LIVE · cybersecurity feed
Live wire
8,539 reasons to rethink how vulnerabilities get patched'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllersNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologyUS warns of AI-powered attacks on Siemens PLCs in critical infrastructureCVE-2024-39943 · Operation CameraSwarm Compromised 14,000+ Dahua CamerasCVE-2026-19490 · CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler GatewayA California county wants to hire Tina Peters to help run its electionsThe long tail of Clop’s PTC hack is just beginning to emergeOracle Critical Patch Update, August 2026 Security Update ReviewCVE-2026-65400 · Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
ai

AI is making fraud harder to spot and identity harder to prove

Online fraud has become a routine concern for consumers and businesses that rely on digital accounts, payments and customer service. Experian’s 2026 U.S. Identity & Fraud Report describes a market where scams extend across messages, websites, documents, voices, images and account activity. Security measures that make consumers feel most secure (Source: Experian) Deception spreads across digital ch

zeroday.news ·

The proliferation of artificial intelligence is fundamentally altering the landscape of online fraud, making deceptive schemes more sophisticated and difficult to detect for both consumers and businesses. This shift is highlighted in Experian's 2026 U.S. Identity Fraud Report, which indicates that fraud has evolved from isolated incidents to an integrated component of digital interactions across various channels.

Fraudulent activities now span phishing emails, scam texts, misleading advertisements, and account alerts, leveraging the growth of online banking, shopping, payments, and customer support. The report notes that AI significantly enhances the creation of these scams, enabling criminals to generate convincing imitations of emails, messages, websites, documents, voices, and even customer support interactions.

A substantial portion of consumers are aware of AI's role in these new forms of fraud. Approximately 60% have heard of scams involving AI-generated images or videos, 53% are familiar with AI-generated phishing messages, and 47% know about deepfake voice impersonation. This awareness contributes to nearly half of consumers feeling more vulnerable to fraud compared to the previous year. For businesses, AI-generated phishing is a primary concern, alongside document forgery, automated bot attacks, and the creation of synthetic identities.

The increasing sophistication of digital scams underscores the critical importance of robust identity verification. A significant 71% of consumers believe accurate online recognition is essential. Security measures such as behavioral biometrics are highly valued, making 83% of consumers feel secure, with banking app authentication, physical biometrics, ID verification, and passwordless login also ranking highly. Businesses are consequently employing multiple identity and authentication signals to assess risk, particularly during account opening to detect stolen credentials, synthetic identities, and manipulated documents.

Consumers expect digital services to be secure without introducing undue friction. While 84% are willing to undergo additional verification to prevent fraud, they prefer that extra checks be reserved for high-risk activities like opening new accounts, recovering access, or making high-value transactions. Routine activities from familiar devices, conversely, should require fewer steps. Adaptive authentication systems can help achieve this balance, and businesses are encouraged to measure fraud losses alongside false declines, abandonment rates, conversion, and customer satisfaction to understand the impact of security on the customer experience.

Data control and privacy are also central to building digital trust. Only 23% of consumers feel they have complete control over how their personal data is used online, though 56% desire this level of control. Consumers are generally willing to share information when they understand the benefits, with security and privacy being key motivators. Businesses share these priorities, making careful data governance a vital component of digital trust.

AI is not only a tool for fraudsters but also an increasingly common component of fraud management for businesses. Eighty percent of U.S. businesses already utilize machine learning or generative AI in their fraud management strategies, employing the technology to identify unusual behavior, detect manipulated documents, and reduce manual review. However, this increased reliance on AI necessitates robust oversight, including reliable data, model monitoring, and human review to ensure accurate decisions and maintain customer trust.

The emergence of AI agents further complicates identity verification. These AI tools are becoming integrated into online shopping and booking, with 31% of consumers having used them for such activities, and another 23% considering it. As AI agents begin acting on behalf of customers, businesses face new challenges in verifying the customer, the agent, their relationship, and the permissions granted. There is a risk of fraudsters impersonating legitimate agents, compromising authorized ones, or exploiting weak permissions. Businesses are beginning to explore "Know Your Agent" as an emerging capability for authentication and fraud control.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

OpenAI confirms ChatGPT is down as logins and signups fail

ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. [...]

ai

Smashing Security podcast #481: Never say this to a robot dog

At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment? Meanwhile, in Salzburg, 280 gold stat

aicritical

'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

'It is an active threat'

security

Researchers find a loophole that lets expired credit cards make unauthorized payments

A team from the University of Massachusetts Amherst has shown that a contactless credit card keeps working past its printed expiration date, even after the cardholder gets a replacement. They named it the Zombie Card attack and presented the findings at USENIX Security 2026. The question behind the loophole “This work is motivated by documented patterns of improper expired card handling. Although

vulnerabilitycritical

8,539 reasons to rethink how vulnerabilities get patched

The window for responding to newly disclosed security flaws is getting shorter. Exploit code can appear quickly, exploitability can be tested soon after disclosure, and organizations have a growing number of weaknesses to sort through. Rapid7’s Q2 2026 Threat Landscape Report counted 8,539 high- and critical-severity vulnerability disclosures, twice the number recorded a year earlier. Source: Rapi

ransomware

Rogue ransomware affiliate poses as data recovery firm to steal payments

A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]