions that compromise security. This often involves malicious links, attachments, or requests for credentials. Social engineering, a broader category, manipulates individuals into divulging confidential information or performing actions that benefit the attacker, often without the use of technical exploits. The reported AI augmentation suggests a move towards more sophisticated and less detectable forms of these attacks.
The increased difficulty in detection stems from the improved quality and personalization of AI-generated content. Traditional detection methods, which might flag common grammatical errors or generic templates, could be less effective against more nuanced and contextually relevant messages. This places a greater burden on both technical security controls and user awareness training.
Mitigation strategies for this class of threat generally involve a multi-layered approach. This includes robust email filtering and security gateways designed to identify and block malicious content, even when sophisticated. User education and awareness training are paramount, focusing on recognizing evolving phishing tactics and the importance of verifying suspicious requests. Implementing multi-factor authentication (MFA) can significantly reduce the impact of compromised credentials, as even if a password is phished, the attacker would still need a second factor to gain access.
For organizations, the rising recovery costs underscore the importance of proactive security measures and incident response planning. The financial implications can stem from direct losses due to fraud, costs associated with data breach remediation, regulatory fines, reputational damage, and business disruption. The study's findings suggest these costs are trending upwards, making effective prevention and rapid response more critical than ever.
The reported supercharging of phishing attacks by AI represents a significant evolution in the threat landscape. It underscores the ongoing arms race between attackers and defenders, where technological advancements are continually adopted by both sides. This trend necessitates a continuous adaptation of security strategies, emphasizing both advanced technical defenses and the human element of cybersecurity awareness and vigilance.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed