The Iran-linked threat actor APT42 is using AI-assisted phishing attacks to target U.S. organizations amidst the Iran-US war, according to researchers at DarkAtlas.
![]()
The Iran-linked threat actor APT42 is using AI-assisted phishing attacks to target U.S. organizations amidst the Iran-US war, according to researchers at DarkAtlas.
![]()
An initial access broker for ransomware gangs is targeting organizations with voice phishing (vishing) attacks through Microsoft Teams, according to researchers at Zscaler’s ThreatLabz.
![]()
As a CISO advisor, I am observing a familiar pattern gaining a new, critical dimension. What we historically identified as “Shadow IT”, the use of unapproved SaaS and tools, is rapidly evolving into “Shadow AI.”
Employees are increasingly leveraging AI bots for drafting, analysis, code generation and strategic decision-making. While the intention is often to drive efficiency, the lack of governance creates a dangerous risk surface: sensitive data leakage, compliance violations and the potential for operational decisions based on unverified, AI-generated content.
![]()
A survey from Trustmi found that most employees believe they’d be able to spot a social engineering attack, but those same employees still rely primarily on outdated guidance to spot red flags. Generative AI has given attackers the ability to craft extremely convincing, error-free phishing emails.
![]()
“Someone online shows them a ‘trick’ that feels harmless at first. Then the community pulls them in. Everyone’s doing it. It feels like skill, not crime.“
![]()
AI agents offer unprecedented capabilities, speed, automation, deep context, and hyper-personalization, that will transform how we work. However, these same capabilities make AI agents significantly more dangerous than traditional software when hijacked by cybercriminals.
![]()
![]()