Feed aggregator
Show HN: LOL Bench – a benchmark for whether LLMs get jokes
Article URL: https://www.lolbench.lol/
Comments URL: https://news.ycombinator.com/item?id=49649243
Points: 1
# Comments: 1
Nvidia's Openness Promise Leaves Out Hosting, Gating and Licensing
Article URL: https://topicqueue.substack.com/p/nvidia-is-buying-hugging-face-its
Comments URL: https://news.ycombinator.com/item?id=49649238
Points: 1
# Comments: 0
Zasper: JupyterLab Alternative Built for Performance
Article URL: https://zasper.io/
Comments URL: https://news.ycombinator.com/item?id=49649237
Points: 1
# Comments: 0
Apple Reference Image, but open source and using steganography
Article URL: https://merybenavente.me/blog/proof-of-capture
Comments URL: https://news.ycombinator.com/item?id=49649222
Points: 3
# Comments: 0
We All Deserve a Better Internet, Not A Smaller One
SAN FRANCISCO - Technology and the laws that regulate it should support and empower young people. California’s AB 1709 - signed into law today by Gov. Gavin Newsom - falls far short of this goal, say the Electronic Frontier Foundation (EFF) and its allies.
Using technology is how we learn and build community in today’s world. Laws such as AB 1709, a functional ban on social media use for people under the age of 16, instead cut young people off from essential information and experiences. That particularly harms those already facing increased challenges, who often find safety in supportive online communities that they can’t always access in the physical world.
"California should be passing laws to ensure that technology really works for people of all ages, not enacting social media bans that cut young people off from digital lifelines, communities, and speech," said EFF Associate Director of State Affairs Rindala Alajaji. "Denying minors access to digital forums - or stripping out basic tools needed to navigate them - is not going to help make young people safer or healthier in the AI age."
Research shows social media bans are ineffectual, while also denying young people opportunities to develop their own voices and perspectives—to share their art, practice religion or engage in politics.
Age-gating requirements also force everyone to give up more personal information. To verify who can pass through their online gates, companies will collect even more data, and this further concentrates power in the hands of companies, rather than protecting people.
AB 1709 is also inconsistent with rights to free expression and California will be spending resources to defend a law tied up in court. Instead, we should redouble our efforts to get technology laws right—and support the passage of new robust privacy laws that target surveillance business models. That’s how we protect everyone in the AI age.
Young people should be able to use technology in safe and healthy ways. The Golden State should model the gold standard laws that ensure technology works for everyone, rather than shut down access to digital forums in ways that do more harm than good.
"Social media bans like AB1709 make kids less safe, while undermining privacy and freedom of expression for everyone,” said Evan Greer, Director of Fight for the Future. “Young people have been on the forefront of every social movement throughout history that has led to positive social change. We need policies that empower young people rather than silencing them. These kid-focused bans are a gift to Big Tech giants, allowing them to continue operating their harmful business model while incentivizing them to collect even more data. California lawmakers should be ashamed. They didn't do anything to protect the kids, they just used kids as pawns to make good headlines."
“In a world of increasing stigma and marginalization for LGBTQ+ families, AB 1709 continues that trend by stripping people with LGBTQ+ parents of the ability to meet and build community with one another on the internet” said Jordan Wilson, Executive Director of COLAGE. “Beyond obstructing the right of youth with LGBTQ+ parents to access information, this bill places an undue burden on all Californians by forcing age verification at a time when digital privacy rights are being eroded globally. We cannot ‘protect children’ by stripping them of their primary avenue for connection.”
Contact: RindalaAlajajiAssociate Director of State Affairsrin@eff.orgProtecting organizations from AI-assisted executive impersonation and invoice fraud
Threat actors are increasingly improving their tactics to make suspicious emails look like legitimate email notifications to potential victims, deploying techniques that impersonate internally sent emails from executive team members. While this technique is not new, the adoption of AI has enabled threat actors to improve their campaign templates and construct emails tailored to their recipients. Additionally, threat actors are incorporating multiple techniques within the same email to improve the overall narrative further.
