Connect with us

Tech Features

Making Sense of Identity Threat Risks

Published

on

phishing

By David Warburton, Director, F5 Labs

The growing maturity of cloud computing, including shifts towards decentralized architectures and APIs, has highlighted the complexity of managing credentials in increasingly interconnected systems. It has also underlined the importance of managing non-human entities like servers, cloud workloads, third-party services, and mobile devices.

F5 Labs’ 2023 Identity Theft Report defines identity as an artifact that an entity uses to identify itself to a digital system – such as a workload, a computer, or an organization. Examples of digital identities include username/password pairs and other personally identifiable information or cryptographic artifacts such as digital certificates.

Digital identities cannot stand on their own. They require a system to accept and validate them. In other words, for a digital identity to function there must be at least two parties involved: an entity and an identity provider (IdP) that are responsible for issuing and vetting digital identities. However, not all organizations that provide resources are IdPs—many digital services rely on third-party IdPs such as Google, Facebook, Microsoft, or Apple to vet identities.

Based on our recent analysis, the three most prominent forms of attack in the identity threat arena currently are credential stuffing, phishing, and multi-factor authentication (MFA) bypass.

Credential stuffing

Credential stuffing is an attack on digital identity in which attackers use stolen username/password combinations from one identity provider to attempt to authenticate to other identity providers for malicious purposes, such as fraud.

It is a numbers game that hinges on the fact that people reuse passwords,
but the likelihood that any single publicly compromised password will work on another single web property is still small. Making credential stuffing profitable is all about maximizing the number of attempts, which requires automation.

Phishing

Phishing is perhaps rivaled only by denial of service (DoS) attacks in being fundamentally different from other kinds of attacks. It is an attack on digital identity, to be sure, but since it usually relies on a social engineering foothold, it is even more difficult to detect or prevent than credential stuffing.

Phishing attacks have two targets: there is the end user who is in possession of a digital identity, and there is the IdP, which the attacker will abuse once they’ve gotten credentials. Depending on the motives of the attacker and the nature of the system and the data it stores, the impact of a successful phishing trip can land primarily on the user (as in the case of bank fraud), solely on the organization (as in the case of compromised employee credentials), or somewhere in the middle.

On the attacker side, phishing can range from simple, hands-off solutions for unskilled actors to custom-built frameworks including infrastructure, hosting, and code. The most hands-off setup is the Phishing-as-a-service (PhaaS) approach in which the threat actor pays to gain access to a management panel containing the stolen credentials they want, and the rest is taken care of by the “vendor.”

Dark web research indicates that the most popular subtype of phishing service is best described as phishing infrastructure development, in which aspiring attackers buy phishing platforms, infrastructure, detection evasion tools, and viable target lists, but run them on their own.

Brokering phishing traffic, or pharming, is the practice of developing infrastructure and lures for the purposes of driving phishing traffic, and then selling that traffic to other threat actors who can capitalize on the reuse of credentials and collect credentials for other purposes.

Finally, the attacker community has a niche for those who exclusively rent out hosting services for phishing.

The most important tactical development in phishing is undoubtedly the rise of reverse proxy/ man-in-the-middle phishing tools (sometimes known as real-time phishing proxies or RTPPs), the best known of which are Evilginx and Modlishka.  This is largely because it grants attackers the ability to capture most multi-factor authentication codes and replay them immediately to the target site facilitating MFA bypass but also making it less likely that the user victim will detect anything is amiss.

Multi-factor authentication (MFA) bypass

Recent years have seen attackers adopt a handful of different approaches to bypassing multi-factor authentication. The differences between these approaches are largely driven by what attackers are trying to accomplish and who they are attacking.

Nowadays, the reverse proxy approach has become the new standard for phishing technology, largely because of its ability to defeat most types of MFA.

