CyberheistNews Vol 16 #30 | July 28th, 2026
[Protect Your Users] AI Hallucinations Are Fueling Phishing Attacks
Threat actors are using a new technique called "phantom squatting" to trick AI tools into directing users to phishing sites, according to researchers at Palo Alto Networks' Unit 42.
Since AI models frequently hallucinate phony information, they sometimes point users to websites that don't exist. Threat actors are now registering these AI-hallucinated domains and using them to host phishing sites.
"To detect the risk posed by phantom squatting, we analyzed 913 global brands and executed 685,339 URL queries across multiple configurations of two distinct LLM models," Unit 42 says. "This generated 2.1 million URLs and revealed over 13,229 confirmed malicious URLs.
"Furthermore, we discovered approximately 250,000 hallucinated domains that remain unregistered, presenting a significant opportunity for adversaries to exploit the software supply chain through preemptive registration."
This technique exploits users' trust in AI tools to generate accurate information. Users are more likely to trust a link provided by an AI chatbot than one sent in an unsolicited email or text message.
"Any user or autonomous AI agent that issues a query triggering the hallucinated URL receives an authoritative, high-confidence recommendation to navigate directly to attacker-controlled infrastructure," the researchers write. "This represents a defining characteristic of the phantom squatting threat.
"The delivery vector bypasses traditional phishing emails, malvertising or watering hole attacks. Instead, the delivery mechanism is the trusted AI assistant already integrated into the user's workflow."
Attackers are quickly adopting this technique, and in at least one case have already incorporated it into a phishing kit called "Montana Empire."
[CONTINUED] At the KnowBe4 blog with further data and links:
https://blog.knowbe4.com/ai-hallucinations-phishing-sites
Email and Messaging Security That Understands You
Email is your riskiest channel for attacks and data loss. Nearly 58,000 threats slip past traditional defenses every day. They're not occasional. They're persistent, high-volume and growing more sophisticated with AI.
See how you can stop up to 97% more attacks and uncover 10x more potential data breaches before they happen.
Join this live demo of KnowBe4's Collaboration Security to see how you can detect the full spectrum of inbound threats and outbound data loss and coach your workforce in real time against every threat.
We will showcase:
- NEW! Microsoft Teams Messaging Security: Extending defense beyond the inbox to monitor external chats, block threats and harden collaboration.
- NEW! Self-Serve DLP Rule Builder: Easily build and manage custom rules to stop outbound data leaks.
- Misdirected Content Analysis: Smarter AI that understands context to catch errors before sensitive data goes to the wrong recipient.
- Teachable Security Moments: Real-time coaching that fixes risky user behavior in the moment.
Your defenses are only as strong as your weakest entry point. Don't let email and Microsoft Teams messaging be it.
Date/Time: TODAY, Tuesday, July 28, @ 2:00 PM (ET)
Save My Spot:
https://info.knowbe4.com/ces-demo-1?partnerref=CHN2
The New Face of AI Risk
By Javvad Malik
Cybercrime used to have a "tell." It was the digital equivalent of a villain stroking their cat - clunky grammar, misspelled links and suspicious attachments that screamed "phishing."
But the arrival of AI has changed everything. Typos have been replaced by perfect prose. Generic lures have evolved into highly personalized attacks that mimic your internal language and align with your project timelines. These attacks don't just land in an inbox; they adapt in real-time if you engage and they can be deployed at a scale we've never seen before.
The once-a-year security awareness training was built for a world that no longer exists. When threats are continuous, your defense cannot be sporadic. Organizations need to move toward live coaching — real-time nudges that guide users exactly when they are about to make a high-risk decision.
The Hybrid Workforce
Your organization's directory is no longer just a list of names. It's a complex ecosystem of humans and their AI agents, held together by APIs, SaaS integrations and a healthy dose of optimism.
These digital assistants are incredibly helpful. They're drafting code, managing calendars and interacting with customers. But they are also vulnerable. An attacker doesn't always need to trick a human; they can trick an agent into oversharing data or overwriting critical files.