In this blog, we will discuss a recent campaign observed using third-party email delivery infrastructure to send out over a million financial fraud scam emails that displayed multiple indicators consistent with the use of generative AI during email template creation. The threat actor impersonated CEOs of multiple target companies, attempting to convince accounts payable departments of the same companies to process an Automated Clearing House (ACH) payment of nearly $50,000. To add legitimacy, the actor included a forwarded email thread (and a fabricated invoice) between the impersonated CEO and ServiceNow (which was also being impersonated).
Attack chain overviewThe campaign follows steps before and during the execution of the campaign: threat actors register impersonation domains, send executive-themed payment requests through trusted infrastructure, embed fabricated invoices and supporting conversations, and attempt to convince finance personnel to initiate ACH transfers.
Figure 1: Attack chain showing domain registration, executive impersonation, invoice fraud delivery, ACH payment execution, and financial theft. Email DeliveryBetween August 3 and 5, Microsoft detected a campaign consisting of more than a million emails targeting enterprise users. The attacker used multiple third-party email service accounts to send out the emails. A huge majority of these emails were sent to users in the United States (87.7% of the total campaign).
Figure 2. Campaign timeline. Figure 3. Industry distribution of targeted enterprises of this campaign with ‘IT services & business advisory’ along with ‘Consumer goods’ and others.Unlike traditional invoice scams that rely on a single social engineering lure, this campaign layered executive impersonation, vendor branding, fabricated invoices, and supporting email conversations into a unified narrative intended to reduce recipient skepticism.
The threat actor impersonated executive team members (such as a CEO, CFO, President) of multiple targeted companies, attempting to convince accounts payable departments of the same companies to process an ACH payment of nearly $50,000. More specifically, the CEOs were impersonated in multiple places in the email such as in the sender display name, reply-to display name, and in the email signature. Email bodies contained a simple and direct “approval” of the “invoice below” as well as urged users to request a PDF version if they need it. Additionally, as mentioned earlier, the email signature contained certain details about the spoofed CEO such as name and email address.
Figure 4. Spoofed message from executive team member.Important note: Throughout this campaign, threat actors impersonated legitimate organizations using attacker-controlled infrastructure, fabricated communications, and lookalike domains. Microsoft found no evidence that the legitimate organizations referenced in the lures, including ServiceNow, were compromised or involved in the activity. Rather, the campaign relied on fraudulent domains and content designed to mimic trusted brands and individuals.
The threat actor did not stop there. To add further legitimacy, directly below the CEO signature, the actor included “forwarded” content , specifically a professional looking but fabricated “ServiceNow Platform — Annual Subscription” invoice. The extremely detailed invoice contains various ServiceNow branding and logos. It has basic invoice details such as invoice number, issue and due dates, currency, amount due, payment method, and itemized line items. The payment method instructed is a bank transfer to accounts controlled by the threat actor. Microsoft observed the use of multiple financial institutions across samples, indicating that payment destinations may vary between targets. Certain parts of the invoice are personalized to the recipient. Specifically, the “BILLED TO” section has the recipient company name and executive name.
The invoice shown below is a threat actor-created impersonation and was not issued by ServiceNow.
Figure 5. Spoofed ServiceNow invoice.Finally, directly below the fake invoice, two more “forwarded” emails are included which are essentially a short conversation between the two spoofed executives (the targeted company executive, and ServiceNow President). The two executives are seen discussing the ServiceNow purchase, implementation and handling of the invoice.
Figure 6. “Forwarded” replies thread within the email lacking usual headers.From a defender point of view there are several indicators within the email indicating that the email and the “forwarded” thread are not genuine.
- “From” headers from the spoofed thread lack any data headers like actual forwarded emails.
- Suspicious language used in the spoofed thread such as “no need to copy me”.
