Security researchers have revealed two vulnerabilities in TP-Link’s Tapo C200 smart camera that could enable nearby network attackers to bypass administrator authentication or disrupt the device’s management service. Khoi Tran and Thai Do from OPSWAT Unit 515 discovered these vulnerabilities, tracked as CVE-2026-15315 and CVE-2026-15316, during the company’s Critical Infrastructure Cybersecurity Graduate Fellowship Program. TP-Link […]
The post TP-Link Tapo Camera Flaw Lets Attackers Gain Admin Access Without Password appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
A newly disclosed vulnerability in Parallels Desktop, tracked as CVE-2026-90894 and dubbed “ParaShells,” can allow any local user on a Mac to gain root privileges on the host system. ParaShells PoC in action (Source: JFrog) The danger is highest on developer laptops, where a single poisoned Homebrew formula or malicious npm preinstall script can go from local user to full control, and on shared university and corporate machines that have many local accounts, JFrog vulnerability … More
The post Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894) appeared first on Help Net Security.
Threat actors sent more than one million AI-assisted invoice fraud emails in a large business email compromise (BEC) campaign targeting enterprise users.
The operation, detected by Microsoft between August 3 and 5, impersonated executives and trusted brands to pressure finance teams into making fraudulent Automated Clearing House (ACH) payments of nearly $50,000.
The campaign primarily targeted organizations in the United States, which received 87.7% of all messages. IT services, business advisory firms, consumer-goods companies, and other enterprises were among the targeted sectors.
Unlike standard invoice scams, the attackers combined several social-engineering techniques in one email.
They impersonated CEOs, CFOs, and presidents of the victim organizations, using executive names in sender display names, Reply-To fields, and email signatures.
The messages included a short approval notice directing accounts payable employees to process an invoice.
To make the request appear legitimate, the attackers added a fabricated ServiceNow annual-subscription invoice and fake forwarded email conversations.
Microsoft stated that ServiceNow and the other organizations named in the campaign were not compromised or involved.
The attackers used fraudulent domains, fake invoices, and impersonated identities to create a believable payment narrative.
The fraudulent invoice used ServiceNow branding, logos, itemized charges, invoice dates, payment details, and a bank-transfer instruction.
The “BILLED TO” section was personalized with the targeted organization’s name and executive details, increasing the likelihood that recipients would trust the payment request.

Attackers also embedded a fake email thread between the victim company’s executive and a supposed ServiceNow president.
These messages discussed a software purchase, implementation, and invoice handling. However, defenders could spot several warning signs.
The forwarded messages lacked normal email headers and visual grouping usually found in genuine threads. Some text contained unusual phrases, such as “no need to copy me.”
In other cases, display names did not match the sender addresses, while subject lines used suspicious financial terms including “due bill” and “ACH payment.”
Before the campaign began, the threat actor registered multiple domains. One, service-nowinc[.]com, was registered on July 31 and impersonated ServiceNow.

It appeared in the fake ServiceNow executive’s email address and within the fabricated invoice. Another domain, domainlify[.]net, was used in Reply-To addresses.
Microsoft identified several signs consistent with generative AI-assisted template development.
These included unusually detailed HTML comments, excessive section labels, uniform formatting, capitalized headers, banner-style separators, and repeated use of em dashes.
These clues do not prove that AI created every message, but they suggest attackers may have used AI to build reusable templates and quickly personalize lures for many organizations.
Indicators of Compromise (IOCs)
| Indicator | Type | Description |
|---|---|---|
service-nowinc[.]com | Domain | Lookalike domain impersonating ServiceNow; used in fake executive communications and fraudulent invoice content |
gomez@service-nowinc[.]com | Email address | Impersonated ServiceNow-related email address associated with attacker-controlled bank-payment activity |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Detect 58% more threats with fresh intelligence from 16K+ organizations. Integrate TI Feeds in you SOC
The post Hackers Send 1 Million AI-Assisted CEO Impersonation Emails in Invoice Fraud Campaign appeared first on Cyber Security News.