MFA bypass tactics include:

  • Malware. In mid-2022, F5 malware researchers published an analysis of a new strain of Android malware named MaliBot. While it primarily targeted online banking customers in Spain and Italy when it was first discovered, it had a wide range of capabilities, including the ability to create overlays for web pages to harvest credentials, collect codes from Google’s Authenticator app, capture other MFA codes including SMS single-use codes, and steal cookies.
  • Social engineering. There are several variations of social engineering for bypassing MFA. Some target the owner of the identity, and some target telecommunications companies to take control of phone accounts.
  • Social Engineering for MFA Code—Automated. These are attacks in which attackers make use of “robocallers” to make phone calls to the target, emulating an identity provider and asking the victim for an MFA code or one-time password (OTP).
  • Social engineering for MFA code—Human. This is the same as the above approach except that the phone calls come from humans and not an automated system.
  • SIM swaps. In this kind of attack, a threat actor obtains a SIM card for a mobile account that they want to compromise, allowing them to assume control of the victim’s phone number, allowing them to collect OTPs sent over SMS. There are several variations of this approach.

So, what does it all mean?

Identity threats are constant and continuous. Whereas a vulnerability represents unexpected and undesirable functionality, attacks on identity represent systems working exactly as designed. They are therefore “unpatchable” not only because we can’t shut users out, but because there isn’t anything technically broken.

This brings us back to the question of what digital identity really is. To go from real, human identity to digital identity, some abstraction is inevitable (by which we mean that none of us is reducible to our username-password pairs). We often teach about this abstraction in security by breaking it down to “something we know, something we have, and something we are.” It is this abstraction between the entity and the digital identity that attackers are exploiting, and this is the fundamental basis of identity risk.

By thinking about digital identities in this way, what we are really saying is that they are
a strategic threat on par with, but fundamentally different from, vulnerability management. With nothing to patch, each malicious request needs to be dealt with individually, as it were. If modern vulnerability management is all about prioritization, modern identity risk management is essentially all about the ability to detect bots and differentiate them from real human users. The next logical step is quantifying the error rate of detecting these attacker-controlled bots. This is the basis on which we can begin to manage the risk of
the “unpatchables.”

Tech Features

WHY LEADERSHIP MUST EVOLVE TO THRIVE IN AN AI DRIVEN WORLD

Published

on

Person wearing a dark blue formal suit with a white shirt, standing indoors with arms crossed. The background features two framed paintings on a light-colored wall.

By Sanjay Raghunath, Chairman and Managing Director of Centena Group

Leadership today is being reshaped not by technology alone, but by the pace at which the world around us is changing. Conventional leadership models built on rigid hierarchies, authority, and control are no longer sufficient in an era defined by artificial intelligence, automation, and constant disruption. What organisations need now is a more human-centric model, adaptive, and grounded form of leadership.

As digital transformation accelerates, the role of a leader has fundamentally shifted from imposing authority. Leadership is no longer about issuing directions from the top; it is about guiding organisations and people through uncertainty with clarity and confidence. In an AI-driven world, effectiveness does not come from being the most technical person in the room, but from understanding how technology reshapes industries and how to integrate it responsibly to create long-term value.

The economic impact of AI is already undeniable. Reports suggest that AI could contribute up to USD 320 billion to the Middle East’s GDP by 2030, with the UAE alone expected to see an impact of nearly 14 per cent of GDPby that time. Globally,PwC estimates that AI adoption could increase global GDP by up to 15 per cent by 2035. These numbers signal more than opportunity, they signal inevitability. Leaders who cling to static models and resist change risk being overtaken as industries evolve around them.

One of the most persistent challenges in leadership today is resistance to change. When leaders rely on outdated hierarchies and familiar ways of working, organisations struggle to respond to volatility. What worked yesterday may no longer work tomorrow. Flexibility, once considered a desirable trait, has become a necessity for survival. Ignoring change is no longer an option.

At the same time, expectations of our colleagues have shifted significantly. People today seek more than compensation or career progression. They are looking for purpose, belonging, and leaders who communicate with transparency rather than authority. This shift is reinforced by the 2025 Employee Experience Trends Report, which draws on feedback from 169,000 employees. The findings show that belonging and purpose are now among the strongest drivers of engagement, while AI-related anxiety and change fatigue are growing concerns within the workforce.