When security teams respond by simply locking everything down, it creates a "shadow AI" problem. Staff will always find a way to use the tools they need to get the job done. The real risk lives in that blurry area between what is officially permitted and what is functionally necessary.
Speed and Precision at Scale
What actually changes when AI takes the lead in cyberattacks? Two things: precision and speed.
- Context Over Content: Attackers can now generate thousands of tailored messages that look like routine business. Red flags are no longer about bad spelling. Today's phish arrives mid-thread, using the correct tone to ask for a plausible favor. In this environment, understanding the context is more important than checking the content.
- Multichannel Conversations: These aren't slow one-off emails; they are rapid dialogues. An attack might start as an email, move to a chat app, and culminate in a quick "verification" video call on a Friday afternoon.
Setting the Controls
To counter a rising tide of risk, we need guidance that appears just at the right time and place.
Imagine a system that interrupts a dangerous action with a simple prompt: "This attachment is from an unfamiliar sender — send to security for a quick check?" or "Payment details have changed; please verify via a secondary known channel." This allows the business to move fast without removing the safety net.
We also need to govern AI agents with the same rigor we apply to colleagues.
- Identity and Access: Give agents unique, rotating credentials.
- Least Privilege: Keep their permissions narrow and explicit.
- The Human Loop: If an agent wants to perform a high-risk task (like moving money or changing permissions), it should require a human sign-off.
- Logging: Record everything. If a bot makes a mistake, you need a breadcrumb trail to figure out why it thought that action was reasonable.
Cultivating a "No-Fear" Culture
Ultimately, your strongest defense is your culture. If your security policy relies on punishment, your employees will hide their mistakes. When people fear being reprimanded, they won't report a suspicious link until it's too late.
We need to reward transparency. Praise the near misses and make the secure path the easiest one to take. When you explain the why behind a rule, people are more likely to follow it.
In an AI-augmented world, thread-hijacking is caught because someone notices a subtle shift in timing or tone. A change to a vendor's bank details is flagged because the workflow demands a manual callback. Sensible points of critical thinking that protect the team.
Leaning into the Workflow
AI has made cyber threats faster and more personal. The solution isn't to retreat or rely on outdated training modules. It's to integrate security into the actual flow of work.
The modern workforce is a hybrid of human intuition and machine speed. To stay safe, we have to secure the entire team as one.
Blog post with links:
https://blog.knowbe4.com/new-face-of-ai-risk
[On-Demand Virtual Summit] Secure Every Human & AI Agent
The workforce has changed; your security strategy needs to catch up. AI agents are proliferating across your organization. Attackers are weaponizing deepfakes and AI-powered social engineering against your people. The old playbook wasn't built for a workforce that is no longer purely human.
You'll walk away with:
- Look to the future of AI-native security: Explore the future of digital workforce security and the innovations shaping what comes next
- Know your threat. Own your defense. Walk away confident you have the knowledge and tools to defend against the threats targeting your people and agents — deepfakes, AI-powered phishing, voice cloning and more
- See what's coming on the KnowBe4 Platform roadmap and get an exclusive inside look at what's next
New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication
Researchers at ReliaQuest are tracking two new phishing toolkits that are designed to bypass multifactor authentication (MFA). The first tool, called "Jalisco," is a device code phishing platform that pairs with AI-powered phishing-as-a-service platforms like EvilTokens to provide fresh OAuth codes in real time.
"Jalisco is a device code phishing toolkit that provisions fresh OAuth codes in real time via a backend API and manages captured sessions through a web portal," ReliaQuest says. "Its use of lure-generation—a recent evolution that bypasses the 15-minute time-to-live (TTL) on device codes—neutralizes one of the core security assumptions defenders rely on to limit device code phishing.
"Its presence in the wild signals that lure-generation is highly likely to become a standard feature across a wider range of phishing kits." The second tool, dubbed "OmegaLord," is a credential harvester that also captures phone numbers in order to intercept MFA codes.