- Suspicious language in headers i.e display name not matching sender address, subjects using financial lure keywords like ‘due bill’, ‘ACH Parment’ etc.
- Despite the sophistication of the generated content, several inconsistencies remained visible to defenders
- In real email threads, the previous threads are normally tabbed or otherwise visually grouped, while the previous threads in this example were left aligned.
- An additional inconsistency was observed where the targeted company’s CEO requested the recipient to send the invoice directly to victims and not CC the sender. However, in the most recent thread, the CEO stated that the invoice is approved and the invoice is sent from his address.
Before initiating the campaign, the threat actor registered several domains. A ‘ServiceNow’ lookalike domain service-nowinc[.]com was registered on July 31, shortly before the campaign activity was observed. This domain was used for the spoofed email address of ServiceNow President. It was also used in several places in the fabricated invoice such as in the contact email in case of any questions. The actor also registered another domain on the same day. The domain domainlify[.]net was used in the Reply-To email.
Figure 7. Account information linked with email of impersonated domain. Generative AI usageMicrosoft observed several indicators consistent with AI-assisted template development. These included extensive HTML comments, structured section labeling, and highly uniform template construction. While these indicators suggest generative AI involvement, they do not independently establish the extent to which AI generated campaign content.
Examples:
Figure 8. Code snippet showing a verbose HTML comment describing a section (a characteristic commonly observed in AI-generated code). Figure 9. Another code snippet showing extensive comments on HTML style elements and sections.Additionally, the use of ‘em dash’ (“—”) and banner ‘===========’ have also become other indicators associated with AI usage.
Figure 10. Another code example indicating AI usage. This example shows a verbose capitalized section header and yet more style elements excessively commented.One possible indication of template-based generation is that invoice identifiers and narrative structure remained largely consistent across samples while organization-specific details changed between targets.
Mitigation and protection guidanceMicrosoft provides layered protection against this type of executive-impersonation and invoice-fraud campaign. Properly configured email authentication, spoof protection, mail-flow connectors, and Microsoft Defender for Office 365 help identify and block suspicious messages before delivery; messages later determined to be malicious can be quarantined or removed through post-delivery remediation, including Zero-hour Auto Purge. Security teams can then use Microsoft Defender XDR and Security Copilot to investigate related alerts, affected users, and campaign indicators, coordinate response, and take remediation actions.
Together, these capabilities help reduce the likelihood that fraudulent payment requests reach finance personnel and support faster containment if a message is delivered.
To defend against social engineering campaigns involving executive impersonation, invoice fraud, and potentially AI-assisted content development, Microsoft recommends the following mitigations:
Configure automatic attack disruption in Microsoft Defender XDR. Automatic attack disruption is designed to contain attacks in progress, limit the impact on an organization’s assets, and provide more time for security teams to remediate the attack fully.
Enable Zero-hour auto purge (ZAP) in Office 365 to quarantine sent mail in response to newly acquired threat intelligence and retroactively neutralize malicious phishing, spam, or malware messages that have already been delivered to mailboxes.
Invest in advanced anti-phishing solutions that monitor and scan incoming emails and visited websites. For example, organizations can leverage web browsers like Microsoft Edge that automatically identify and block malicious websites, including those used in this phishing campaign, and solutions that detect and block malicious emails, links, and files.
These links provide information on how to properly configure mail flow with connectors:
- Manage mail flow using a third-party cloud service with Exchange Online
- Configure mail flow using connectors in Exchange Online
- Mail flow rules (transport rules) in Exchange Online
- Enhanced filtering for connectors in Exchange Online
These links provide information on configuring SPF, DKIM, and DMARC:
- Email authentication in cloud organizations
- Set up SPF to identify valid email sources for your custom cloud domains
- Set up DKIM to sign mail from your cloud domain
Microsoft Defender customers can refer to the list of applicable detections below. Microsoft Defender coordinates detection, prevention, investigation, and response across endpoints, identities, email, and apps to provide integrated protection against attacks like the threat discussed in this blog.
