whysecurity

"Prevention is cheaper than a breach"

14
Sep

Protecting Organizations from AI-Assisted Executive Impersonation and Invoice Fraud

Threat actors are increasingly leveraging generative AI to conduct highly sophisticated financial fraud campaigns. A recent large-scale attack, targeting over a million enterprise users, demonstrates how adversaries are evolving traditional business email compromise (BEC) tactics by layering executive impersonation with fabricated vendor invoices. The Attack Strategy In this campaign, attackers…
9
Sep

How to Secure Edge AI in Customer-Owned Environments

Edge AI represents a fundamental shift in the AI security landscape. By moving model execution, IP, and data into local environments—such as devices, sensors, or factory floors—Edge AI grants customers more control over the stack, but it also transfers the burden of security from cloud providers to the customer. The…
4
Sep

ASCII Smuggling: From AI Prompt Injection to Phishing Evasion

Microsoft researchers have identified a significant phishing campaign that repurposes ‘ASCII smuggling’—a technique originally popularized in AI prompt injection research—to bypass email security filters. Instead of hiding malicious instructions from humans to target AI models, attackers are using invisible Unicode tag characters (U+E0000 to U+E007F) to fracture high-signal keywords like…
30
Aug

TerminalFix Campaign: A Dangerous New Multi-Stage Attack Chain

Microsoft Threat Intelligence has identified a sophisticated new threat campaign dubbed ‘TerminalFix.’ This evolution of the ‘ClickFix’ social engineering technique targets organizations by leveraging compromised websites to display fake Cloudflare CAPTCHA verifications. Instead of directing users to the Windows Run dialog, TerminalFix tricks victims into pasting malicious PowerShell commands into…
Scroll to top