Philadelphia Live News

collapse
Home / Daily News Analysis / Think you can spot fake AI photos? They’re now a security risk

Think you can spot fake AI photos? They’re now a security risk

Jul 21, 2026  Twila Rosenbaum  7 views
Think you can spot fake AI photos? They’re now a security risk

Generative AI is advancing at a breakneck pace, making it increasingly difficult to distinguish real photographs from synthetic ones. Just a few months ago, common tells like extra fingers or garbled text were reliable giveaways. Today, AI image generators produce faces, landscapes, and even video footage that can fool casual observers and trained professionals alike. This rapid improvement isn't just a curiosity for entertainment — it has become a serious security risk, particularly for financial scams and identity fraud.

In December, a widely shared NPR quiz tested the ability to identify AI-generated video clips. Many participants, including seasoned journalists, found themselves surprisingly poor at telling fact from fiction. Shortly after, the BBC published a similar quiz focused on AI-generated faces. Even with recent reading on how to spot fake content, many people still struggled. The problem is that the clues keep changing: what worked six months ago — such as looking for unnatural skin textures or lighting inconsistencies — may no longer apply as models are retrained on ever-larger datasets.

This matters far beyond viral animal videos or amusing deepfake memes. Cybercriminals have weaponized deepfakes to impersonate loved ones in emergency scams, clone the voices of executives to authorize fraudulent transfers, and create fake social media profiles to trick victims into sharing sensitive information. In 2024 alone, reports of deepfake-related fraud rose by over 300% according to several cybersecurity firms. The Federal Trade Commission has issued warnings about AI-generated images being used in romance scams, investment schemes, and job offer fraud.

Unfortunately, automated deepfake detection tools are not yet reliable. Many of them return false positives or miss sophisticated fakes altogether. For example, one prominent detection tool failed to flag an AI-generated video of a public figure that was circulating on TikTok, despite the video having obvious visual artifacts. The current state of the art suggests that, at best, using a detection tool is akin to asking a friend with moderate knowledge for an opinion — it provides a second perspective, but the final judgment still rests with you.

What then can individuals do to protect themselves? Research indicates that even a small amount of training can dramatically improve detection accuracy. In one study, participants who received just one hour of exposure to real and fake images, along with expert tips, saw their accuracy jump from 40% to 80%. Key visual cues include unnatural facial symmetry, overly smooth skin, lighting that doesn't match the scene, and eyes that lack natural reflections. Background details such as inconsistent shadows or blurry edges can also be telltale signs. For video, look for jerky movements, odd lip-syncing, or audio that doesn't match the person's mannerisms.

Those tips, however, are not permanent. Just as the six-fingered hand giveaway became obsolete when models learned to generate accurate hands, new flaws will inevitably appear and then be corrected. This creates a cat-and-mouse game where awareness must be constantly updated. The key takeaway is to adopt a mindset of healthy skepticism — do not automatically trust any image or video, especially if it arrives unexpectedly or asks for money or personal information.

Beyond deepfakes: Other security concerns this week

While AI-generated content dominates headlines, several other security issues have emerged that demand attention.

Meta backs down on AI image training

Meta recently announced plans to roll out its AI image generation tool, Muse, more widely across Instagram. The tool would have allowed any user to generate images using the likenesses of others, effectively turning everyone's photos into training data without explicit consent. After a significant public backlash — including protests from privacy advocates and lawmakers — Meta withdrew the plan. This victory demonstrates that user resistance can force tech giants to reverse controversial moves. However, the underlying data practices remain a concern, as companies continue to train AI on user-uploaded content under ambiguous terms of service.

Critical Zoom vulnerability

Zoom has disclosed a critical vulnerability in its desktop application that could allow an attacker to take over a user's account. The flaw (CVE-2025-1234) affects all versions prior to the latest update. Applying the update is the only remedy, and users are urged to do so immediately. This serves as a reminder that even widely used collaboration tools can harbor serious security holes, and prompt patching is essential.

Shark robot vacuum spying vulnerability

A security researcher discovered that certain Shark robot vacuum models contain a weakness that enables an attacker in the same geographic region to access live video feeds, Wi-Fi credentials, and detailed maps of home layouts. The vulnerability stems from insufficient authentication in the device's cloud communication. While Shark has pushed a firmware update, the incident highlights the risks of internet-connected home devices. Security experts recommend placing all smart gadgets on a separate guest network to limit the potential blast radius of any compromise.

Data brokers: The silent threat

Data leaks are only part of the problem. Data brokers collect vast amounts of personal information from public records, purchase histories, social media activity, and more. They then sell this data to anyone willing to pay — including marketers, insurers, and even malicious actors. Opting out is possible but involves a cumbersome process of contacting each broker individually. Services like DeleteMe can help, but the ideal approach is to minimize the information you share online in the first place.

Tip of the week: Enable Microsoft Edge's scareware blocker

Scareware attacks use alarming pop-up warnings — often mimicking legitimate antivirus alerts — to trick users into paying for fake repairs or downloading malware. Microsoft Edge includes a built-in scareware blocker that proactively identifies and blocks these fraudulent websites. To enable it, navigate to Settings > Privacy, Search, and Services > Security. Scroll down to find the Scareware Blocker toggle and make sure it's turned on. This free feature is particularly valuable for less tech-savvy family members who may be more vulnerable to such tactics.

As AI continues to evolve, the line between reality and fabrication will blur further. The best defense is a combination of ongoing education, technical hygiene like keeping software updated, and a skeptical mindset. While no single solution offers complete protection, layering awareness, secure practices, and privacy tools provides a robust barrier against the growing wave of AI-enabled threats.


Source: PCWorld News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy