KnowBe4 Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in human and agent security including social and prompt engineering, ransomware and phishing attacks.

AI Agent Governance Part 2 - What Good Looks Like: Governing AI Agents in Practice

If AI agents are becoming organizational actors, then governance needs to move beyond principles and into operational structure. In Camille Stewart Gloster’s upcoming book The Insider You ...

8 Ways to Reduce False Positives in Email Security

False positives can disrupt inbound email security as much as missed threats by slowing business workflows and eroding trust in security controls.

Ransomware Attacks Drive a Surge in Cyber Insurance Claims

Cyber insurance claims surged by 40% over the past eighteen months, while ransomware payments have dropped by 44%, according to a new report from Cowbell Cyber. The three most common ...

My Favorite 5 KnowBe4 Agents

With over 10 years of experience in implementing AI, KnowBe4 has a ton of agents on its platform which customers can use to significantly lower risk. They help to secure the digital ...

Perry Carpenter KB4-CON 2026 Q&A: Deepfakes & Deception

In just a couple years, deepfakes have gone from cartoonishly silly and largely academic exercises to sophisticated audio and video creations with the potential to trick just about anyone ...

Free Gift Fallacy: How Attackers Harvest Credit Cards via Fake Surveys

Lead Analysts: Jeewan Singh Jalal, Dilsha Dines, Karthikeyan Dharmaraj

When Global Conflict Becomes a Cyber Weapon: How Iran Tensions and Other Stressful Events Fuel Social Engineering Attacks

When geopolitical tensions rise, whether due to conflicts like the current one involving Iran or other global flashpoints, many organizations focus on physical security, supply chains, or ...

Alert: Extortion Groups Are Using Phishing Kits to Automate Their Attacks

Researchers at Push Security have analyzed a phishing platform used by organized criminal threat actors like ShinyHunters and BlackFile, finding more than 400 domains linked to attacks ...

Beyond the Chatbot: Why Your AI Agents are Your Newest (and Most Vulnerable) Colleagues

The era of "typing into a box" is over. For years, we viewed artificial intelligence as a digital assistant—a sophisticated autocomplete tool that waited for human input. But according to ...

Report: Adversarial Use of AI is Evolving

Threat actors are increasingly augmenting their attacks with AI tools, according to researchers at Google’s Threat Intelligence Group (GTIG). For the first time, GTIG observed a threat ...

AI Agent Governance Part 1 - Beyond the Chatbot: Mastering AI Agent Governance

In 2024, we talked to AI. In 2026, AI is talking to our systems, our customers, and increasingly, acting on our behalf. With AI agents, we are moving AI from a tool to an actor, from ...

Report: The Tycoon 2FA Phishing Kit Has Evolved

The Tycoon 2FA phishing-as-a-service platform is now using OAuth device code phishing to compromise devices that are protected by multifactor authentication, according to eSentire’s ...

KnowBe4 CEO Bryan Palma Q&A From KB4-CON 2026

By Bree Fowler, contributor Artificial intelligence is dramatically changing the digital threat landscape and how security professionals fight back against the cybercriminals that use ...

How Agentic AI and Automation Are Changing Cybersecurity

There is no question that AI is changing cybersecurity in a massive way. In many respects, its impact is comparable to the rise of the internet. AI tools are helping organizations improve ...

AI Alone Won’t Stop the Breach: Why Email Security Needs Humans-on-the-Loop

2026 has officially become the year of speed, scale and support. The delta between a phishing email landing and a full organizational compromise has shrunk to mere seconds.

[Heads Up] GitHub Breach Shows Developer Tools Are Social Engineering Targets

GitHub disclosed that attackers accessed its internal repositories after compromising an employee device through a poisoned Visual Studio Code extension. The company said the activity ...

Build Custom, High-Impact Training with KnowBe4’s Content Creation Agent

In the world of security awareness training, a comprehensive library of relevant and engaging content is a necessity. But even the best training can feel limited when you need to talk ...

Robinhood Glitch Allowed Attackers to Send Phishing Emails to Customers

A phishing campaign exploited a glitch in Robinhood’s account creation process to send phishing emails from the investment platform’s own systems, SecurityWeek reports.

Reducing Phish-Prone Rates Without Training Fatigue: A Practical Playbook for Traditional Organizations

Phishing remains the single biggest human-driven threat in most organizations. Yet many security leaders face a familiar problem: the stronger the push to run frequent training and ...