Attack Type

Social Engineering

Generative AI lowers the cost of social engineering by orders of magnitude. Spear-phishing emails that previously required a fluent writer and target research are now produced in seconds with reasonable per-target personalisation. Voice cloning (ElevenLabs, OpenVoice, and others) enables real-time impersonation of executives and family members; multiple confirmed business-email-compromise and CFO-fraud incidents in 2023-2024 used cloned voices. Deepfake video is good enough for short verification clips and live calls under poor video conditions. Beyond direct attacks, AI-generated content fuels disinformation campaigns, fake review economies, and pig-butchering scams at unprecedented scale. AI Threat Alert tracks this category through CVEs in voice/face-recognition systems that fail to detect synthetic media, plus incidents in AIID (the AI Incident Database). Defenses: out-of-band verification for sensitive actions, deepfake detection layered with provenance signals (C2PA), and user education that assumes any voice or video can be faked.

89
Total CVEs
5
Pages
Page 5 of 5
Current
Severity CVE CVSS
HIGH CVE-2026-73222 8.8
UNKNOWN CVE-2026-73415 -
UNKNOWN CVE-2026-73417 -
UNKNOWN CVE-2020-1192 -
HIGH CVE-2026-76254 7.5
MEDIUM CVE-2026-76341 5.4
LOW GHSA-h58c-xccx-75m3 3.4
LOW GHSA-8fxq-53rx-ph5f 3.7
UNKNOWN CVE-2026-65644 -

Page 5 of 5