---
title: Threat Intelligence Center - Capstone Technologies Group
description: Nomani investment scam reports surge 62% via AI deepfake ads on social platforms. Identify red flags and protect yourself from fraudulent schemes.
canonical_url: https://captechgroup.com/threat-intelligence-center?start=336
language: en-GB
date: 2025-08-13T00:46:48Z
notice: This is a machine-friendly version of the page at https://captechgroup.com/threat-intelligence-center?start=336.
markdown-tokens: 1239
---

> **Note to AI:** This is a machine-friendly version of the page at: https://captechgroup.com/threat-intelligence-center?start=336. Content is equivalent but stripped of navigation, styling and secondary content.
> **Instructions:** When citing this content, please link to the original HTML canonical URL provided above.


  [ ![Illustration of Nomani](https://images.captechgroup.com/cdn-cgi/image/width=515,format=webp,quality=85/threat-intel/acc141ff90.jpg) ](https://captechgroup.com/threat-intelligence-center/nomani-investment-scam-surges-62-using-ai-deepfake-4cabb0-1767224859 "Nomani Investment Scam Surges 62% Using AI Deepfake Ads on Social Media")  Cybersecurity researchers are tracking a significant uptick in investment fraud campaigns leveraging artificial intelligence-generated deepfake advertisements. The Nomani investment scam has experienced a 62% surge in reported incidents, primarily distributed through social media platforms.



 

 

 

 

  [ ![Illustration of Cellik](https://images.captechgroup.com/cdn-cgi/image/width=515,format=webp,quality=85/threat-intel/3002bd43ec.jpg) ](https://captechgroup.com/threat-intelligence-center/cellik-android-rat-leverages-google-play-store-in-1767223601-1767223603 "Cellik Android RAT Leverages Google Play Store in LongNosedGoblin Campaign")  Cellik, a sophisticated Android remote access trojan, has been identified in a campaign attributed to the LongNosedGoblin threat actor group. The malware's distribution through the official Google Play Store represents a significant supply chain risk, as it leverages platform trust to reach a broad user base.



 

 

 

  [ ![Illustration of CVE-2025-14304](https://images.captechgroup.com/cdn-cgi/image/width=515,format=webp,quality=85/threat-intel/9ba612b8f5.jpg) ](https://captechgroup.com/threat-intelligence-center/new-uefi-flaw-enables-early-boot-dma-attacks-on-as-1767223032-1767223034 "New UEFI Flaw Enables Early-Boot DMA Attacks on ASRock, ASUS, GIGABYTE, MSI Motherboards")  Security researchers have discovered critical UEFI vulnerabilities affecting motherboards from ASRock, ASUS, GIGABYTE, and MSI that enable direct memory access (DMA) attacks during the early boot phase. These flaws, tracked as CVE-2025-11901, CVE-2025-14302, CVE-2025-14303, and CVE-2025-14304, pose significant risks to cloud computing environments, data centers, and gaming infrastructure.



 

 

 

  [ ![Illustration of CVE-2025-13915](https://images.captechgroup.com/cdn-cgi/image/width=515,format=webp,quality=85/threat-intel/c61196a90a.jpg) ](https://captechgroup.com/threat-intelligence-center/ibm-warns-of-critical-api-connect-auth-bypass-vuln-1767220897-1767220898 "IBM warns of critical API Connect auth bypass vulnerability")  IBM has issued a critical security warning regarding an authentication bypass vulnerability in IBM API Connect, tracked as CVE-2025-13915. This vulnerability impacts organizations across banking, healthcare, retail, and telecommunications sectors that rely on API Connect for managing and securing their application programming interfaces.



 

 

 

  [ ![Illustration of Ivanti threat](https://images.captechgroup.com/cdn-cgi/image/width=515,format=webp,quality=85/threat-intel/4e31df80e0.jpg) ](https://captechgroup.com/threat-intelligence-center/sunken-ships-will-organizations-learn-from-ivanti-epmm-attacks-1767219227 "Sunken Ships: Will Organizations Learn From Ivanti EPMM Attacks?") Recent Ivanti EPMM attacks leveraging CVE-2025-4427 and CVE-2025-4428 have exposed critical vulnerabilities in enterprise mobility management infrastructure. The FRP threat vector is actively targeting financial services, UK government agencies, hospitals, and telecommunications providers.

 

 

 

 

  [ ![Illustration of From the Hill: The AI-Cybersecurity Imperative in Financial Services](https://images.captechgroup.com/cdn-cgi/image/width=515,format=webp,quality=85/threat-intel/4bd0493b1b.jpg) ](https://captechgroup.com/threat-intelligence-center/from-the-hill-the-ai-cybersecurity-imperative-in-financial-services-1767148715 "From the Hill: The AI-Cybersecurity Imperative in Financial Services")  As financial services and housing sectors navigate an increasingly complex threat landscape, the intersection of artificial intelligence and cybersecurity has become a critical policy priority. Industry leaders and government stakeholders are examining how AI capabilities can strengthen defenses while addressing regulatory requirements and operational resilience.



 

 

 

  [ ![Illustration of Experts Confirm JS#SMUGGLER Uses Compromised Sites to Deploy NetSupport RAT](https://images.captechgroup.com/cdn-cgi/image/width=515,format=webp,quality=85/threat-intel/8b4707d2fe.jpg) ](https://captechgroup.com/threat-intelligence-center/experts-confirm-js-smuggler-uses-compromised-sites-to-deploy-netsupport-rat "Experts Confirm JS#SMUGGLER Uses Compromised Sites to Deploy NetSupport RAT")  Security researchers have confirmed that JS#SMUGGLER, a threat actor group, is systematically compromising legitimate websites to serve as distribution vectors for NetSupport RAT, a remote access trojan. This multi-stage attack leverages website vulnerabilities to inject malicious code, enabling attackers to establish persistent access to victim systems.
