Attack Type

Social Engineering

Generative AI lowers the cost of social engineering by orders of magnitude. Spear-phishing emails that previously required a fluent writer and target research are now produced in seconds with reasonable per-target personalisation. Voice cloning (ElevenLabs, OpenVoice, and others) enables real-time impersonation of executives and family members; multiple confirmed business-email-compromise and CFO-fraud incidents in 2023-2024 used cloned voices. Deepfake video is good enough for short verification clips and live calls under poor video conditions. Beyond direct attacks, AI-generated content fuels disinformation campaigns, fake review economies, and pig-butchering scams at unprecedented scale. AI Threat Alert tracks this category through CVEs in voice/face-recognition systems that fail to detect synthetic media, plus incidents in AIID (the AI Incident Database). Defenses: out-of-band verification for sensitive actions, deepfake detection layered with provenance signals (C2PA), and user education that assumes any voice or video can be faked.

38
Total CVEs
2
Pages
Page 1 of 2
Current
Severity CVE CVSS
CRITICAL CVE-2026-27495 9.9
CRITICAL CVE-2026-27577 9.9
MEDIUM CVE-2025-58177 5.4
MEDIUM CVE-2025-7021 6.5
MEDIUM CVE-2021-28796 6.1
LOW CVE-2025-3777 3.5
MEDIUM CVE-2024-4940 6.1
MEDIUM CVE-2024-8021 6.1
MEDIUM CVE-2026-26320 6.5
MEDIUM CVE-2024-37146 6.1
HIGH CVE-2026-26286 8.5
MEDIUM CVE-2025-49592 5.4
HIGH CVE-2026-21893 7.2
MEDIUM CVE-2026-25631 6.5
CRITICAL CVE-2025-62593 -
HIGH CVE-2025-64496 7.3
LOW CVE-2025-50736 -
LOW CVE-2025-59842 -
HIGH CVE-2025-47783 -
MEDIUM GHSA-564p-rx2q-4c8v 6.1

Page 1 of 2