Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

New Phishing Kit Uses AI to Fully Automate Vishing Attacks

A new phishing kit is using generative AI to fully automate voice phishing (vishing) attacks, according to researchers at Group-IB. The phishing platform, called “Balonx,” includes a module dubbed “CallFlow” that the researchers say “represents a fundamental evolution” in the phishing-as-a-service market.

Shadow AI: What Clients Aren't Telling Their MSPs

MSPs are expected to understand their clients’ technology environments. They know which endpoints are managed, which applications are business-critical, which systems require patching or maintenance, where sensitive data resides and who has access to it. Increasingly, however, critical technology decisions are now being made without IT or MSP involvement. Across client environments, this can take many forms: And each instance can occur without the MSP ever knowing.

The Screenshot Looked Better-But One AI Edit Changed the Evidence

A security analyst prepares a phishing report for publication. The original screenshot is accurate but messy: a personal email address is visible, the browser contains unrelated tabs, and a notification blocks part of the page. The analyst uses an image editor to clean it up. The result looks professional. Unfortunately, one character in the suspicious domain has also changed. Tools such as Nano Banana can edit existing images and generate new ones, but security communication introduces a requirement ordinary visual content may not have: some pixels represent facts. Improving the image cannot be allowed to rewrite them.

Three Frameworks, Three Definitions of AI Risk

Cross-mapping tables for AI evidence in life sciences already exist and are broadly right. Data integrity practice lines up against data governance requirements, software lifecycle logs against technical documentation and logging, human review checks against human oversight duties, post-market surveillance against post-market monitoring. Build one repository, present it two ways. ‍ All of that is sound and it starts one step too late.

Defending against AI-fueled social engineering

Social engineering has always been the softest edge of enterprise defense, and AI is sharpening adversaries’ attacks. Phishing, business email compromise, and impersonation still dominate the initial-access playbook, but AI has stripped out the cost, time, and skill barriers that once forced attackers to choose between reach and precision.

DIFC Regulation 10: AI system certification requirements orgs need to know

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

CrowdStrike Falcon Guardian Defines the Next Generation of AI Security

AI has rapidly evolved into a technology that takes action. AI agents can reason, access enterprise systems, and execute tasks autonomously at machine speed, often with the full permissions of the users they serve. As these agents proliferate across the enterprise, organizations need to understand where they operate, what they do, what they can access, and how to stop threats before they become breaches. This shift demands a new approach to AI security.

Secure Data Sharing: Best Practices for Privacy and Compliance

Data sharing creates business value only when organizations can control where data goes, who can use it, and what happens after it leaves its original system. That becomes harder as businesses exchange customer records, financial information, healthcare data, and AI-ready datasets across employees, vendors, applications, and regions. The answer is not simply sending files through an encrypted channel.