# spoofing

A cybersecurity technique in which an attacker impersonates an authorized user or induces a user or resource to take an incorrect action.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Protecting organizations from AI-assisted executive impersonation and invoice fraud

DevFeed: [Protecting organizations from AI-assisted executive impersonation and invoice fraud](<https://devfeed.tech/articles/protecting-organizations-from-ai-assisted-executive-impersonation-and-invoice-fraud-7645.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/>)

Author: Microsoft Security Research

Published: 2026-09-10T17:23:05Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [spoofing](<https://devfeed.tech/topics/spoofing.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [executive](<https://devfeed.tech/tags/executive.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [scam](<https://devfeed.tech/tags/scam.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>)

### AI overview

Microsoft examines an email-fraud campaign that used AI-assisted executive impersonation, fabricated invoices, and fake supporting conversations to prompt ACH payments.

### Source excerpt

Microsoft examines an AI-assisted business email compromise campaign that used executive impersonation and fake invoices to target finance teams with ACH payment fraud. The post Protecting organizations from AI-assisted executive impersonation and invoice fraud appeared first on Microsoft Security Blog.

## Detect and disrupt AI-themed attacks with Microsoft Defender

DevFeed: [Detect and disrupt AI-themed attacks with Microsoft Defender](<https://devfeed.tech/articles/detect-and-disrupt-ai-themed-attacks-with-microsoft-defender-7644.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/10/detect-and-disrupt-ai-themed-attacks-with-microsoft-defender/>)

Author: Rob Lefferts

Published: 2026-09-10T16:00:00Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [adversary-in-the-middle-aitm](<https://devfeed.tech/tags/adversary-in-the-middle-aitm.md>), [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [claude](<https://devfeed.tech/tags/claude.md>), [copilot](<https://devfeed.tech/tags/copilot.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [deepseek](<https://devfeed.tech/tags/deepseek.md>), [defender](<https://devfeed.tech/tags/defender.md>), [github](<https://devfeed.tech/tags/github.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>)

### AI overview

Microsoft describes AI-themed phishing, malvertising, credential theft, and malware campaigns that impersonate popular AI services and tools. It argues that attackers are exploiting trust and urgency around AI brands rather than compromising the referenced services.

### Source excerpt

See how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain. The post Detect and disrupt AI-themed attacks with Microsoft Defender appeared first on Microsoft Security Blog.

## Defending against AI-fueled social engineering

DevFeed: [Defending against AI-fueled social engineering](<https://devfeed.tech/articles/defending-against-ai-fueled-social-engineering-4794.md>)

Original publisher: [Read original article](<https://www.elastic.co/blog/defending-against-ai-fueled-social-engineering>)

Author: Joe DeFever

Published: 2026-09-01T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Blog - Elasticsearch, Kibana, and ELK Stack](<https://devfeed.tech/sources/elastic-blog-elasticsearch-kibana-and-elk-stack.md>)

Topics: [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>)

Tags: [agentic-ai-alerting-security-analytics](<https://devfeed.tech/tags/agentic-ai-alerting-security-analytics.md>), [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [soc](<https://devfeed.tech/tags/soc.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>)

### AI overview

The article describes how AI enables personalized spear phishing, smishing, and deepfake-based impersonation at greater scale. It argues that defenders should detect behavioral signals rather than rely solely on static signatures and known patterns.

### Source excerpt

AI is supercharging social engineering. Learn how SOC teams can detect deepfakes, spear phishing, and smishing before they cause real damage.

## This month in security with Tony Anscombe - August 2026 edition

DevFeed: [This month in security with Tony Anscombe - August 2026 edition](<https://devfeed.tech/articles/this-month-in-security-with-tony-anscombe-august-2026-edition-8418.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/videos/month-security-tony-anscombe-august-2026/>)

Author: Editor

Published: 2026-08-31T08:55:00Z

Content type: news

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [hugging face](<https://devfeed.tech/topics/hugging-face.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>), [Flight](<https://devfeed.tech/topics/flight.md>), [Network](<https://devfeed.tech/topics/network.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [airline](<https://devfeed.tech/tags/airline.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [hugging-face](<https://devfeed.tech/tags/hugging-face.md>), [incident](<https://devfeed.tech/tags/incident.md>), [network](<https://devfeed.tech/tags/network.md>), [openai](<https://devfeed.tech/tags/openai.md>), [spoof](<https://devfeed.tech/tags/spoof.md>), [video](<https://devfeed.tech/tags/video.md>)

### AI overview

Tony Anscombe reviews major cybersecurity stories from August 2026, including the Hugging Face hack involving OpenAI agents, attacks on critical infrastructure, a spoofed airline Wi-Fi network, and the shutdown of fraudulent call centers in Ukraine.

