
Our cyber security team has a stark warning this month – you can no longer trust a familiar voice. The next time you get a call from your CEO asking to reset a password or transfer funds, treat it with extreme caution. Vishing attacks are now supercharged by AI and more convincing than ever before. We have tips for how staff and systems can be better protected.
Does your business use Node.js or Python in its software? We’ve got advice from the NCSC about the security risks of open-source software and why third-party components should be treated as a major malware risk.
Apple customers will soon have their weak passwords upgraded by AI. But is that necessarily a good thing?
And finally, an urgent message from the government to every board member – make cyber resilience a priority today because enemy states are already at your door.
Attack of the voice clones
Our cyber security team is warning against the rise of vishing scams targeting specific job roles within an organisation. As we have previously covered, vishing is short for ‘voice phishing’. In this type of social engineering scam, hackers target their victims over the phone in order to steal information or money. Cyber criminals are increasingly using voice cloning tools powered by AI to impersonate the voices of senior staff to gain access to internal systems and data.
The arrival of highly sophisticated and freely available AI tools has made it extremely easy for criminals to clone voices. A few seconds of someone’s voice, either pulled from a Teams call recording, a video, a podcast, or even a LinkedIn clip, is all it takes to produce a convincing clone.
Our team has seen vishing attempts first hand. Recently, they received a voice message that sounded exactly like a senior colleague asking to reset a password and send a one-time access link back via WhatsApp. The use of unofficial channels like WhatsApp is deliberate. Hackers want to move the response off company systems so that there is no audit trail, IT visibility or safety net.
It’s why we now use security and identity verification tools to replace voice-based verification with secure MFA. This method removes the risk of deepfakes and voice impersonations by sending verification requests directly to a user’s pre-registered device.
Organisations are urged to stay alert and follow this advice:
- Beware of urgent-sounding messages: “I need this now”, “don’t go through the normal channels”, “just send it to my personal number” – these phrases are pressure tactics designed to make you act before you think.
- Don’t be afraid to question requests from senior staff: Senior figures are the most valuable targets because people are less likely to question them, which is exactly what attackers rely on.
- Do not action any request sent via voice message or WhatsApp, no matter how familiar the voice sounds.
- Check with the user on a confirmed business communication channel, i.e. Teams, Outlook, etc.
- Flag anything suspicious to the security team immediately – even if you’re not sure.
Says Intersys Cyber Security Analyst Aaron Davy, “As a rule of thumb, if you get an urgent-sounding call asking for access, just stop, verify and report. Your instincts are your best security tool. If something feels off, trust that feeling and verify before you act. It is never wrong to double-check.”
Is your open-source software an open door for criminals?
Modern open-source software ecosystems rely on dependencies such as external code, libraries and frameworks to build and reuse software at scale. Some of these components are less secure than others and prime targets for hosting malware.
The NCSC has urged organisations using open-source software to review their third-party dependencies for malware risks.
Node.js, Rust and Python have been highlighted as being particularly exposed, because of their increased use of third-party dependencies. The fact that these components are used during automated lifecycle development also means that malware introduced in one package can rapidly scale across many organisations before being discovered.
The Mini Shai-Hulud supply chain attack is one such example where hackers compromised many groups of related packages at once, to increase the scale and impact of the hack. Commonly used package registries such as NPM and PyPI were affected.
The NCSC has called for organisations to take the following steps to identify their exposure:
- Maintain an up-to-date inventory of all software dependencies
- Review all dependencies, including package updates, version changes and any newly introduced components
- Scan for unusual behaviour in CI/CD activity, credential use and network traffic
- Use dependency scanning tools for signs of compromised packages
- Check developer and registry accounts for unauthorised access
Apple has an AI remedy for weak passwords – but should you trust it?
An upcoming security feature in the soon-to-be-launched iOS 27 will automatically fix weak and compromised passwords for Apple customers.
The new AI feature will operate across the tech giant’s built-in Passwords app and Safari to automatically update eligible accounts to strong passwords.
For those worried about letting AI loose on their passwords, Apple has tried to reassure customers by emphasising that its AI systems are built on privacy-first architecture. While the company does rely on on-device processing and Private Cloud Compute to minimise exposure, concerns remain about the AI’s deep access to sensitive apps, online accounts and reliance on cloud servers.
Hostile states behind 75% of cyber attacks on UK critical infrastructure
Hostile nation states such as Russia, China and Iran were behind 75% of a total 200 cyber attacks on the UK’s critical national infrastructure in the last year alone. The NCSC, which managed the UK’s response, has warned that cyber security needs to be treated not just as a risk but as a permanent contest with formidable opponents.
The CEO of the NCSC, Dr Richard Horne, has called on “every board member and every executive, in every organisation” to bolster their cyber resilience by working on three main areas: understanding their threat exposure, building better defences based on standard security fundamentals and ensuring they can recover quickly after an attack.
Dr Horne highlighted the urgency of fixing security weaknesses. He said, “[…] the many vulnerabilities that organisations tolerate today will be exploited in conflict tomorrow. If they are too expensive or hard to fix in peacetime, then they certainly will be in war […] In cyberspace, we are not preparing for tomorrow’s conflicts, to some degree we are fighting them today.”
Other vulnerabilities and updates
Chrome V8 Zero-Day CVE-2026 – 11645
Ubiquiti UniFi OS Improper Access Control Vulnerability
Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability