CyberheistNews Vol 16 #40 | October 6th, 2026
Why Microsoft’s Latest Defense-in-Depth Email Benchmark Is So Surprising
Let’s face it: inertia is often the most common yet most dangerous adversary when it comes to acquiring new technology, especially in cybersecurity.
There is still a persistent assumption across many organizations that email security architecture that worked three years ago is still good enough for today’s threat landscape. Even when security teams suspect gaps, the friction of evaluating, procuring and operationalizing new technology creates a massive organizational bottleneck.
Calculating the true total cost of ownership (TCO) and return on investment (ROI) has historically felt like an exercise in guesswork that often leaves executives, like the CFO, questioning whether the investment is worth it. Vendor claims are notoriously reliant on synthetic lab simulations or cherry-picked sample sizes that rarely survive in an organization’s live environment.
That reality is why Microsoft’s latest benchmark release is an eye opener for organizations looking to evaluate the effectiveness of their tech stack.
Microsoft has published its fifth consecutive Microsoft email security benchmarking report that analyzed real-world customer telemetry from May - July 2026. This report strips away marketing hyperbole and measures what security tools actually catch inside live production tenants.
The data reveals two fundamental realities:
- Native cloud defense has matured significantly. Microsoft Defender stops the overwhelming volume of commodity spam, mass phishing and known malware before it reaches an inbox. Routing email via a legacy Secure Email Gateway (SEG) into Microsoft Defender introduces unnecessary cost, latency, technical complexity and operational friction.
- Evasive, payload-free attacks demand specialized behavioral AI. Baseline perimeter filtering inevitably leaves an attack surface exposed to executive impersonation and Business Email Compromise (BEC). Hyper-personalized GenAI spear phishing and adversarial prompt injections have also become widespread, targeting users wherever they collaborate, whether in Outlook or Microsoft Teams. Because these attacks contain no malicious attachments or known-bad links, static inspection has nothing to detonate. Stopping them requires behavioral AI that understands communication history, organizational relationships and conversational context to detect deception before it reaches the inbox.
To understand how the market solves this challenge, Microsoft measured seven leading Integrated Cloud Email Security (ICES) add-on solutions running directly on top of Microsoft Defender.
The result? KnowBe4 Defend ranked #1 across every single uplift metric reported.
[KEEP READING] Check out that 100% Microsoft Telemetry:
https://blog.knowbe4.com/what-microsofts-latest-email-benchmark-proves-about-defense-in-depth
[FREE Kit] Your 2026 Cybersecurity Awareness Month Kit Is Here
Cybersecurity Awareness Month is here, and your mission, should you choose to accept it, starts now.
This free campaign-in-a-box turns your employees into "Secret Agents" against cybercrime. Inside:
- NEW! Four "Workforce Risk Division Specialist" character cards, posters and digital signage in multiple languages
- NEW! Four tabletop exercises to test your team against real-world scenarios
- Training videos and interactive modules from KnowBe4's award-winning library
- A Strategy Dossier and Weekly Planner to help you plan your activities
- A top-secret Mission Brief on a free KnowBe4 tool
- Two new on-demand webinars and whitepapers
Equip your users for October and beyond.
[Heads Up] Social Engineering Attacks Using Deepfakes Increase Big Time
Forty-one percent of CISOs said an audio deepfake targeted their organization within the last 12 months, according to a new survey by Gartner. Additionally, 36% of respondents said employees were targeted by deepfake video calls over the past year.
Craig Porter, Director Analyst at Gartner, noted that social engineering and human deception remain at the core of these AI-assisted attacks.
"Attackers can combine phishing, business email compromise, synthetic media and aggregated personal context across multiple channels," Porter said. "Most attacks will continue to rely on users, stolen credentials, weak recovery processes and familiar technical methods. CISOs must use the same discipline used to assess identity and access risks to combat AI-driven social engineering threats."