### Source excerpt

Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity news

## The day after the zero-days

DevFeed: [The day after the zero-days](<https://devfeed.tech/articles/the-day-after-the-zero-days-10852.md>)

Original publisher: [Read original article](<https://blog.apnic.net/2026/08/28/the-day-after-the-zero-days/>)

Author: Niels Provos

Published: 2026-08-28T04:42:57Z

Content type: opinion

Language: en

Sources: [APNIC Blog](<https://devfeed.tech/sources/apnic-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Orchestration](<https://devfeed.tech/topics/orchestration.md>), [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Code](<https://devfeed.tech/topics/code.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [anthropic](<https://devfeed.tech/topics/anthropic.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Frontier Model](<https://devfeed.tech/topics/frontier-model.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [ai](<https://devfeed.tech/tags/ai.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [guest-post](<https://devfeed.tech/tags/guest-post.md>), [model](<https://devfeed.tech/tags/model.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [tech-matters](<https://devfeed.tech/tags/tech-matters.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

The article reflects on three decades of vulnerability research, contrasting a historically manual TCP source-routing spoofing discovery with an AI-assisted discovery of a long-standing OpenBSD kernel bug. It argues that vulnerability discovery is primarily an orchestration problem, demonstrates the capability with the open-source IronCurtain framework and several language models, and warns that defenders and attackers should assume capability parity.

### Source excerpt

Guest Post: Patching faster cannot keep up with AI-driven discovery. Leverage structural invariants to make bug classes irrelevant.

## Time: The cornerstone of digital sovereignty and independence

DevFeed: [Time: The cornerstone of digital sovereignty and independence](<https://devfeed.tech/articles/time-the-cornerstone-of-digital-sovereignty-and-independence-10840.md>)

Original publisher: [Read original article](<https://blog.apnic.net/2026/08/18/time-the-cornerstone-of-digital-sovereignty-and-independence/>)

Author: Luca Cicchelli

Published: 2026-08-18T01:45:10Z

Content type: article

Language: en

Sources: [APNIC Blog](<https://devfeed.tech/sources/apnic-blog.md>)

Topics: [digital sovereignty](<https://devfeed.tech/topics/digital-sovereignty.md>), [systems](<https://devfeed.tech/topics/systems.md>), [1.1.1.1](<https://devfeed.tech/topics/1-1-1-1.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [5G](<https://devfeed.tech/topics/5g.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [5g](<https://devfeed.tech/tags/5g.md>), [ai](<https://devfeed.tech/tags/ai.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [digital-sovereignty](<https://devfeed.tech/tags/digital-sovereignty.md>), [energy](<https://devfeed.tech/tags/energy.md>), [gnss](<https://devfeed.tech/tags/gnss.md>), [guest-post](<https://devfeed.tech/tags/guest-post.md>), [ixps](<https://devfeed.tech/tags/ixps.md>), [operational](<https://devfeed.tech/tags/operational.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [systems](<https://devfeed.tech/tags/systems.md>), [tech-matters](<https://devfeed.tech/tags/tech-matters.md>), [time](<https://devfeed.tech/tags/time.md>)

### AI overview

Time is presented as a foundational requirement for digital sovereignty and independent operation. The article explains how synchronized time supports telecommunications, finance, energy, cloud and AI systems, and transport, while dependence on GNSS introduces risks from interference, jamming, and spoofing.

### Source excerpt

Guest Post: Though often overlooked, time underpins telecommunications, finance, energy, cloud, AI, and transport systems. As dependence on GNSS increases, organizations need resilient, traceable time sources to strengthen cybersecurity, improve operational continuity, and support digital sovereignty.

