The cybersecurity landscape is evolving with the advent of "Phishing 3.0," where attackers are increasingly using AI-powered agents to conduct sophisticated, multi-channel attacks. These agents automate reconnaissance and personalize lures, moving beyond simple malicious content to exploit trust through social engineering, deepfakes, and impersonation across email, voice, and video. Traditional defenses are struggling to keep pace, necessitating a shift towards proactive, agent-assisted security measures for defenders.

The cybersecurity community is reportedly facing a new phase of attack, dubbed "Phishing 3.0," characterized by the increasing deployment of AI-powered agents by malicious actors. This development signifies a shift in the nature of phishing campaigns, moving towards more automated and sophisticated multi-channel assaults. The core concern is that these AI agents are enhancing attackers' capabilities in reconnaissance and the personalization of social engineering lures, making traditional defenses less effective.
At the technical level, these AI-powered agents are described as automating key aspects of the attack chain. This includes conducting reconnaissance to gather information about targets, which is then used to craft highly personalized and believable lures. Unlike earlier phishing attempts that often relied on generic malicious links or attachments, Phishing 3.0 leverages advanced social engineering techniques. This can involve the use of deepfakes and sophisticated impersonation tactics across various communication vectors, including email, voice calls, and video interactions. The goal is to exploit trust relationships rather than simply tricking users into clicking a link.
The reported shift indicates that attackers are moving beyond static malicious content, which is often detectable by signature-based or even heuristic analysis. Instead, the focus is on dynamic, adaptive interactions that mimic legitimate communication. The multi-channel approach means that an initial email might be followed by a targeted voice call or even a video interaction, all orchestrated by AI agents to build a convincing narrative and overcome skepticism. This level of automation and personalization presents a significant challenge for existing security frameworks.
Products designed for email gateway security, endpoint protection, and even some behavioral analytics tools may struggle to identify these highly personalized and context-aware attacks. Traditional phishing defenses often rely on detecting known malicious indicators, suspicious URLs, or common social engineering patterns. However, when AI agents are generating unique, contextually relevant content and orchestrating multi-stage interactions, these defenses can be bypassed. The human element, which is often the weakest link, becomes even more vulnerable when confronted with highly convincing, AI-generated impersonations.
Mitigation strategies for this evolving threat class typically involve a multi-layered approach. Enhanced user training, focusing on recognizing sophisticated social engineering tactics, deepfakes, and multi-channel impersonations, becomes critical. Organizations may also need to explore advanced threat detection systems that incorporate AI and machine learning to identify anomalous communication patterns, unusual voice characteristics, or inconsistencies in video interactions. Furthermore, the reported need for "agent-assisted security measures for defenders" suggests a move towards leveraging defensive AI to counter offensive AI, potentially through automated threat hunting, real-time anomaly detection, and adaptive access controls.
This development underscores an ongoing arms race in cybersecurity, where advancements in artificial intelligence are being leveraged by both attackers and defenders. The reported emergence of "Phishing 3.0" highlights a significant escalation in the sophistication and automation of social engineering attacks. It signals a future where the battle for digital security may increasingly involve AI agents on both sides, necessitating a proactive and adaptive approach to defense that moves beyond traditional reactive measures.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.