Threat Brief — 2026-09-28 — AI-driven exposure and fraud escalate
Executive summary: Two AI-related incidents headline today: a deepfake voice fraud netted €95 million from a bank via WhatsApp social engineering, and over 16,000 AI-generated applications were found with insecure databases exposing personal, messaging, and payment data. Separately, Canonical is shifting to weekly Ubuntu kernel releases, citing an avalanche of new CVEs accelerated by AI-driven vulnerability discovery. OpenAI is also preparing an always-on assistant called "o" that could handle email — a broad new attack surface if realised.
Top items
- AI deepfake voice fraud steals €95 million from a bank. A convincing fake voice impersonating a lawyer persuaded a senior executive to approve a series of international wire transfers via WhatsApp. This is one of the largest publicly reported deepfake-enabled financial frauds. The technique requires only voice samples and a plausible cover story, lowering the barrier for replication. (src: SecurityLab)
- 16,000+ AI-generated applications found with insecure databases. Access-control errors in AI-generated apps exposed services handling personal data, messages, and payment information. The scale suggests systematic insecure defaults in AI-assisted development pipelines rather than isolated misconfigurations. (src: SecurityLab)
- Canonical moving Ubuntu kernels to weekly releases. The company states it cannot keep up with the volume of new CVEs under the previous cadence, citing AI-accelerated vulnerability discovery and Linux's changed patch policy turning fixes into a continuous pipeline. Organisations relying on Ubuntu should expect a significantly faster kernel patch treadmill. (src: SecurityLab)
- OpenAI preparing always-on assistant "o" with potential email handling. References to the unannounced feature briefly appeared on OpenAI's website. An always-on assistant that reads and acts on email would represent a high-value target for prompt injection, credential theft, and data exfiltration. No release date or security architecture details are available yet. (src: BleepingComputer)
- FreeBSD now offers a ready-to-use cloud desktop accessible via RDP. The pre-configured image removes the need to manually install a graphical environment and configure remote access, but RDP exposure is a well-known attack surface. Organisations considering this should treat the RDP endpoint as internet-facing infrastructure requiring network-level restrictions. (src: SecurityLab)
Themes
AI as both weapon and vulnerability multiplier. Three of today's top items illustrate a converging pattern: AI accelerates vulnerability discovery (straining kernel patch cycles), AI-generated code ships with systemic security flaws (16,000 exposed databases), and AI-generated content enables large-scale social engineering (€95M deepfake fraud). The technology is simultaneously expanding the attack surface on the development side and providing new tools for adversaries on the operational side.
Autonomous AI assistants widening trust boundaries. OpenAI's planned always-on email assistant follows a pattern seen across the industry — AI agents gaining persistent access to sensitive communication channels. Each new agent integration expands the surface for prompt-injection and indirect-instruction attacks.