## Disrupting a Criminal Scam Operation

DevFeed: [Disrupting a Criminal Scam Operation](<https://devfeed.tech/articles/disrupting-a-criminal-scam-operation-6383.md>)

Original publisher: [Read original article](<https://openai.com/index/disrupting-malicious-uses-of-ai-criminal-scam-operation>)

Published: 2026-07-31T00:00:00Z

Content type: article

Language: en

Sources: [OpenAI News](<https://devfeed.tech/sources/openai-news.md>)

Topics: [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>)

Tags: [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [openai](<https://devfeed.tech/tags/openai.md>), [safety](<https://devfeed.tech/tags/safety.md>), [scam](<https://devfeed.tech/tags/scam.md>), [scams](<https://devfeed.tech/tags/scams.md>), [southeast-asia](<https://devfeed.tech/tags/southeast-asia.md>)

### AI overview

OpenAI describes disrupting a Cambodia-based criminal scam operation that used ChatGPT to create fake personas, generate and translate scam messages, produce promotional content, and support administrative work. The operation involved investment, romance, gambling, and impersonation schemes, with possible links to human trafficking and forced criminality.

### Source excerpt

OpenAI disrupted a Cambodia-based scam operation using ChatGPT to support investment, romance, gambling, and impersonation schemes.

## Inside an AI coal mine security camera network powered by plaintext passwords

DevFeed: [Inside an AI coal mine security camera network powered by plaintext passwords](<https://devfeed.tech/articles/inside-an-ai-coal-mine-security-camera-network-powered-by-plaintext-passwords-32622.md>)

Original publisher: [Read original article](<https://eaton-works.com/2026/07/08/coal-india-camera-hack/>)

Author: Eaton

Published: 2026-07-08T17:07:38Z

Content type: opinion

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [API](<https://devfeed.tech/topics/api.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [breach](<https://devfeed.tech/tags/breach.md>), [browser](<https://devfeed.tech/tags/browser.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [security](<https://devfeed.tech/tags/security.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This security write-up examines Coal India's Project DigiCoal camera-monitoring platform, developed by DeepSight AI Labs and Accenture. It reports that the RPI Dashboard exposed user accounts and plaintext, weak, duplicated passwords through an unauthenticated API. The article also describes bypassing client-side access controls to view camera alerts and feeds across seven coal mines.

### Source excerpt

Coal India's intelligent CCTV platform developed by DeepSight AI Labs and Accenture had plaintext passwords and no API authentication.

## How Android helps keep you safe from impersonation scams with fake call detection

DevFeed: [How Android helps keep you safe from impersonation scams with fake call detection](<https://devfeed.tech/articles/how-android-helps-keep-you-safe-from-impersonation-scams-with-fake-call-detection-7617.md>)

Original publisher: [Read original article](<https://blog.google/security/android-fake-call-detection/>)

Author: Oren Schetrit

Published: 2026-06-02T18:00:00Z

Content type: release

Language: en

Sources: [Security](<https://devfeed.tech/sources/security.md>)

Topics: [spoofing](<https://devfeed.tech/topics/spoofing.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [android](<https://devfeed.tech/tags/android.md>), [android-security](<https://devfeed.tech/tags/android-security.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [audio](<https://devfeed.tech/tags/audio.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [mobile-security](<https://devfeed.tech/tags/mobile-security.md>), [none](<https://devfeed.tech/tags/none.md>), [scams](<https://devfeed.tech/tags/scams.md>), [spoof](<https://devfeed.tech/tags/spoof.md>), [voice](<https://devfeed.tech/tags/voice.md>), [voice-cloning](<https://devfeed.tech/tags/voice-cloning.md>)

### AI overview

Android introduces fake call detection to flag suspected spoofed calls between contacts using Phone by Google, aiming to counter AI voice-cloning impersonation scams.