Tactic Observed activity Microsoft Defender coverage Financial TheftScam emailsMicrosoft Defender for Office 365– Invoice scams delivered detected as Spam and malicious categories.
– Email messages marked malicious removed after delivery and spam moved to quarantine
– Email messages removed after delivery
– Messages retroactively removed through Zero-hour Auto Purge (ZAP). Microsoft Security Copilot
Security Copilot customers can use the standalone experience to create their own prompts or run the following prebuilt promptbooks to automate incident response or investigation tasks related to this threat:
- Incident investigation
- Microsoft User analysis
- Threat actor profile
- Threat Intelligence 360 report based on MDTI article
- Vulnerability impact assessment
Note that some promptbooks require access to plugins for Microsoft products such as Microsoft Defender XDR or Microsoft Sentinel.
Threat intelligence reportsMicrosoft Defender XDR customers can use Threat Analytics reports in the Defender portal (requires license for at least one Defender XDR product) to get the most up-to-date information about the malicious activity and techniques discussed in this blog. These reports provide the intelligence, protection information, and recommended actions to prevent, mitigate, or respond to associated threats found in customer environments.
MITRE ATT&CK Techniques observedThis threat has exhibited use of the following attack techniques. For standard industry documentation about these techniques, refer to the MITRE ATT&CK framework.
ReconnaissanceT1591 – Gather Victim Organization Information
Threat actors collect publicly available information about target organizations, executives, finance personnel, vendors, and business relationships to build convincing invoice-fraud narratives.
T1598 – Phishing for Information
Information gathered from victims and public sources is used to craft highly targeted business email compromise (BEC) lures.
T1583.001 – Acquire Infrastructure: Domains
Threat actors register domains that impersonate trusted organizations, vendors, or business partners.
T1585.002 – Establish Accounts: Email Accounts
Attacker-controlled email accounts are created to support impersonation and fraudulent communications.
T1583 – Acquire Infrastructure
Third-party email delivery infrastructure and supporting services are leveraged to distribute campaigns.
T1566 – Phishing
Targeted phishing emails are delivered to finance personnel using executive and vendor impersonation themes.
T1566.001 – Spearphishing Attachment
Fraudulent invoices or supporting documents are attached to phishing emails.
T1566.003 – Spearphishing via Service
Third-party email services are used to distribute phishing messages and improve legitimacy.
T1036 – Masquerading
Attackers disguise emails, domains, invoices, and business correspondence as legitimate communications.
T1656 – Impersonation
Executives, vendors, and trusted business entities are impersonated to establish credibility and influence payment decisions.
T1657 – Financial Theft
Victims are deceived into transferring funds to attacker-controlled financial accounts through fraudulent invoice payment requests.
For the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.
To get notified about new publications and to join discussions on social media, follow us on LinkedIn, X (formerly Twitter), and Bluesky.
To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the Microsoft Threat Intelligence podcast.
Review our documentation to learn more about our real-time protection capabilities and see how to enable them within your organization.
- Learn more about securing Copilot Studio agents with Microsoft Defender
- Evaluate your AI readiness with our latest Zero Trust for AI workshop.
- Microsoft 365 Copilot AI security documentation
- How Microsoft discovers and mitigates evolving attacks against AI guardrails
- How Microsoft discovers and mitigates evolving attacks against AI guardrails | Microsoft Security Blog
- Manipulating AI memory for profit: The rise of AI Recommendation Poisoning | Microsoft Security Blog – a related example of an AI-era technique observed in email traffic
- Defending the inbox against prompt injection attacks | Microsoft Defender for Office 365 Blog – feature announcement introducing prompt injection protection in Microsoft Defender for Office 365.
- Prompt injection protection in Microsoft Defender for Office 365 – official documentation of the prompt injection protection in Microsoft Defender for Office 365.
