Faking it on the phone: How to tell if a voice call is AI or not
Can you believe your ears? Increasingly, the answer is no. Here’s what’s at stake for your business, and how to beat the deepfakers.
Can you believe your ears? Increasingly, the answer is no. Here’s what’s at stake for your business, and how to beat the deepfakers.
ESET researchers have identified PromptSpy, marking the first documented Android malware to leverage generative AI within its attack mechanism. The discovery indicates an emerging threat vector where threat actors are integrating AI capabilities into mobile malware operations.
Like any other marketplace, the social commerce platform has its share of red flags. It pays to know what to look for so you can shop or sell without headaches.
In this episode, we’ll take a look at another obscure, registry-based execution artifact that may help you fill in yet another piece of the puzzle. *** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. *** 📖 Chapters 00:00 - Intro 00:33 - About Registry Hives 02:10 - Demo 🛠 Resources FeatureUsage — Evidence of Execution:
When it comes to our children’s digital lives, prohibition rarely works. It’s our responsibility to help them build a healthy relationship with tech.
When corporate data is exposed on a dedicated leak site, the consequences linger long after the attack fades from the news cycle
Google Project Zero researcher has documented five root causes behind nine discovered bypasses of Windows Administrator Protection, all of which have now been fixed. The vulnerabilities primarily exploited weaknesses in the UI Access feature—originally designed to allow accessibility applications to function across privilege boundaries—including insecure directory checks, token manipulation, DLL hijacking through environment variables, and TOCTOU race conditions in the RPC process creation mechanism. While all reported issues have been patched, the researcher emphasizes that the underlying architectural reliance on UI Access processes remains a potential vector for future attacks if code execution can be achieved in a High integrity level process.
Bitdefender researchers have identified a resurgence in LummaStealer activity, demonstrating how this prolific information-stealing malware persisted despite near-disruption by law enforcement within the past year. Operating as a malware-as-a-service since late 2022, LummaStealer has established itself as one of the most widely deployed information stealers through its highly scalable architecture. The malware's renewed distribution alongside CastleLoader indicates continued evolution and adaptation by the threat actors behind the operation.
It’s time to file your tax return. And cybercriminals are lurking to make an already stressful period even more edgy.
Cybereason's Q4 2025 TTP Briefing highlights emerging threat trends observed across their incident response engagements, with particular emphasis on diversifying phishing tactics and increased remote access trojan (RAT) activity. The report synthesizes frontline intelligence gathered from global IR investigations and security operations center detections to provide actionable insights into current attacker techniques. Security teams can use these findings to understand and prepare for evolving threat landscapes based on real-world incident data.
The mobile marketplace app has a growing number of users, but not all of them are genuine. Watch out for these common scams.
Cybereason Security Services analyzed a fake installer campaign leading to ValleyRAT infections, identifying previously undocumented findings and new threat intelligence insights from the malware. The report investigates this repeatedly observed attack vector and provides practical recommendations for organizations to defend against it. The analysis contributes updated threat intelligence on this infection method to help security teams better protect their environments.
It’s snow joke – sporting events are a big draw for cybercriminals. Make sure you’re not on the losing side by following these best practices.
The trends from January offer useful clues about the risks and priorities that security teams are likely to contend with throughout the year
ESET researchers have conducted a technical analysis of DynoWiper, a data destruction tool used in an incident targeting a Polish energy sector company. The analysis includes attribution findings that provide insight into the threat actor behind the attack and the malware's capabilities.
Google Project Zero researchers have detailed the exploitation of CVE-2024-54529, a type confusion vulnerability in macOS's coreaudiod system daemon that affects the CoreAudio framework's com.apple.audio.audiohald Mach service. The exploit required sophisticated techniques including heap feng shui with property lists, leveraging uninitialized memory in ngne objects, and crafting a ROP chain to achieve arbitrary code execution in the privileged coreaudiod process. The research demonstrates how a seemingly simple type confusion crash can be transformed into a working exploit through creative problem-solving, custom tooling for heap analysis, and careful manipulation of the memory allocator's behavior across process restarts.
ESET researchers have identified a targeted Android spyware campaign in Pakistan that leverages a fake dating app as a social engineering lure, exploiting romance scam tactics to deceive users. The discovery reveals connections to a wider surveillance operation, highlighting how threat actors combine dating app fraud with malware distribution to compromise mobile devices in the region.
Has your inbox recently been deluged with unwanted and even outright malicious messages? Here are 10 possible reasons – and how to stem the tide.
Google Project Zero researcher discovered nine separate vulnerabilities in Windows 11's new Administrator Protection feature, including one complex bypass that exploits the lazy initialization of per-logon-session DOS device directories to hijack the system drive of elevated processes. Microsoft patched all reported issues either before the feature's official release via optional update KB5067036 or through subsequent security bulletins, though the feature itself was later disabled in December 2025 due to unrelated application compatibility issues. While Administrator Protection represents a meaningful security improvement over legacy User Account Control by establishing a more defensible boundary against silent privilege escalation, the researcher notes that it still carries forward nearly two decades of unfixed UAC bypasses due to Microsoft's conservative approach prioritizing app compatibility over a more radical redesign.