### Source excerpt

Warning that says 'someone may be pretending to call from your contact's number'

## What's New in Android Security and Privacy in 2026

DevFeed: [What's New in Android Security and Privacy in 2026](<https://devfeed.tech/articles/what-s-new-in-android-security-and-privacy-in-2026-7635.md>)

Original publisher: [Read original article](<https://blog.google/security/whats-new-in-android-security-privacy-2026/>)

Author: Eugene Liderman

Published: 2026-05-12T17:00:00Z

Content type: article

Language: en

Sources: [Security](<https://devfeed.tech/sources/security.md>)

Topics: [Android](<https://devfeed.tech/topics/android.md>), [Android Security](<https://devfeed.tech/topics/android-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [On-device AI](<https://devfeed.tech/topics/on-device-ai.md>), [Chrome](<https://devfeed.tech/topics/chrome.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [android](<https://devfeed.tech/tags/android.md>), [android-security](<https://devfeed.tech/tags/android-security.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [none](<https://devfeed.tech/tags/none.md>), [on-device-ai](<https://devfeed.tech/tags/on-device-ai.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

The article describes planned Android security and privacy enhancements for 2026, including verified financial calls to combat spoofed banking scams. Android can verify incoming calls through participating financial apps and automatically end calls that are not genuine. It also highlights expanded Live Threat Detection, which uses on-device AI to analyze app behavior and warn about suspicious activity.

### Source excerpt

New Android security and privacy features

## This month in security with Tony Anscombe - April 2026 edition

DevFeed: [This month in security with Tony Anscombe - April 2026 edition](<https://devfeed.tech/articles/this-month-in-security-with-tony-anscombe-april-2026-edition-8416.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/videos/month-security-tony-anscombe-april-2026/>)

Author: Editor

Published: 2026-04-30T09:00:00Z

Content type: news

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [spoofing](<https://devfeed.tech/topics/spoofing.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [helpdesk](<https://devfeed.tech/tags/helpdesk.md>), [iran](<https://devfeed.tech/tags/iran.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [microsoft-teams](<https://devfeed.tech/tags/microsoft-teams.md>), [scams](<https://devfeed.tech/tags/scams.md>), [security](<https://devfeed.tech/tags/security.md>), [us](<https://devfeed.tech/tags/us.md>), [video](<https://devfeed.tech/tags/video.md>)

### AI overview

A monthly video security roundup covers Microsoft Teams helpdesk impersonation scams, Iran-linked targeting of Rockwell PLCs at U.S. critical-infrastructure organizations, and FBI figures on cyber-enabled crime.

### Source excerpt

Warnings about helpdesk impersonation scams and Iran-linked hackers targeting critical sectors in the US, plus the most damaging scams of 2025 - here's some of what made the headlines this month

## As breakout time accelerates, prevention-first cybersecurity takes center stage

DevFeed: [As breakout time accelerates, prevention-first cybersecurity takes center stage](<https://devfeed.tech/articles/as-breakout-time-accelerates-prevention-first-cybersecurity-takes-center-stage-8326.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/breakout-time-accelerates-prevention-first-cybersecurity-center-stage/>)

Author: Phil Muncaster

Published: 2026-04-07T09:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-automation](<https://devfeed.tech/tags/ai-automation.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [automation](<https://devfeed.tech/tags/automation.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [tools](<https://devfeed.tech/tags/tools.md>)

### AI overview

Threat actors are using AI, automation, credential theft, phishing, zero-day exploits, reconnaissance, and AI-powered scripts to accelerate attacks. The article argues that shrinking breakout times require defenders to adopt a prevention-first cybersecurity strategy.

### Source excerpt

Threat actors are using AI to supercharge tried-and-tested TTPs. When attacks move this fast, cyber-defenders need to rethink their own strategy.

## A cunning predator: How Silver Fox preys on Japanese firms this tax season

DevFeed: [A cunning predator: How Silver Fox preys on Japanese firms this tax season](<https://devfeed.tech/articles/a-cunning-predator-how-silver-fox-preys-on-japanese-firms-this-tax-season-8328.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/cunning-predator-how-silver-fox-preys-japanese-firms-tax-season/>)

Author: Dominik Breitenbacher Takahiro Sajima

Published: 2026-03-27T07:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [business](<https://devfeed.tech/tags/business.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [finance](<https://devfeed.tech/tags/finance.md>), [government](<https://devfeed.tech/tags/government.md>), [japan](<https://devfeed.tech/tags/japan.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>)

### AI overview

Silver Fox is conducting a targeted spearphishing campaign against Japanese manufacturers and other businesses during tax-filing and organizational-change season. The attackers use convincing tax- and HR-themed emails, links, and attachments to exploit expected business communications and increase the likelihood of compromise.