The post Protecting organizations from AI-assisted executive impersonation and invoice fraud appeared first on Microsoft Security Blog.
Google DeepMind’s AI workers are attempting to unionise over ethical concerns around the provision of cloud and AI technologies to the US and Israeli militaries, but the company is pushing back
Maggie Philbin charity urges public sector leaders to mentor and sponsor, as students demand education reform, soft-skill extracurriculars and a ‘mission in AI literacy’
Building society creates a single company-wide data platform using Microsoft cloud technology
UHCW added daily theatre capacity and got correct utilisation data using Proximie’s AI as part of what partners describe as the NHS’s largest surgical AI deployment
Cybersecurity M&A Roundup: 33 Deals Announced in August 2026
Significant cybersecurity M&A deals announced by Brinqa, Cribl, Echo, Fortinet, Kiteworks, Palo Alto Networks, and Visa.
The post Cybersecurity M&A Roundup: 33 Deals Announced in August 2026 appeared first on SecurityWeek.
The Apple Watch Gets Its Siri AI Upgrade
Show HN: Pascal's Pager – Webhooks In. Push Notifications Out
Sometimes it just takes too long to parse a webhook from one service to another just so you can get a push notification on your iPhone.
Pascal's Pager turns any JSON webhook data into a human readable push notification on your iPhone using AI.
It includes notification grouping and data redaction so you can select to exclude specific values from ever going to the AI.
Comments URL: https://news.ycombinator.com/item?id=49646009
Points: 1
# Comments: 0
Gambit Loop: a roguelike where you write IF/THEN rules instead of playing
Article URL: https://store.steampowered.com/app/4531320/Gambit_Loop/
Comments URL: https://news.ycombinator.com/item?id=49646008
Points: 1
# Comments: 0
Show HN: MySamantha – a productivity app where the AI is optional
Most of the recent tools being developed are versions of the personal assistant that everyone has been promising for a long time. I see ChatGPT, Claude, Gemini, Instinct (now viral), Muse, and many more. When I started to build MySamantha I thought about building a personal assistant as well. Connect email and calendar accounts to it, add some memory and context, give it some tools and it'll do things for you.
I did launch it before here, and we realized that we were putting the least permanent part of the system at the center. I started wondering why the Assistant had to be the main product?
But before that, why do I need a personal assistant? I was on team productivity before and I only wanted the AI to make me more productive.
I had Notion, Obsidian, Todoist and I used them to be more productive at work and since ChatGPT came, I started using that heavily. But one thing that continued to piss me off is the fact that I am unable to share context between what I wanted to do.
Sure, I am going to complain what each of these productivity apps did. Every productivity app had so much enshittification with AI stuffed down my throat that even though I love AI, I stopped going into those apps. Agents and shit. I don't need that, give me back my simple note taking app which I always loved. Their MCPs? No. I had context all over. I wanted something simple.
With Models increasing intelligence day by day and labs releasing more and more models, there's one thing I knew for sure. Idk which model I'll be using two years from now. But I know I'll still have my emails, calendars, notes, documents, tasks, meetings and everything I've accumulated.
So we started building MySamantha around that instead (I launched MySamantha before here)
Instead of a separate Notes app, Todo app, Email client or Calendar for everything, we built a place where I can work on all at the same place. Combine AI, connect my emails, my calendars associated with my work email, my Meeting Recorder are all here.
At the same time, we don't want "everything in one place" to mean everything is stuck here. You can import from Notion, back your notes to both Notion and Google drive (as Google Docs), your to-do from Todoist or Microsoft To-do, import your vault from Obsidian, enjoy the same knowledge graph as Obsidian does, Export, etc.,
MySamantha sits on top of this.
You can use any models. Bring your OpenAI, Anthropic, Google or even pay-as-you-go. If another model becomes better, change it.
Don't like AI? switch it off. The product still works.
