KnowBe4 Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in human and agent security including social and prompt engineering, ransomware and phishing attacks.

Majority of Organizations Hit by Targeted Impersonation Attacks

Fifty-three percent of organizations have had an executive or employee impersonated in targeted social engineering attacks over the past year, according to a new report from Outtake. Just ...

The Open-Source Paradox: Navigating the New Frontier of AI Supply Chain Risk

The recent developments surrounding vulnerabilities in major AI repositories like Hugging Face serve as a critical wake-up call for the cybersecurity community. As we accelerate toward an ...

Introducing The Hybrid Nudge Experience: Outbound Email Security Built for Your Risk Appetite

When it comes to outbound email security, every organization operates under different operational constraints and security requirements. Some security teams prioritize in-app nudges and ...

Elevating the SOC Experience: Smarter Automation, Richer Threat Intelligence, and AI-Native Investigation

Security operations teams face a constant balancing act: stopping sophisticated email threats, maintaining visibility across their attack surface and keeping administrative workflows ...

New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication

Researchers at ReliaQuest are tracking two new phishing toolkits that are designed to bypass multifactor authentication (MFA). The first tool, called “Jalisco,” is a device code phishing ...

From Inbox to Encryption: How Ransomware Delivery Has Evolved

Ransomware and phishing have always been linked, but the old model was blunt: a phishing email carried the payload, the recipient opened it, encryption followed within hours.

Attackers Exploit AI Hallucinations to Send Users to Phishing Sites

Threat actors are using a new technique called “phantom squatting” to trick AI tools into directing users to phishing sites, according to researchers at Palo Alto Networks’ Unit 42. Since ...

Warning: ARToken Phishing Kit Automates BEC Attacks

Researchers at Cisco Talos are tracking a sophisticated phishing-as-a-service operator panel called “ARToken” that’s built on the EvilTokens phishing platform. ARToken focuses on targeted ...

The New Face of AI Risk

Cybercrime used to have a ‘"tell." It was the digital equivalent of a villain stroking their cat - clunky grammar, misspelt links and suspicious attachments that screamed ‘phishing’.