### Source excerpt

Silver Fox is back in Japan, spoofing tax and HR emails timed to the one season when no one thinks twice about opening them

## Face value: What it takes to fool facial recognition

DevFeed: [Face value: What it takes to fool facial recognition](<https://devfeed.tech/articles/face-value-what-it-takes-to-fool-facial-recognition-8394.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/privacy/face-value-what-takes-fool-facial-recognition/>)

Author: Tomáš Foltýn

Published: 2026-03-13T10:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [conference](<https://devfeed.tech/tags/conference.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [financial-services](<https://devfeed.tech/tags/financial-services.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [fraud-prevention](<https://devfeed.tech/tags/fraud-prevention.md>), [identity](<https://devfeed.tech/tags/identity.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [uk](<https://devfeed.tech/tags/uk.md>)

### AI overview

ESET cybersecurity advisor Jake Moore demonstrates how facial recognition can be misused and defeated. His tests used identity-finding smart glasses, an AI-generated face to bypass bank onboarding, and real-time face-swapping software to evade a facial recognition watchlist.

### Source excerpt

ESET's Jake Moore used smart glasses, deepfakes and face swaps to 'hack' widely-used facial recognition systems - and he'll demo it all at RSAC 2026

## Taxing times: Top IRS scams to look out for in 2026

DevFeed: [Taxing times: Top IRS scams to look out for in 2026](<https://devfeed.tech/articles/taxing-times-top-irs-scams-to-look-out-for-in-2026-8411.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/scams/taxing-times-top-irs-scams-look-out-2026/>)

Author: Phil Muncaster

Published: 2026-02-10T10:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [malware](<https://devfeed.tech/tags/malware.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [scams](<https://devfeed.tech/tags/scams.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [tax](<https://devfeed.tech/tags/tax.md>), [tax-return](<https://devfeed.tech/tags/tax-return.md>)

### AI overview

The article outlines common IRS and tax-return scams, including impersonation through phone, email, text, and social media; demands for urgent payment; requests for personal or financial information; fraudulent refund claims; and attempts to deliver malware. It also warns that AI-assisted scams can make deceptive messages and calls harder to recognize.

### Source excerpt

It's time to file your tax return. And cybercriminals are lurking to make an already stressful period even more edgy.

## Drowning in spam or scam emails? Here's probably why

DevFeed: [Drowning in spam or scam emails? Here's probably why](<https://devfeed.tech/articles/drowning-in-spam-or-scam-emails-here-s-probably-why-8351.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/cybersecurity/drowning-spam-scam-emails-why/>)

Author: Phil Muncaster

Published: 2026-01-27T10:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [obfuscation](<https://devfeed.tech/topics/obfuscation.md>), [pii](<https://devfeed.tech/topics/pii.md>), [data](<https://devfeed.tech/topics/data.md>), [Internet](<https://devfeed.tech/topics/internet.md>), [Netflix](<https://devfeed.tech/topics/netflix.md>)

Tags: [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [data](<https://devfeed.tech/tags/data.md>), [digital-security](<https://devfeed.tech/tags/digital-security.md>), [internet](<https://devfeed.tech/tags/internet.md>), [malware](<https://devfeed.tech/tags/malware.md>), [obfuscation](<https://devfeed.tech/tags/obfuscation.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [pii](<https://devfeed.tech/tags/pii.md>), [scam](<https://devfeed.tech/tags/scam.md>), [security](<https://devfeed.tech/tags/security.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>)

### AI overview

This article explains why inboxes can suddenly be flooded with spam and scam emails. It identifies data breaches, leaked personal information, updated phishing kits, spam-filter bypasses, and targeted campaigns as possible causes, and describes risks including credential theft, financial fraud, and malware installation.

### Source excerpt

Has your inbox recently been deluged with unwanted and even outright malicious messages? Here are 10 possible reasons - and how to stem the tide.

