AI Security Daily Briefing — November 19, 2025

A concise, fact-based update for security and risk professionals covering the past 24 hours.


🔐 Core Security Intelligence

1) Deepfakes, hacked court systems and cloned voices: Ohio’s AI-crime surge

What’s new:
In Ohio, law-enforcement agencies report a sharp rise in AI-enabled crimes, including deepfake voice scams and disruption of municipal court systems. One county reported scammers using AI-cloned relatives’ voices to extort money, and one local court system was knocked offline for weeks.
Source: Deepfakes, hacked courts and cloned voices: Inside Ohio’s new AI crime wave

Why it matters:
These incidents illustrate how quickly AI tools are migrating into real-world crime, lowering the barrier for attackers and increasing scale. Local government and civic systems are becoming prime targets for adversaries exploiting voice cloning and deepfake technology.

Defenses:

  • Implement voice-biometric validation and multi-factor escalation. For critical systems such as courts or municipal services, require multi-factor checks before action based on voice or identity alone.
  • Audit public-sector infrastructure for known deepfake and clone-voice vectors. Train staff in recognizing AI-generated impersonation, phishing and scam tactics.
  • Deploy anomaly-detection on unusual access patterns. Monitor for large-scale automated voice-calls, impersonation attempts or unexpected service disruptions.

Expert Insight:
We have passed the point where deepfakes are only fringe threats, they are now integrated into everyday crime and infrastructure attacks. Public institutions must treat AI-enabled impersonation and disruption as a core risk, not a novelty.


2) Black Kite launches “AI Agent” to automate third-party risk management

What’s new:
Cyber-risk platform Black Kite announced a new AI-Agent product that automates vendor risk assessment, breach tracking, executive-report generation and vendor-score prioritization across third-party ecosystems.
Source: Black Kite launches AI Agent to automate third-party risk work

Why it matters:
Third-party risk remains one of the top network vulnerability vectors. Automating the assessment and monitoring of vendor ecosystems with AI tools shifts the defence from reactive to continuous, and raises the bar for vendors lacking mature security postures.

Defenses:

  • Integrate AI-assisted vendor risk tools into your procurement process. Set up first-look dashboards for vendor scores, breach histories and change-tracking via AI-Agent outputs.
  • Enforce remedial action thresholds. If a vendor’s risk score deteriorates, trigger contract review, temporary suspension or remediation support automatically.
  • Audit vendor usage of AI tools internally. Ensure that vendor AI-agents do not themselves introduce new supply-chain exposure or automated mis-use of your data.

Expert Insight:
Automating vendor risk is not just a convenience, it is a strategic necessity. As vendors themselves adopt AI, they become faster targets. Organisations that embed automated vendor-risk monitoring now will avoid cascading breaches via supplier ecosystems.


3) New “ShadowRay 2.0” exploit uses AI framework to attack AI infrastructure

What’s new:
Security researchers from Oligo discovered an active campaign exploiting a known vulnerability (CVE-2023-48022) in the Ray AI orchestration framework. The campaign (“ShadowRay 2.0”) uses AI-generated payloads to convert compromised compute clusters into a self-replicating botnet.
Source: New ShadowRay Exploit Targets Vulnerability in Ray AI Framework to Attack AI Systems

Why it matters:
This is a “double AI” threat: attackers use AI-generated tools to compromise AI infrastructure itself. As model hosting and compute orchestration grow, these frameworks become high-value targets and the attack surface expands outside typical IT stacks.

Defenses:

  • Patch vulnerable AI orchestration frameworks immediately. Confirm Ray deployments are updated, especially if used for inference or training at scale.
  • Segment AI compute clusters from general-purpose infrastructure. Apply network isolation and strict access controls on orchestration environments.
  • Deploy monitoring for botnet-type behaviour in AI environments. Watch for unusual compute usage, replication, or clusters acting like distributed attack nodes.

Expert Insight:
Infrastructure that hosts AI is no longer a passive platform—it can become an active battleground. When attackers treat model-orchestration platforms as targets, your compute fabric becomes weaponised. Defence must evolve accordingly.


🌐 Extended Risk & Governance

4) AI in cybersecurity industry to hit USD 154.8 billion by 2032

What’s new:
A market research forecast from Allied Analytics projects that the global AI-in-cybersecurity market will grow from USD 19.2 billion in 2022 to USD 154.8 billion by 2032, driven by automation, threat growth and cloud/IoT expansion.
Source: AI in cybersecurity market to hit $154.8 bn by 2032

Why it matters:
Massive investment and industry growth signals both opportunity and risk. As security vendors scale AI-tools, organisations must ensure those tools meet security requirements themselves. Market size alone doesn’t guarantee maturity or effectiveness.

Expert Insight:
Alongside opportunity comes risk: vendors will rush products to market, many with incomplete controls, weak telemetry or poor governance. Organisations should treat vendor-AI tools with the same scrutiny they apply to internal tools and demand transparency, auditability and model-risk controls.


⚠️ Updates / Follow-ups

No prior featured stories received verified, material updates in the last 24 hours.


Summary Table

Threat / TrendKey RiskDefence Highlights
AI-enabled impersonation & deepfakesPublic infrastructure and citizens targeted via voice and AI crimeMulti-factor validation; voice-scam monitoring; audit responses
Vendor-ecosystem AI automationFaster vendor risk and potential supply-chain exposureAutomate vendor risk monitoring; enforce risk thresholds
AI-infrastructure supply-chain exploitAI frameworks converted into botnet/infrastructure abusePatch orchestration frameworks; isolate AI compute stacks; monitor usage
AI-security market surgeVendor spin-up risk, rapid product churn, control gapsEvaluate vendor maturity; demand auditability; embed continuous governance


Categories: Cybersecurity News

Tags: , , , ,

Leave a Reply

Discover more from TECHMANIACS.com

Subscribe now to keep reading and get access to the full archive.

Continue reading