Gartner recommends that organizations take the following steps to protect themselves:
- "Evolve secure behavior and culture programs from teaching employees to 'spot the fake,' toward making secure verification the expected behavior for consequential requests. Train employees and approvers to pause, verify and report high-risk requests regardless of whether the request arrives through e-mail, voice, video, collaboration tools or an AI application. Use workforce simulations to test verification and reporting behavior of AI-related suspicious events.
- Protect high-value workflows such as account recovery, privileged access and payment authorization with phishing-resistant authentication, risk-based identity controls and trusted verification channels. In addition, implement controls to detect identity abuse, including after a successful login or password reset.
- Correlate suspicious communications and impersonation reports with account recovery events, new devices, privilege changes and financial transactions to improve threat detection. Update incident response playbooks for multimodal impersonation, manipulated AI recommendations, compromised or misused agents and, where applicable, agents that operate beyond their intended boundaries."
Blog post with links:
https://blog.knowbe4.com/report-social-engineering-attacks-are-increasingly-using-audio-and-video-deepfakes
[NEW WEBINAR] Autonomous AI Attacks Explained: What Happened and What's Next
In July 2026, an OpenAI model escaped its test sandbox. It found its way onto the open internet, and hacked into Hugging Face's production infrastructure, entirely on its own, with no human steering it. It wasn't trying to cause damage. It was trying to cheat on a benchmark. It succeeded anyway.
If an AI agent can pull off a real intrusion by accident, what happens when someone points one on purpose?
Join Harlan Parrott, VP of AI Innovation at KnowBe4, and Matthew Duren, SVP of AI and Data at KnowBe4, as they break down what actually happened, why it matters and what it means for how you defend your organization.
You'll Learn:
- Real-world examples of autonomous AI attacks, dissected
- Why these attacks aren't as novel as they sound: what they borrow from decades-old self-replicating malware and the three things that make them genuinely more dangerous
- Where rogue agents and autonomous threats go from here
- The approach that actually prevents these incidents, and why the fundamentals still matter more than the hype
The attackers are moving at machine speed. Make sure your defenses are too. Save your spot and get the insights you need to stay ahead of what's coming next.
Date/Time: TODAY, Tuesday, Oct. 6, @ 2:00 PM (ET)
Save My Spot:
https://info.knowbe4.com/autonomous-ai-cyberattacks?partnerref=CHN
FBI Alert: Phishing Attacks Are Impersonating Law Enforcement
The U.S. Federal Bureau of Investigation (FBI) has issued an alert warning that widespread fraud campaigns are impersonating law enforcement or government officials to trick users into handing over money or sensitive information.
"Scammers primarily contact victims through unsolicited phone calls; however, other methods, including text messages and emails, are also used," the FBI says. "Scammers often spoof authentic phone numbers, email addresses, employee names and credentials of well-known government and law enforcement agencies, including IC3.
"Scammers will use a variety of approaches while impersonating these officials, such as using urgent and aggressive tones, refusing to speak to or leave messages with anyone other than the targeted victim, keeping victims on the phone for the duration of the scam, or urging victims not to tell family, friends, financial institutions or law enforcement about the call.
"The scammers demand payment through a variety of methods, including prepaid cards, couriers, bank wires, cryptocurrency or cash inserted into cryptocurrency kiosks."
The FBI offers the following advice to help users avoid falling for these attacks:
- "Law enforcement and government authorities will never contact members of the public by telephone or text message to demand any form of payment or to request personal or sensitive information.
- Law enforcement and government officials will never request payment via prepaid cards, cryptocurrency or courier.
- Never give your personal information to anyone without verifying the person is who they say they are. Ask for credentials and use official, publicly available information to contact the government or law enforcement agency to verify the caller and their credentials; do not use contact information provided by the person contacting you.
- If you are sent any webpage URLs, do not click without reviewing them to ensure they match the official domain of the law enforcement or government agency. Remember, scammers may use URLs closely mirroring official ones, but with slight variations or incorrect domain extensions (.com instead of .gov)."
Blog post with links:
https://blog.knowbe4.com/fbi-alert-phishing-attacks-are-impersonating-law-enforcement
Personalized Security Awareness Training Proven to Reduce Risk by 87%
A whopping 68% of breaches still involve a human element. As attackers use AI to create hyper-personalized attacks, even your most security-conscious users can be fooled. Yet they're still getting the same generic training that ignores those real-world risks.
Join us for a live demo to see how our AI-Native Security Awareness Training helps you close the gap. Training that adapts to each user's actual risk, content you can build in minutes instead of months, and defenses built for the way people are attacked today.
See how you can:
- Change behavior with training tailored to each user's role, behavior and risk level
- Prepare your workforce for real threats like vishing, deepfakes and AI-generated phishing
- Create custom content unique to your policies and workflows in minutes with generative AI
- Deliver real-time coaching the moment risky behavior happens — before it becomes a mistake
- Reduce Phish-prone™ Percentage from an industry average of 33.1% to 4.1% in one year (87% reduction in human-related cyber risk)
See how training that adapts in real time can close the gap generic training leaves open.
Date/Time: Wednesday, Oct. 14, @ 2:00 PM (ET)
Save My Spot:
https://info.knowbe4.com/sat-demo-month1?partnerref=CHN
Now You Can Govern Claude AI with KnowBe4’s Agent Risk Manager
Agent Risk Manager, KnowBe4’s AI agent security product in the KnowBe4 Platform, integrates with the Claude Compliance API to help organizations monitor Claude activity and detect risks in real time. Today, that integration is featured in Claude’s Compliance API milestone announcement.
Agents Are Acting, but Who’s Watching?
Ask a security leader which employees used Claude last week, what they connected it to and whether any sensitive information passed through, and many won’t be able to provide a definitive answer. Not because they don’t care or because they don’t want to know, but because there hasn’t been a place for them to look.
AI agents can read files, send emails, pull records from connected systems and take multi-step action, largely outside the controls organizations already have for human activity.
KnowBe4’s 2026 "From Agentic Risk to Human Wins" report puts numbers on that gap: 58% of cybersecurity leaders say AI agents are already taking real actions inside their organization’s workflows, and 52% say their organization’s AI use is unapproved or ungoverned. Most security leaders know AI agents are acting on their behalf, but they haven’t been able to govern those agents the same way they govern their people.
We believe that human risk and AI risk are not two separate problems. They are the same problem that has grown with agents entering the workforce, and they need to be treated that way.
Our integration with the Claude Compliance API is one way we address that problem.
What Does Agent Risk Manager’s Claude Integration Do?
This integration brings an organization’s Claude activity into Agent Risk Manager, the same console security teams use to govern Microsoft Copilot Studio, ChatGPT, Google Gemini and browser-based shadow AI. With Agent Risk Manager, that activity gets inventoried, analyzed for risk and tied to the people behind the agents.
Detection built for agent risk
Agent Risk Manager’s detection agents evaluate Claude activity for prompt injection, sensitive data and PII exposure, privilege escalation, excessive agency and unapproved access, using the full context of an interaction and not just a keyword match.
See and understand Claude activity
Every connected organization gains a proactive inventory of Claude agents and tools, and a unified AI Activity Log covering detections and policy events, all in one place instead of scattered across consoles.
Coverage for your whole Claude footprint
One compliance API key is all it takes. Agent Risk Manager automatically discovers every workspace tied to your organization's key, so there's no per-team or per-agent setup to maintain. What's visible follows how you've deployed Claude. On Claude Platform, that's activity logs. On Claude Enterprise, it can also include conversation content like chats and files.
[CONTINUE] On the knowBe4 blog for availability and how to get started:
https://blog.knowbe4.com/govern-claude-ai-with-knowbe4s-agent-risk-manager
Let's stay safe out there.
Warm regards,
Stu Sjouwerman, SACP
Executive Chairman
KnowBe4, Inc.