"OmegaLord is a newly discovered JavaScript-based credential harvester that goes beyond standard tools by deliberately collecting phone numbers alongside credentials, likely to intercept or hijack MFA—a signal that even traditional credential-theft phishing is being engineered around modern authentication defenses," the researchers write.
"OmegaLord displays a fake PDF reader login page that prompts the user for their email address, password and phone number. Collecting phone numbers is unusual for credential harvesters and is likely intended to help the attacker intercept or hijack MFA requests during authentication."
Both of these toolkits indicate that attackers are increasingly interested in automating techniques to bypass MFA. "Neither tool exists in isolation," the researchers explain. "Device code phishing tricks users into authenticating on behalf of an attacker, bypassing MFA without exposing credentials, and has surged in 2026—driven by AI-powered PhaaS kits that let any attacker impersonate any brand with minimal skill.
"Once inside a compromised Microsoft 365 account, attackers establish persistence by pairing multiple attacker-controlled devices to the victim's Entra ID tenant, then move quickly to exfiltrate sensitive data from software-as-a-service (SaaS) platforms for extortion."
KnowBe4 empowers your workforce to make smarter security decisions every day.
Blog post with links:
https://blog.knowbe4.com/new-phishing-kits-automate-bypassing-mfa
Identify Weak User Passwords in Your Organization with the Newly Enhanced Weak Password Test
Cybercriminals never stop looking for ways to hack into your network, but if your users' passwords can be guessed, they've made the bad actors' jobs that much easier.
Verizon's Data Breach Investigations Report showed that 81% of hacking-related breaches use either stolen or weak passwords.
The Weak Password Test (WPT) is a free tool to help IT administrators know which users have passwords that are easily guessed or susceptible to brute force attacks, allowing them to take action toward protecting their organization.
Weak Password Test checks the Active Directory for several types of weak password-related threats and generates a report of users with weak passwords.
Here's how Weak Password Test works:
- Connects to Active Directory to retrieve password table
- Tests against 10 types of weak password related threats
- Displays which users failed and why
- Does not display or store the actual passwords
- Just download, install and run. Results in a few minutes!
Don't let weak passwords be the downfall of your network security. Take advantage of KnowBe4's Weak Password Test and gain invaluable insights into the strength of your password protocols.
Download Now:
https://info.knowbe4.com/free-cybersecurity-tools/weak-password-test-chn
Let's stay safe out there.
Warm regards,
Stu Sjouwerman, SACP
Executive Chairman
KnowBe4, Inc.
PS: Yours Truly in Forbes: "Your AI Agent Thinks It's Right, And That's Exactly The Problem":
https://www.forbes.com/councils/forbestechcouncil/2026/06/25/your-ai-agent-thinks-its-right-and-thats-exactly-the-problem/
PPS: [New Research] AI models know they are guessing but they don't tell you:
https://www.instagram.com/reel/DaiB7g5xzIf/?igsh=MWtjNjV3ZjJrZ2d3cQ==
- Thomas Jefferson (1743-1826) Principal author of the Declaration of Independence
- Bruce Lee - Martial Artist (1940 -1973)
You can read CyberheistNews online at our Blog
https://blog.knowbe4.com/cyberheistnews-vol-16-30-protect-your-users-ai-hallucinations-are-fueling-phishing-attacks
North Korean Hackers Are Targeting LinkedIn Users With Phony Job Offers
Hackers with the North Korean threat actor Famous Chollima are posing as recruiters on LinkedIn and attempting to trick users into falling for ClickFix attacks, according to researchers at SOCRadar.
"In the latest variant of the ClickFake campaign, Famous Chollima actors rely on social engineering, posing as potential recruiters to convince targets into a skill assessment, part of a fake interview, and run malicious payloads," SOCRadar says. "They occasionally create fake front companies or impersonate known ones in the crypto and Web3 industries, and reach out to their targets via social media (LinkedIn, Discord, Telegram and Email)."
