Attack Type

Social Engineering

Generative AI lowers the cost of social engineering by orders of magnitude. Spear-phishing emails that previously required a fluent writer and target research are now produced in seconds with reasonable per-target personalisation. Voice cloning (ElevenLabs, OpenVoice, and others) enables real-time impersonation of executives and family members; multiple confirmed business-email-compromise and CFO-fraud incidents in 2023-2024 used cloned voices. Deepfake video is good enough for short verification clips and live calls under poor video conditions. Beyond direct attacks, AI-generated content fuels disinformation campaigns, fake review economies, and pig-butchering scams at unprecedented scale. AI Threat Alert tracks this category through CVEs in voice/face-recognition systems that fail to detect synthetic media, plus incidents in AIID (the AI Incident Database). Defenses: out-of-band verification for sensitive actions, deepfake detection layered with provenance signals (C2PA), and user education that assumes any voice or video can be faked.

89
Total CVEs
5
Pages
Page 4 of 5
Current
Severity CVE CVSS
HIGH CVE-2026-26192 7.3
MEDIUM CVE-2025-46571 -
MEDIUM CVE-2026-56359 5.4
HIGH CVE-2026-59806 7.4
MEDIUM CVE-2026-56354 5.4
HIGH CVE-2026-61428 7.3
MEDIUM CVE-2025-34430 -
HIGH CVE-2026-56400 8.3
HIGH CVE-2026-61436 8.6
HIGH CVE-2026-65592 -
HIGH GHSA-pppj-hq3g-57pj -
HIGH GHSA-gx64-gj6p-pc4c -
HIGH CVE-2026-59714 7.1
HIGH GHSA-pvcr-8mvp-w8qr 7.7
MEDIUM CVE-2026-16774 5.3
MEDIUM CVE-2026-67338 6.1
MEDIUM CVE-2026-67618 6.5
HIGH CVE-2026-66881 8.1
MEDIUM CVE-2026-66885 6.5
MEDIUM CVE-2023-35394 4.6

Page 4 of 5