PS: And here is the brand new Microsoft Digital Defense Report 2026:
https://www.microsoft.com/en-us/corporate-responsibility/topics/cybersecurity/reports/microsoft-digital-defense-report/
- Richard P. Feynman, physicist (1918–1988)
- Carl Sagan, astronomer (1934–1996)
You can read CyberheistNews online at our Blog
https://blog.knowbe4.com/cyberheistnews-vol-16-40-why-microsofts-latest-defense-in-depth-email-benchmark-is-so-surprising
Report: Russian APT Launches Widespread Phishing Campaigns Using New Tactics
Microsoft warns that the Russian APT "Star Blizzard" is launching widespread phishing campaigns against Western organizations, using a new malware infection flow.
Star Blizzard is linked to Russia's Federal Security Service (FSB) Centre 18. Microsoft says the ongoing phishing campaigns have hit more than a hundred organizations, primarily in the U.S. and United Kingdom.
"Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique that Microsoft tracks as 'RedFlick.'"
"These changes represent a notable shift in the actor's operational tradecraft and support ongoing cyberespionage activity targeting Ukrainian individuals and institutions as well as international non-government organizations (NGOs), Western think tanks, governments and other organizations associated with international policy—particularly those with a nexus in supporting Ukraine."
Star Blizzard's shift to the RedFlick technique is significant because these attacks only involve a single user interaction in the social engineering stage of the attack.
"As part of this evolution, Star Blizzard adopted RedFlick, a malware delivery technique that helps evade detection by initiating a set of scheduled tasks to deploy the actor's custom backdoor, CosmicPulse," the researchers write. "This technique is a notable departure from the actor's previous use of ClickFix-based infection chains which required victims to complete multiple actions before CosmicPulse could be installed.
"The RedFlick infection flow only requires a single user interaction, reducing friction in the compromise process. Combined with the actor's shift toward large-scale phishing operations during the same period, these changes likely improve Star Blizzard's ability to reach more targets, evade detection and increase the likelihood of successful compromise."
KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 Platform to strengthen their security culture and reduce workforce risk.
Microsoft has the story:
https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/
New Phishing Campaign Uses Claude-Themed Lures
A phishing campaign is targeting Google accounts with lures that promise free subscriptions to Anthropic’s Claude Max AI model, Malwarebytes warns.
"The site announces that Anthropic has passed 100 million users and is thanking people by giving away 10,000 free one-month subscriptions to Claude Max, its highest-usage plan," Malwarebytes says. "The presentation is careful, down to the real logo and colors, invented five-star reviews and a long footer whose links lead almost entirely to genuine Anthropic pages.
"This is probably the most effective trust signal on the site, and it cost the operator nothing. A counter claims that fewer than 750 of the 10,000 slots remain, dropping by a few every several seconds. Nothing is actually being counted.
"The number is generated inside your browser and resets when you reload the page, so every visitor sees the same manufactured shortage." The goal of the phishing site is to trick the user into entering the credentials to their Google account. The site uses the "browser-in-the-browser" technique to open a fake Google login window inside the tab.
"Two sign-in options appear, but only one works," the researchers explain. "The Apple button produces a pre-written notice saying that the method is temporarily unavailable. The email box discards whatever you type into it and triggers the Google button instead. Every route leads to the same place....Clicking the Google button doesn’t open a real Google sign-in window.
"Instead, the page draws a browser window inside the existing tab, complete with a padlock and a correctly spelled Google sign-in address. It can even be dragged around the page. The address bar, padlock and everything inside the supposed window belong to the phishing page, not Google.
"It begins with a human-verification step rather than a password box, which may reassure visitors while helping to keep automated scanners away from the next stage."
Malwarebytes has the story:
https://www.malwarebytes.com/blog/threat-intel/2026/09/fake-claude-max-giveaway-hides-a-google-account-phishing-trap
What KnowBe4 Customers Say
"Good morning Bryan. Yes, we have encountered a few challenges along the way, but we have worked closely with our KnowBe4 Customer Success Manager, Christina H., as well as Robinson L. and the KnowBe4 Technical Support team to effectively address and remediate those issues.
"Their responsiveness and support have been greatly appreciated as we continue to learn and mature our program. We are excited to move forward with our Legal Team's compliance training campaigns next week and are looking forward to continuing our partnership with KnowBe4.
"Thank you for reaching out and for your continued support."