The best part? everything is here in one place. Compare the meeting notes I had with the email I received to draft an email? yup, done. All context in one place. The Assistant becomes more useful, the more it knows about you.
No model lock-ins. A pure productivity personal workspace where you can switch AI off if you don't need it.
Feel free to check out what we're trying at https://mysamantha.ai
Curious to know what HN thinks about this. Feedbacks and Queries welcome.
Comments URL: https://news.ycombinator.com/item?id=49645994
Points: 1
# Comments: 0
Pamir AI Launches the Lapis One Linux Computer with Built-In Agent KVM Feature
Article URL: https://www.hackster.io/news/pamir-ai-launches-the-lapis-one-linux-computer-2c5446b94a23
Comments URL: https://news.ycombinator.com/item?id=49645974
Points: 1
# Comments: 0
Detect and disrupt AI-themed attacks with Microsoft Defender
Every wave of technology excitement creates a new opportunity for cyberattackers, and AI is no exception. Microsoft Threat Intelligence has published research showing a growing set of campaigns that impersonate popular AI platforms and tools, including ChatGPT, Microsoft Copilot, DeepSeek, and Claude.1 The goal is to make phishing, search-driven malware campaigns, and malvertising—which is malicious advertising that uses online ads to lure users to harmful sites, downloads, or redirect chains—more convincing. A ChatGPT-themed phishing campaign sent up to 100,000 emails in a single day, tricking users into updating their ChatGPT Plus payment information and stealing personal and credit card data. These campaigns do not represent a compromise of the AI services being referenced. They represent something more familiar—cyberattackers doing what they have always done: borrowing trust. Right now, AI brands can carry significant trust and curiosity, making them attractive themes for cyberattackers to exploit.
Prevent and disrupt cyberthreats with Microsoft DefenderUnderstanding why this trend matters and what it means for security teams is critical to shaping a modern protection strategy. The tactics are the same ones cyberattackers have always refined: urgency, curiosity, and impersonation of something familiar to lower a user’s guard. What has changed is the wrapper. A message about a new model release, a policy update from a familiar AI assistant, or a plugin that promises to make the workday easier is today’s version of the fake invoice or the shipping notification. AI-themed lures deserve attention not because they are a passing trend tied to one product cycle, but because AI remains a genuine source of excitement and urgency for employees and consumers alike, and cyberattackers are exploiting the human instinct to explore what is new, useful, or urgent.
The attack pattern is evolvingMicrosoft’s research team recently observed several AI brand campaigns including:
- A ChatGPT-themed phishing kit built to harvest credit card data.
- A Claude-themed campaign that harvested credentials and access tokens through adversary-in-the-middle (AiTM) techniques.
- Malvertising for a fake AI Windows plugin that delivered the Vidar stealer.
- Fraudulent DeepSeek installers distributed through GitHub.
In one case, an initial access broker tracked as Storm-3075 used AI-themed malvertising to distribute payloads for multiple downstream actors, a sign of how quickly this tactic is being commoditized across the criminal ecosystem.
Figure 1. Snippet of the top portion of the email impersonating ChatGPT and enticing users to click on the link.What ties these campaigns together is not sophistication in the traditional sense. It is patience and precision in exploiting a moment. Threat actors are capitalizing on anticipated launches and emerging trends, layering multi-stage redirection chains and disposable infrastructure to slip past both users and defenses. That has real implications for security leaders: it means these incidents cannot be evaluated one surface at a time. A single AI-themed lure can begin as an email, become a malicious link, trigger a suspicious download, and end as an identity or endpoint compromise. Organizations that assess each of those as an isolated event are always a step behind. Organizations that connect them see the full shape of the cyberattack, often early enough to stop it.
Turning AI lures into dead ends with Microsoft DefenderIn practice, protection starts before the user ever engages with the lure. Microsoft Defender’s anti-phishing policies can help detect spoofing and impersonation attempts, including user and domain impersonation, first-contact messages, mailbox intelligence signals, and other suspicious sender characteristics. For an AI-themed lure, that might look like a fake “Copilot policy update,” a spoofed support notice, or a lookalike domain designed to make a credential collection page feel legitimate.