At the end of the phony interview process, the attackers fabricate a problem that the user supposedly needs to fix. This is when the ClickFix attack is launched: the attackers send the victim instructions to paste a command into their computer, which will result in malware installation.
"After convincing them with the pretext of high salaries, they send out an invitation for a skill assessment on their infrastructure. Their targets include non-technical profiles such as advisors, investment partners and business intelligence analysts.
"The fake assessment includes multiple choice questions as part of the tasks of each role, as well as a final question in the end to record themselves answering it. The final lure is that something is not working with the camera or the microphone on this last step, and ClickFix instructions are presented to the target to resolve the issue."
DPRK threat actors have been using job-themed attack campaigns for years, often landing remote jobs at U.S. organizations by posing as legitimate IT workers. KnowBe4 itself was among the first to spread wide awareness about this issue when we were targeted by a fake North Korean IT worker in 2024.
The individual was detected before they could exfiltrate any data, but the incident demonstrated the effectiveness of AI-enhanced social engineering. KnowBe4 empowers your workforce to make smarter security decisions every day.
SOCRadar has the story:
https://socradar.io/blog/dprk-clickfake-pylangghost-golangghost-rats/
Report: Employees Are Overconfident in Their Ability to Spot Scams
A survey from Trustmi found that most employees believe they'd be able to spot a social engineering attack, but those same employees still rely primarily on outdated guidance to spot red flags. Generative AI has given attackers the ability to craft extremely convincing, error-free phishing emails.
"Findings suggest employee confidence is rooted in their ability to spot traditional fraud tactics," the report says. "A large majority (78% of respondents) said they were confident they could identify a fraudulent payment request at work. But they're still looking for the traditional phishing tactics - such as typos or fake email addresses - they were trained to recognize years ago. 70% rank typos, fonts or grammatical errors as their No. 1 warning sign."
While typos and grammatical errors are still red flags, employees need to be aware that many phishing emails now have perfect spelling and grammar. Users should be on the lookout for other signs of social engineering as well.
"Every other cue trails well behind: 25% cite an unfamiliar sender, 22% [cite] unusual urgency and 16% [cite] a suspicious invoice," the researchers write. "Even unusual urgency - the pressure tactic common to executive-impersonation and payment-diversion scams - ranks near the bottom. The reliance on old signals is sharpest among the youngest workers: Gen Z ranks grammar mistakes as a top warning sign more than any other generation (82%), compared with 50% of Baby Boomers."
Employees are also lagging in awareness of established social engineering techniques. Most (81%) respondents said they would trust a payment request that appeared in an existing email thread, even though attackers have been hijacking existing email threads for years to launch business email compromise (BEC) attacks.
Trustmi has the story:
https://www.accessnewswire.com/newsroom/en/computers-technology-and-internet/trustmi-survey-employees-are-confident-they-can-spot-payment-frau-1190502
What KnowBe4 Customers Say
"I wanted to take a moment to let you know how much we appreciate working with Zach. It's not often that you come across someone who combines such a high level of technical knowledge with the ability to explain things so clearly and patiently.
"No matter the question or challenge, he never rushes the conversation. He takes whatever time is needed to walk us through the details, making sure we understand not just the answer, but the reasoning behind it. What we appreciate even more is that he doesn't stop there — he takes the extra step to test his recommendations and confirm that the solution actually works. That kind of thoroughness gives us tremendous confidence and has saved us time and frustration on more than one occasion.
"Beyond his expertise, he's simply a pleasure to work with. He's approachable, thoughtful, and genuinely invested in helping us succeed. We never feel like we're just another customer; we feel like we're working with someone who truly cares about finding the best outcome for us. The partnership we've built with him is one that we value tremendously, and he has earned our trust and respect.
"We wanted to make sure you knew what a positive impact he has had on our team. People like him are a real credit to your organization, and we are grateful for everything he does. Please extend our sincere thanks and appreciation to him. We look forward to continuing to work together."