These factors highlight the role of authentic human connection in leadership. One of the critical elements in this regard is emotional intelligence (EQ), which enables leaders to build trust, inspire confidence and form meaningful relationships with their teams. While data, analytics, and AI can inform better decisions, it is empathy that sustains relationships and credibility. Leaders who lack emotional awareness often appear distant, making trust difficult to establish and sustain.

In an era of advanced technologies such as AI, automation and chatbots, there is a prevailing fear about technology overtaking the human role. It is the leadership’s responsibility to instil confidence in people that technologies are designed to enhance human capability, not to diminish it. Technology must be positioned as an enabler. Even though the pace of this transformation can be exhausting, leaders must navigate this challenge with renewed energy and a clear strategy to guide their organisations.

Today, leadership that is adaptable, collaborative, and emotionally aware is proving far more effective than traditional command-and-control models. The transition is from exercising authority to creating genuine connections. Strong leaders integrate change into their strategies while keeping people at the centre of their organisations, while viewing technological innovations as a partner rather than a threat.

Investing in people is not optional, as roles continue to evolve and skill requirements change.  Our colleagues must feel valued and supported, as recognition and empathy contribute to boosting engagement and innovation. Empathic leadership helps bridge the gap between market demands and individual needs. Listening with intent, understanding context and responding with genuine concern are no longer additional qualities, they are essential leadership competencies.

The future belongs to leaders who blend clear thinking with empathy, who remain grounded in the present while envisioning bold possibilities and driving innovation forward without eroding trust. In this AI-driven age, success depends on how leaders balance innovation with trust. Leadership is neither about resisting change nor surrendering to it entirely. It is the ability to guide people through uncertainty with emotional depth and stability, recognising that true authority is not earned through control, but through the strength of human connection.

Continue Reading

Cover Story

PLAUD Note Pro: This Tiny AI Recorder Might Be the Smartest Life Upgrade You Make!

Published

on

By Srijith KN

I’ve been using the Plaud Note Pro for over three months now, and this is a device that has quietly earned a permanent place in my daily life now. Let me walk you through what it does—and why I say that so?

Well at first I thought this wasn’t going to do much with my life, and by the looks of it Plaud Note Pro looks like a tiny, card-sized gadget—minimal, unobtrusive to carry it around.

With a single press of the top button, it starts recording meetings, classes, interviews, or discussions. Once you end your session, the audio is seamlessly transferred to the Plaud app on your phone, where it’s transformed into structured outputs—summaries, action lists, mind maps, and more.

In essence, it’s a capture device that takes care of one part of your work so you can concentrate on the bigger game.

Design-wise, the device feels premium, it features a small display that shows battery level, recording status, and transfer progress—just enough information without distraction. The ripple-textured finish looks elegant and feels solid, paired with a clean, responsive button. It also comes with a magnetic case that snaps securely onto the back of your phone, sitting flush and tight, making it easy to carry around without thinking twice.

Battery life is another standout. On a full charge, the Plaud Note Pro can last up to 60 days, even with frequent, long recording sessions. Charging anxiety simply doesn’t exist here.

Well, my impressions about the device changed once I had an audio captured. I tested this in a busy press conference setting—eight to ten journalists around me, multiple voices, ambient noise—and the recording came out sharp and clear. Thanks to its four-microphone array, it captures voices clearly from up to four to five meters away, isolating speech with precision and keeping voices naturally forward. This directly translates into cleaner transcripts. It supports 120 languages, and yes, I even tested transcription into Malayalam—it worked remarkably well, condensed the entire convo-interview that I had during an automotive racing show that I was into.

Real meetings or interviews are rarely happens in a neat environment, and that’s where I found the Plaud Note Pro working for me. It captures nuances and details I often miss in the moment. As a journalist, that’s invaluable. The app also allows you to add photos during recordings, enriching your notes with context and visuals.