If the campaign relies on links, Defender’s Safe Links provides URL scanning and detonation during mail flow, plus time-of-click verification when a user selects a link in email, Microsoft Teams, or supported Microsoft 365 apps. That is important when cyberattackers use redirect chains, delayed activation, or links that appear benign at delivery but later resolve to phishing infrastructure, fake sign-in pages, or malicious downloads.
For campaigns that use fake installers, malicious downloads, or weaponized attachments, Safe Attachments adds another layer by detonating attachments in a virtual environment before delivery when policies are configured. For example, if a message promotes a “new AI plugin” but includes a harmful attachment, Safe Attachments can analyze the file for malware, ransomware, or phishing behavior before it reaches the user. If a cyberthreat is identified after delivery, Defender’s post-delivery filtering capabilities help remove malicious content from mailboxes and reduce the window of exposure.
Figure 2. Simplified Defender email detection stack with pre-delivery and post-delivery protections. Protect against multi-stage attacks with attack disruptionBut AI-powered attacks don’t stop at email. Their objective is to gain the highest level of access possible, using compromised accounts as a foothold to move across identities, devices, and data. When a cyberattack moves beyond the inbox, Defender helps connect the evidence. Signals from email and collaboration tools, endpoints, identities, and software as a service (SaaS) apps are correlated into an attack story so analysts can see whether the same lure led to a clicked link, a downloaded payload, risky sign-in behavior, or endpoint activity.
As cyberattackers expand beyond email to gain broader access across the environment, Defender moves from detection to disruption. For multi-stage, multi-domain attacks like business email compromise or AiTM, Defender’s powerful, built-in response capability, attack disruption, will contain the compromised asset during the attack to prevent further lateral movement while security teams investigate and remediate. Attack disruption contains more than 81,000 compromised user accounts monthly and is now disrupting more than 45,000 AiTM attacks each month.
Figure 3. Recent attack disruption statistics. (Source: Internal Microsoft Research, September 2026)In a recent case study, Defender disrupted a business email compromise attack within four minutes of the initial activity (Figure 4). While response times may vary by scenario, this case shows the impact of attack disruption on a real cyberthreat. The cyberattacker used a convincing document-sharing lure to trick a user to start a legitimate Microsoft device code sign-in flow, which avoided traditional credential theft techniques. Defender recognized the resulting device code authentication and follow-on activity as suspicious, correlated signals across identity and email telemetry, and disrupted the attack within four minutes before the attacker could establish persistence, create inbox rules, or execute payroll fraud.
Figure 4. Business email compromise attack through OAuth device code phishing. The takeawayAI brands are the new bait, but the underlying lesson is bigger than any single campaign. As cyberattackers continue to exploit the momentum around AI, organizations should expect social engineering to become more targeted, more believable, and more difficult to evaluate in isolation.
The answer is not to treat every new lure as a brand-new category of risk. It is to build a protection model that makes trust harder to exploit across the full attack chain. Microsoft Defender helps organizations do that by connecting prevention, detection, investigation, and response across the attack path, so AI-themed lures are harder to deliver, harder to trust, and harder to turn into broader compromise.
Learn more about Microsoft DefenderTo learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.
1AI brands as bait: How threat actors are using the AI hype in social engineering, Microsoft Threat Intelligence. June 8, 2026.
The post Detect and disrupt AI-themed attacks with Microsoft Defender appeared first on Microsoft Security Blog.
The Nexus of Critical Citizenship and Social Media (2020)
Article URL: https://citejournal.org/volume-19/issue-4-19/social-studies/the-nexus-of-critical-citizenship-and-social-media/
Comments URL: https://news.ycombinator.com/item?id=49645919
Points: 2
# Comments: 0