- F.C., Sr. Sys Admin
- Europol flags 4,340 URLs for removal in 'The Com' crackdown:
https://www.europol.europa.eu/media-press/newsroom/news/europol-led-action-against-nihilistic-violent-extremist-network-com - FBI Warns of Scammers Impersonating the IC3:
https://www.ic3.gov/PSA/2026/PSA260720 - The ransomware economy continues to grow and evolve:
https://www.emsisoft.com/en/blog/47821/the-state-of-ransomware-in-q2-2026/ - Russian Hacker Turns Jailbroken Claude Into Pentest Platform:
https://www.infosecurity-magazine.com/news/trim-jailbroken-claude-ai-pentest/ - The Small S.C. Town in Turmoil Over a $545,000 Business Email Compromise Attack:
https://www.wsj.com/articles/the-south-carolina-town-in-turmoil-over-a-545-000-email-phishing-scam-988a9acb?mod=djemCybersecruityPro&tpl=cs - APT42 Uses AI-Assisted Phishing and TAMECAT Malware to Target Government and Defense Officials:
https://cybersecuritynews.com/apt42-uses-ai-assisted-phishing-and-tamecat-malware/ - Kratos phishing-as-a-service kit loses its battle with international law enforcement:
https://www.theregister.com/security/2026/07/21/german-authorities-lead-takedown-of-kratos-phishing-platform/5275666 - Watch out. That Microsoft Calendar invite dated 2050 could be hiding stolen files and worse:
https://www.techradar.com/pro/security/watch-out-that-microsoft-calendar-invite-dated-2050-could-be-hiding-stolen-files-and-worse - Phishing links could plant a rogue AI agent inside a company's ChatGPT workspace:
https://www.theregister.com/security/2026/07/23/one-chatgpt-link-could-smuggle-a-rogue-ai-agent-into-your-company/5275116 - Scammers target users searching for pirated versions of The Odyssey movie:
https://www.malwarebytes.com/blog/threat-intel/2026/07/the-odyssey-piracy-scams-appear-within-hours-of-the-movies-release
- [ROBOT SUPER FAVE] Unitree Super Athlete AS2-W:
https://youtu.be/Xha2TJ_1C6Q - Virtual Vaca #1 - La Roque-Gageac & Castelnaud Castle, France's Epic Cliffside Gems:
https://youtu.be/j9yxgkJgUnA - Virtual Vaca #2 - Top 10 Places To Visit in Wales:
https://youtu.be/Qz_Mi8D1cis - Virtual Vaca #3 - Little Lofoten | Norway's Arctic Paradise, Little Big World:
https://youtu.be/XhSiJcXrtXw - Three new world records Sebastián Álvarez wingsuit flight:
https://www.flixxy.com/sebastian-alvarez-becomes-the-fastest-flying-human.htm?utm_source=chn&utm_medium=email - [SUPERFAVE] I Outsmarted "Relay Attack" Pro Car Thieves:
https://www.youtube.com/watch?v=h0EGCnBjTVk - New Lexus LFA Concept comes with a drone:
https://youtu.be/2EB8KrJ4YM4 - This Country is Dominating The Nuclear Power Race:
https://youtu.be/uTCA6RZmQbY - Flying Into the Sunset - Wingsuit Race With Live Stats:
https://youtu.be/WNqAGxAe6ow - Can You Ship A Potato Through The Mail?
https://www.youtube.com/shorts/kgSHJhX6ly0 - For Da Kids #1 - Born to Swim! Baby Elephant Sam Houston Is a Water Baby:
https://youtu.be/vlXe7_-LDSk - For Da Kids #2 - Wild Birds Fall in Love With a Husky:
https://youtu.be/E6B7Gidws6Y - For Da Kids #3 - Orphaned Owl Defies The Odds To Return To The Wild:
https://youtu.be/kPSukGcRFrw - For Da Kids #4 - Mama Opossum And Her Babies Trapped Between Two Fences:
https://youtu.be/73D0KUOkHT4 - For Da Kids #5 - Sheep Knocks On Door To Play With Cat Friend:
https://youtu.be/IF0sAI5yvmE