I tested transferring files over 20 minutes long, and the process was smooth and quick. Accessing the recordings on my PC via the browser was equally intuitive—everything is easy to navigate and well laid out.

Now to what is inside this tiny recorder. Well, the core of the experience is Plaud Intelligence, the AI engine powering all Plaud note-takers. It dynamically routes tasks across OpenAI, Anthropic, and Google’s latest LLMs to deliver professional-grade results. With over 3,000 templates, AI Suggestions, and features like Ask Plaud, the system turns raw conversations into organized, searchable, and actionable insights. These capabilities are available across the Plaud App (iOS and Android) and Plaud Web.

Privacy is what I happen to see them look at seriously. All data is protected under strict compliance standards, including SOC 2, HIPAA, GDPR, and EN18031, ensuring enterprise-grade security.

What makes the AI experience truly effective is the quality of input. Unlike a phone recorder—where notifications, distractions, and inconsistent mic pickup interfere—the Plaud Note Pro does one job and does it exceptionally well. It records cleanly, consistently, and without interruption, delivering what is easily one of the smoothest recording and transcription experiences I’ve used so far.

I’m genuinely curious to see how Plaud evolves this product further. If this is where they are today, the next version should be very interesting indeed.



“The Plaud Note Pro isn’t just a recorder; it’s a pocket-sized thinking partner that captures the details so you can think bigger, clearer, and faster.”

Continue Reading

Tech Features

Localization is at the Core of Hisense’s Middle East Strategy!

Published

on


In conversation with Jason Ou, President, Hisense Middle East & Africa on regional R&D, AI-powered products, and next-generation home innovation.

Here in the interview, we take a look at the strategic role of its Dubai R&D Centre in localizing global innovation for Middle Eastern consumers, ensuring products are climate-ready, culturally relevant, and aligned with regional lifestyles.

We talk about how the company is embedding AI across TVs and home appliances to improve performance, energy efficiency, and ease of use, while reducing manual intervention.

Through Hisense we take a look at the advantages of Laser TV technology, and what Hisense is offering through its large-format, energy-efficient cinema experiences suited to our homes.

Can you start by telling us about the role of the Hisense R&D Centre in Dubai within the company’s broader innovation ecosystem?

Our Dubai R&D Centre is an essential part of how we localise global Hisense technology for the Middle East. It allows us to test products under real regional conditions, understand consumer behaviour more accurately, and adapt features or performance where needed.

The centre also helps us coordinate closely with local partners, retailers, and government entities. This ensures our innovations are not only technically strong, but also aligned with local lifestyle needs, climate demands, and regulatory standards. It strengthens the link between our international R&D network and what consumers expect from the brand here.

  • Can you share examples of product tweaks or innovations that originated from local feedback? How does the R&D team ensure Hisense products meet the expectations of increasingly tech-savvy and connected households in the region?

We’ve made several practical product adjustments based on insights gathered in this market.  For example, we enhanced compressor durability and airflow design to handle prolonged periods of extreme heat, dust, and humidity. We also refined our filtration systems to better suit environments where air quality can vary throughout the year. Another important highlight is our anti-mould functionality, developed specifically for this region. During the summer months, higher levels of humidity can lead to mould formation within AC units, so we engineered a cycle that keeps internal components dry and prevents mould from growing, ensuring cleaner air and improved long-term performance. Additionally, we’ve optimised cooling performance to ensure faster temperature recovery, which is a key priority for consumers in this climate.

From a smart technology perspective, we have incorporated features such as AI-enabled energy optimisation, advanced Wi-Fi controls, and more intuitive mobile app interfaces. These include smart notifications and automated modes that help users maintain healthier indoor air quality, especially during periods of high humidity. These updates came from feedback that users want greater visibility and control over energy consumption, remote access, and seamless integration with smart home systems.