– B.D., Lead IT Compliance Analyst
- Ransomware data theft has surged by 275% in 2026:
https://www.zscaler.com/blogs/security-research/ransomware-data-theft-surged-275-2026-schools-hospitals-and-government - Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation:
https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/ - 9 out of 10 Americans say they’ve been targeted by a scam:
https://www.consumerreports.org/media-room/press-releases/2026/10/new-study-by-consumer-reports-reveals-9-in-10-americans-targeted-by-a-cyberattack-or-digital-scam-attempt/ - White House unveils ‘super intelligence’ executive order and industry accord:
https://www.nextgov.com/artificial-intelligence/2026/09/white-house-unveils-super-intelligence-executive-order-and-industry-accord/416325/ - Google AI Threat Defense helps you actively predict attacks and deploy fixes at machine speed:
https://cloud.google.com/security/ai-threat-defense? - Two US Air Force members given over 6 years in prison for cyber theft of more than $2 million:
https://therecord.media/us-air-force-members-given-6-year-sentence-cyber - Massive Pentagon hack sees records of 2.7 million US military personnel leaked:
https://www.techradar.com/pro/security/massive-pentagon-hack-sees-records-of-2-7-million-us-military-personnel-leaked-during-months-long-data-breach-names-military-service-records-and-social-security-numbers-all-revealed - Attackers are increasingly using vishing and device-code phishing to breach organizations:
https://reliaquest.com/blog/threat-spotlight-whats-trending-top-cyber-attacker-techniques-june-2026-august-2026/ - UK government survey finds that more than half of businesses lack confidence in basic cyber skills:
https://www.theregister.com/security/2026/09/30/more-than-half-of-uk-businesses-lack-confidence-in-basic-cyber-skills/5299991 - India Phishing sites are exploiting the release of the new iPhone:
https://www.deccanherald.com/technology/want-to-buy-an-iphone-18-pro-at-discount-beware-you-might-lose-more-than-just-your-money-4163898
- Virtual Vaca #1 - Capri, Italy - In Depth Tour:
https://youtu.be/89xxno7jZE0 - Virtual Vaca #2 - Top 10 Places To Visit in Bosnia & Herzegovina:
https://youtu.be/qGsNmbiOtAQ - Virtual Vaca #3 - 10 Incredible Natural Wonders on Utah's Hole-In-The-Rock Road:
https://www.youtube.com/watch?v=OSW7YtPaX1k - Magician EXPOSES Penn & Teller Code, THEN FOOLS them! Giancarlo Bernini:
https://youtu.be/JC0Djiv4_jw - World's First Continuous Ski Descent of Nanga Parbat (no oxygen). I have gone down a black diamond piste in Switzerland, but THIS is something else...
https://youtu.be/dheQxiIrr8s - Is Vegas Dying?:
https://youtu.be/oYc33xwX-JQ - New Stronger Hands for Boston Dynamics' Atlas:
https://youtu.be/4whgw2gLBS8 - Extreme Skills & Talents | Best of October:
https://youtu.be/hErCGp-0pQ8 - LockPickingLawyer - Electronic Time Lock (Opened 3 Ways)
https://youtu.be/ueJn7eU27hQ - The James Bond Movie GoldenEye used the mountain Tällistock to film a stunt. Here is the Wingsuit Base Jump:
https://youtu.be/CsLWOGL0HJM - For Da Kids #1 - Baby Goat Who Could Barely Stand Grows Up To Race Her Dog Brother:
https://youtu.be/DUbdCop9XIw - For Da Kids #2 - The crowned sea cucumber is part of the deep-sea clean-up crew:
https://youtu.be/vsit2ZvNbNs - For Da Kids #3 - Hero Frees Pelicans Beak:
https://youtube.com/shorts/gD1rrXoAXAY - For Da Kids #4 - Couple Faces Their Biggest Camping Fear For Their Dogs:
https://youtu.be/7fReXcLsqeE - For Da Kids #5 - Woman Saves Lonely Donkey And Gains A Best Friend:
https://youtu.be/NQL42Z3u0oI

