Attack Type

Social Engineering

Generative AI lowers the cost of social engineering by orders of magnitude. Spear-phishing emails that previously required a fluent writer and target research are now produced in seconds with reasonable per-target personalisation. Voice cloning (ElevenLabs, OpenVoice, and others) enables real-time impersonation of executives and family members; multiple confirmed business-email-compromise and CFO-fraud incidents in 2023-2024 used cloned voices. Deepfake video is good enough for short verification clips and live calls under poor video conditions. Beyond direct attacks, AI-generated content fuels disinformation campaigns, fake review economies, and pig-butchering scams at unprecedented scale. AI Threat Alert tracks this category through CVEs in voice/face-recognition systems that fail to detect synthetic media, plus incidents in AIID (the AI Incident Database). Defenses: out-of-band verification for sensitive actions, deepfake detection layered with provenance signals (C2PA), and user education that assumes any voice or video can be faked.

38
Total CVEs
2
Pages
Page 2 of 2
Current
Severity CVE CVSS
MEDIUM CVE-2024-7044 6.8
HIGH CVE-2025-23205 -
MEDIUM CVE-2024-6581 6.5
MEDIUM CVE-2026-33720 4.2
MEDIUM GHSA-364x-8g5j-x2pr 5.4
MEDIUM GHSA-w673-8fjw-457c 4.1
MEDIUM GHSA-q4fm-pjq6-m63g 5.4
MEDIUM CVE-2026-33709 -
MEDIUM CVE-2026-35651 4.3
UNKNOWN CVE-2026-42230 -
MEDIUM CVE-2025-61669 -
MEDIUM CVE-2026-42045 6.2
HIGH CVE-2026-42557 -
MEDIUM CVE-2026-44550 5.0
MEDIUM CVE-2026-44568 4.8
MEDIUM CVE-2026-44899 4.7
HIGH CVE-2026-45303 7.7
HIGH CVE-2026-45665 8.1

Page 2 of 2