To stay connected with highly tech-savvy consumers, we run continuous testing cycles and user studies. We also gather retailer feedback and analyse usage data to understand how households interact with our products. This helps us shape updates and features that are relevant, intuitive, and reliable for the region.

  • How is Hisense embedding AI into its consumer products? Beyond convenience, what real benefits does AI bring to users?

We apply AI where it consistently delivers value. In TVs, AI enhances picture and audio quality by analysing content and room conditions in real time. In appliances, AI improves energy efficiency, adjusts performance based on usage patterns, and supports predictive maintenance, reducing the likelihood of breakdowns and improving overall product life. In our laundry category, AI plays an increasingly important role in recommending the ideal wash cycle based on fabric type, colour, and load size. It can even set the appropriate water temperature and spin speed, helping users to protect delicate garments while improving wash performance.

For users, the benefit is straightforward: better performance with less manual intervention. AI helps the product adapt to the user, rather than requiring the user to adapt to complex settings.

  • What differentiates Laser TV from traditional LED or OLED technology, both in performance and environmental impact?

Laser TVs offer a fundamentally different viewing experience and cannot be directly compared to traditional LED or OLED panels, as they each serve different purposes. The laser TV is designed to replicate a true cinema environment; it uses ultra-short throw laser technology which is better suited for large-format screens due to consistent colour accuracy, strong contrast, and reduced eye strain. It performs especially well at sizes above 100 inches, where conventional panels become less practical, heavier, and significantly more power-intensive.

From an environmental standpoint, the laser TV uses far less energy and production materials than similarly sized LED or OLED screens. This makes it a more sustainable choice for consumers who want a big-screen experience without the high power consumption of traditional panels.

At Hisense, we are pioneering this category globally, with a current positioning as the world’s number one laser TV brand. We endeavour to continue expanding the technology to bring the big-screen cinema experience into modern homes.

  • How is Hisense adapting its Laser TV lineup for Middle Eastern consumers, who often value both cinematic experience and design aesthetics?

Middle Eastern households are generally more accommodating of large, high-quality displays and interior design. While we have not developed a laser TV range exclusively for the Middle East, we are continuously enhancing our overall TV ecosystem in ways that benefit local users, particularly through our updated VIDAA operating system, which now includes more Arabic interfaces, regional apps, and local streaming platforms such as Shahid.

The region presents a strong opportunity for laser TV adoption, especially in large homes and villas where dedicated cinema rooms are becoming increasingly popular. The Hisense laser TV is ideal for this environment, offering an ultra-short throw set-up, immersive large-format viewing, and a cinema-style experience without the need for complex installation or heavy wall-mounted panels.

We continue to focus on features such as ALR (ambient light rejection) screens, enhanced sound performance, and clean, modern industrial design, all of which make laser TV a natural fit for households looking to elevate both their viewing habits and their interior spaces.

  • What are the next big innovation priorities for Hisense in the Middle East?

Across the world and in the MEA region, our goal is to innovate products that simplify everyday life. We are focused on advancing our AI chips, enhancing intelligent capabilities, and expanding ConnectLife to build a fully connected home ecosystem that is smarter, more intuitive, and increasingly predictive.

We are also strengthening our core product lineup with meaningful category breakthroughs. In our laundry segment, we recently launched PureView and X-Zone Master, two products that we believe represent a new standard in performance, design, and user-centric innovation. In the display category, we’ve introduced the 116-inch RGB Mini-LED, a landmark innovation that we expect will redefine what consumers can expect from large-screen entertainment.

From a regional standpoint, we continue to develop our air-conditioning solutions to withstand extreme heat, humidity, dust, and long operational hours , priorities that are especially important for the Middle East. For home appliances, we’re building features tailored to local lifestyles, such as the Abaya wash cycle in our washing machines, ensuring cultural relevance and ease of use for consumers in this market. These initiatives reflect the growing needs of our consumers in the region: reliability, connectivity, climate-ready performance, and elevated home entertainment experiences

Continue Reading

Trending

Copyright © 2023 | The Integrator