Mohamad Fadli Zolkipli
School of Computing, Universiti Utara Malaysia

Published : 2 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 2 Documents
Search
Journal : journal of applied computer and information technology

Beyond the human firewall: A systematic analysis of deepfake-mediated social engineering and the erosion of traditional security awareness Mohd Ruhaifi Zainol; Marhakim Mokhtar; Mohamad Fadli Zolkipli
Journal of Applied Computer and Information Technology Vol. 1 No. 2 (2026): Journal of Applied Computer and Information Technology (JACoIT)
Publisher : Global Research Innovation

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.67131/jacoit.v1i2.25

Abstract

The proliferation of generative artificial intelligence has transformed the cyber threat landscape, particularly in the domain of social engineering. Deepfake technology, encompassing synthetic audio and video generation, has emerged as a vector for advanced phishing campaigns that can bypass conventional controls, exposing limitations of traditional Security Awareness Training (SAT) when confronted with AI-driven deception. This paper presents a systematic analysis of empirical evidence on deepfake-enabled social engineering and its implications for existing security-awareness frameworks, drawing on 56 primary studies involving 86,155 participants, supplemented by 47 documented corporate incidents and a review of current technical detection methods. Pooled human detection accuracy for deepfake content was 55.54% (95% CI [52.3%, 58.8%]), only marginally above chance; the pooled estimate is, however, accompanied by substantial heterogeneity (I² = 78.4%) and should be interpreted as an average performance rather than a uniform inability to discriminate. Traditional SAT was associated with a non-significant +1.6% improvement in deepfake detection, whereas SAT incorporating synthetic-media examples produced significant gains of +8.1% to +15.5%. The study identifies three persistent limitations in current awareness training: the absence of deepfake-specific detection heuristics, inadequate calibration of trust in response to synthetic authority cues, and insufficient inoculation against cognitive-load manipulation; a 21.1-percentage-point laboratory-to-field performance gap was also observed. The paper proposes a resilience-oriented training framework that integrates technical literacy, psychological preparedness, and organisational verification mechanisms. Rather than declaring the “human firewall” obsolete, the analysis argues for its reconceptualisation as a complementary safeguard within layered, procedure-anchored defence.
Security challenges in serverless architectures: Vulnerabilities and penetration testing approaches for AWS Lambda and Google Cloud Functions Norsyazwani Mohd Puad; Paiwand Hadi Hama Saeed; Braw Araz Mohammed; Mohamad Fadli Zolkipli
Journal of Applied Computer and Information Technology Vol. 1 No. 2 (2026): Journal of Applied Computer and Information Technology (JACoIT)
Publisher : Global Research Innovation

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.67131/jacoit.v1i2.27

Abstract

This study examines the evolving security landscape of serverless computing, specifically focusing on AWS Lambda and Google Cloud Functions. While serverless architectures offer significant scalability and cost advantages, their event-driven nature introduces unique vulnerabilities that traditional infrastructure-based security measures often fail to address. To identify these risks, a multi-methodological approach was employed, involving systematic literature mapping, platform benchmarking, and threat modeling using the STRIDE framework. The research specifically analyzed the "blast radius" of compromised functions and the efficacy of current penetration testing methodologies. Results indicate that Identity and Access Management (IAM) misconfigurations are the primary driver of cloud breaches, accounting for 42% of critical vulnerabilities, while traditional network scanning yielded zero actionable detection data. Furthermore, simulation data revealed that unthrottled "Denial-of-Wallet" attacks can cause catastrophic financial loss within minutes. Based on these findings, a five-layer defense-in-depth framework is proposed, integrating secure secret management, automated dependency scanning, and identity-centric governance. The study concludes that securing serverless environments requires a paradigm shift from network-level protection to granular application logic validation and continuous observability. These measures are essential for maintaining data integrity in decentralized cloud-native environments.