## Doppel's AI defense system stops attacks before they spread

DevFeed: [Doppel's AI defense system stops attacks before they spread](<https://devfeed.tech/articles/doppel-s-ai-defense-system-stops-attacks-before-they-spread-6387.md>)

Original publisher: [Read original article](<https://openai.com/index/doppel>)

Published: 2025-10-28T10:00:00Z

Content type: article

Language: en

Sources: [OpenAI News](<https://devfeed.tech/sources/openai-news.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Fine-tuning](<https://devfeed.tech/topics/fine-tuning.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [human feedback](<https://devfeed.tech/topics/human-feedback.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [fine-tuning](<https://devfeed.tech/tags/fine-tuning.md>), [gpt](<https://devfeed.tech/tags/gpt.md>), [human-feedback](<https://devfeed.tech/tags/human-feedback.md>), [internet](<https://devfeed.tech/tags/internet.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

Doppel uses OpenAI GPT-5 and o4-mini models, together with reinforcement fine-tuning and human-graded feedback, to detect, classify, and remove deepfake, phishing, spoofed-domain, and impersonation threats. The system reduces analyst workloads by 80%, triples threat-handling capacity, and cuts response times from hours to minutes.

### Source excerpt

Doppel uses GPT-5 and reinforcement fine-tuning to stop deepfake and impersonation attacks, cutting analyst workloads by 80% and reducing response times from hours to minutes.

## Homographic Spoofing: a new Ruby toolkit

DevFeed: [Homographic Spoofing: a new Ruby toolkit](<https://devfeed.tech/articles/homographic-spoofing-a-new-ruby-toolkit-33502.md>)

Original publisher: [Read original article](<https://dev.37signals.com/homographic-spoofing/>)

Author: Jacopo Beschi

Published: 2024-06-25T17:00:00Z

Content type: tutorial

Language: en

Sources: [37signals Dev](<https://devfeed.tech/sources/37signals-dev.md>)

Topics: [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Ruby](<https://devfeed.tech/topics/ruby.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [email](<https://devfeed.tech/topics/email.md>), [domain](<https://devfeed.tech/topics/domain.md>), [ASCII](<https://devfeed.tech/topics/ascii.md>)

Tags: [ascii](<https://devfeed.tech/tags/ascii.md>), [domain](<https://devfeed.tech/tags/domain.md>), [email](<https://devfeed.tech/tags/email.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [ruby](<https://devfeed.tech/tags/ruby.md>), [security](<https://devfeed.tech/tags/security.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>)

### AI overview

This article explains homograph attacks, in which visually similar Unicode characters are used to spoof identities in domains or email. It describes browser and email-client protections using Punycode and UTS #39, then introduces an open-source Ruby gem implementing those guidelines for IDNs and email addresses.

### Source excerpt

What is a homograph attack and how to protect from it with a new gem.

## Port Scan with Spoofed IP Addresses

DevFeed: [Port Scan with Spoofed IP Addresses](<https://devfeed.tech/articles/port-scan-with-spoofed-ip-addresses-30831.md>)

Original publisher: [Read original article](<https://hookrace.net/blog/port-scan-with-spoofed-ip-addresses/>)

Published: 2024-03-18T23:00:00Z

Content type: opinion

Language: en

Sources: [Dennis Felsing](<https://devfeed.tech/sources/dennis-felsing.md>)

Topics: [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [networking](<https://devfeed.tech/topics/networking.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [game-servers](<https://devfeed.tech/tags/game-servers.md>), [incident](<https://devfeed.tech/tags/incident.md>), [network](<https://devfeed.tech/tags/network.md>), [networking](<https://devfeed.tech/tags/networking.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>)

### AI overview

The article describes how spoofed-source port scans can cause abuse reports to be misattributed to a victim's VPS, potentially leading a hoster to suspend or terminate the server. It presents the scenario in a satirical, adversarial tone and discusses defensive traffic-blocking measures.

### Source excerpt

Or how to make naïve hosters shut down your victim's server. Do you want to bring down your victim's game servers? Do they host their game servers on cheap VPSes at hosters who are not that experienced with networking? Is running an actual DoS against the server too expensive and illegal for you? Just grab a server for yourself from a questionable hoster with IP address spoofing allowed on their network. Next run a port scan using nmap (man page) with a spoofed source address (-S or -D for multiple decoys) using your victim's IP address(es). As the target of the port scan choose a university with a cybersecurity department that likes to send security incident reports to abuse mail addresses. To the target university of the port scan it will look like the scan came from your victim, since you are spoofing their IP address, so they will send a serious sounding email to the victim's hoster: As a consequence your victim's VPS will most likely be shut down for a few hours or even days. To prevent this your victim will try to block all of their incoming and outgoing TCP traffic on their VPS, and also block the reporting university's IP range entirely: $ iptables -L Chain INPUT (policy ACCEPT) target prot opt source destination DROP all -- 147.251.0.0/16 anywhere DROP tcp -- anywhere anywhere tcp ctstate NEW multiport dports !27685,6546,ssh Chain OUTPUT (policy ACCEPT) target prot opt source destination DROP all -- anywhere 147.251.0.0/16 And yet you can rerun your port scan against the university's network every day, which will trigger automatic abuse mails to the victim's hoster, who will still trust these abuse mails more than the victim, since the hoster is unlikely to be able to monitor the network traffic of the VPS to check if those packets actually originated there. At some point the hoster will be so annoyed that they simply terminate the VPS and throw out the customer, victory! Congratulations, you have brought down some small-fish game servers in the DDNet commu

## Reflecting on Threats: The Frame

DevFeed: [Reflecting on Threats: The Frame](<https://devfeed.tech/articles/reflecting-on-threats-the-frame-36953.md>)

Original publisher: [Read original article](<https://shostack.org/blog/reflecting-on-threats-the-frame/>)

Author: Adam

Published: 2023-04-10T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [systems](<https://devfeed.tech/topics/systems.md>), [standard](<https://devfeed.tech/topics/standard.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [bug](<https://devfeed.tech/topics/bug.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [YAML](<https://devfeed.tech/topics/yaml.md>)

Tags: [bug](<https://devfeed.tech/tags/bug.md>), [code](<https://devfeed.tech/tags/code.md>), [password](<https://devfeed.tech/tags/password.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [standard](<https://devfeed.tech/tags/standard.md>), [yaml](<https://devfeed.tech/tags/yaml.md>)

### AI overview

The author reflects on how the framing and subtitle of the Threats book shaped its content. The article discusses the value of shared engineering terminology and argues that common understandings, standards, and available tools can support more consistent threat assessment and evaluation of software flaws.

### Source excerpt

Reflecting on the framing of the Threats book

## Threats: The Table of Contents

DevFeed: [Threats: The Table of Contents](<https://devfeed.tech/articles/threats-the-table-of-contents-37062.md>)

Original publisher: [Read original article](<https://shostack.org/blog/threats-table-of-contents/>)

Author: Adam

Published: 2023-01-16T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [spoofing](<https://devfeed.tech/topics/spoofing.md>)

Tags: [books](<https://devfeed.tech/tags/books.md>), [contents](<https://devfeed.tech/tags/contents.md>), [guide](<https://devfeed.tech/tags/guide.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [table](<https://devfeed.tech/tags/table.md>)

### AI overview

The article presents the table of contents for Threats: What Every Engineer Should Learn From Star Wars. It explains that the book covers threats such as spoofing and authenticity, with each chapter organized around the threat, mechanisms, scenarios or technologies, and defenses. The book is announced as available for preorder and sale on January 25th.

### Source excerpt

Like the Force, each threat has a light side, and a dark side.

## GPT-3

DevFeed: [GPT-3](<https://devfeed.tech/articles/gpt-3-36812.md>)

Original publisher: [Read original article](<https://shostack.org/blog/gpt-3-threat-modeling/>)

Author: Adam

Published: 2022-12-09T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [Library](<https://devfeed.tech/topics/library.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Back end](<https://devfeed.tech/topics/backend.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [backend](<https://devfeed.tech/tags/backend.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [client](<https://devfeed.tech/tags/client.md>), [gpt](<https://devfeed.tech/tags/gpt.md>), [gpt-3](<https://devfeed.tech/tags/gpt-3.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [libraries](<https://devfeed.tech/tags/libraries.md>), [library](<https://devfeed.tech/tags/library.md>), [service](<https://devfeed.tech/tags/service.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>)

### AI overview

The article reports that GPT-3 was used to generate sample STRIDE threat libraries for backend-to-backend services in Kubernetes and client-side threats. It notes that the output may be imperfect and requires human judgment.

### Source excerpt

Text captured from GPT-3

## The Threats book is complete

DevFeed: [The Threats book is complete](<https://devfeed.tech/articles/the-threats-book-is-complete-37057.md>)

Original publisher: [Read original article](<https://shostack.org/blog/threats-announce/>)

Author: Adam

Published: 2022-12-08T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Parsing](<https://devfeed.tech/topics/parsing.md>), [Computing](<https://devfeed.tech/topics/computing.md>)

Tags: [book](<https://devfeed.tech/tags/book.md>), [complete](<https://devfeed.tech/tags/complete.md>), [parsing](<https://devfeed.tech/tags/parsing.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [security](<https://devfeed.tech/tags/security.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>)

### AI overview

The author announces that the Threats book is complete and describes its goal of making security and threat concepts accessible to engineers who are not security specialists. The article discusses topics including privilege, permissions, safe parsing, and STRIDE-related spoofing examples.

### Source excerpt

Threats is almost in bookstores

## Update on DoS Attacks against our Online Game

DevFeed: [Update on DoS Attacks against our Online Game](<https://devfeed.tech/articles/update-on-dos-attacks-against-our-online-game-30814.md>)

Original publisher: [Read original article](<https://hookrace.net/blog/dos-attacks-update/>)

Published: 2022-05-15T22:00:00Z

Content type: article

Language: en

Sources: [Dennis Felsing](<https://devfeed.tech/sources/dennis-felsing.md>)

Topics: [spoofing](<https://devfeed.tech/topics/spoofing.md>), [servers](<https://devfeed.tech/topics/servers.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [client](<https://devfeed.tech/topics/client.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [https](<https://devfeed.tech/tags/https.md>), [ipv4](<https://devfeed.tech/tags/ipv4.md>), [ipv6](<https://devfeed.tech/tags/ipv6.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [server](<https://devfeed.tech/tags/server.md>), [servers](<https://devfeed.tech/tags/servers.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [udp](<https://devfeed.tech/tags/udp.md>)

### AI overview

This update describes ongoing DoS attacks against the open-source DDraceNetwork online game. It explains how spoofed UDP connection attempts overload single-threaded game servers and outlines an HTTPS-based IP whitelist, along with limitations involving capacity, IPv4, IPv6, and ISP address translation.

### Source excerpt

In my previous post 8 months ago I described how our open source online game DDraceNetwork has been suffering under DoS attacks for about 8 years, basically since its inception. Recently the attacks have gotten much worse, forcing us to work on further approaches. Since many players made suggestions recently, I'm writing this blog post to summarize what we are attempting and to ask for help again. These traffic graphs are from two of the servers we are running, note the logarithmic x-axis. Each spike represents an incoming DoS attack, as you can see some of them last for nearly a day. Recently the attacks have been relatively weak in terms of incoming bandwidth, using spoofed IP addresses imitating our UDP-based connection process. At first the CPU gets overloaded since the server suddenly has to try and handle hundreds of thousands of connection attempts per second. Since our game servers are mostly running on cheap VPSes and each game server runs single-threaded, it is quite easy to overload a system in this manner. HTTPS-based Whitelist To prevent spoofing we collect all players' IP addresses and whitelist those. Since we also develop the game client, we can modify the client to connect to a server via HTTPs for this whitelisting. The iptables rules and ipset setup on the game servers for this whitelist look something like this: ipset create official iphash ipset create whitelist-ip iphash iptables -N serverinfo iptables -A serverinfo -m hashlimit --hashlimit-above 40/s --hashlimit-mode dstport --hashlimit-name si_dstport -j DROP iptables -N game iptables -A game -m set --match-set official src -j ACCEPT iptables -A game -m set --match-set whitelist-ip src -m u32 --u32 "38=0x67696533" -j serverinfo iptables -A game -m set --match-set whitelist-ip src -m u32 --u32 "38=0x66737464" -j serverinfo iptables -A game -m set --match-set whitelist-ip src -j ACCEPT # Still allow non-whitelisted players when there is no attack iptables -A game -m limit --limit 10000 -j ACCEP

[Next page](<https://devfeed.tech/topics/spoofing.md?cursor=WyIyMDIyLTA1LTE1VDIyOjAwOjAwKzAwOjAwIiwgIjVjZWY1MmE5LWFhZjktNDdlYy04NjczLTExZjQ1ZmE1ODUxNyJd>)