KnowBe4 Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in human and agent security including social and prompt engineering, ransomware and phishing attacks.

Confirm Your Unsubscribe Request? Not So Fast

An email phishing campaign that BleepingComputer describes as “long-running” has shown a distinct uptick recently. The phishbait in the subject line will read something like this: ...

Bad Guys Exploit CapitalOne Breach to Push Backdoor Trojan

The bad guys are now exploiting news of the CapitalOne breach to push a malicious backdoor trojan via a phishing email purporting to offer a Windows Security Update. See the attached ...

Pleading Guilty to Business Email Compromise

Amil Hassan Raage has taken a guilty plea to charges of fraud in a business email compromise (aka CEO fraud) case that netted him and his criminal co-conspirators almost three-quarters of ...

[NEW PhishER Feature] Identify Email Threats Even Faster with PhishML™

We are excited to announce the availability of PhishML™ as part of the PhishER platform to all PhishER customers. PhishML is a new machine-learning module that helps you identify and ...

New UK Study: "3 out of 4 phishing scams get to your inbox untouched"

Chris Matyszczyk wrote: "Apple sends me so many invoices every week that I scarcely know what I've gone and bought. This appears to have also crossed the minds of researchers at the UK's ...

Why School Districts are Targets of Social Engineering

School districts are becoming increasingly popular targets for ransomware, with at least five of these attacks occurring in July, according to the New York Times.

Why Is Windows Defender The World's No. 1 Antivirus With More Than Half A Billion EndPoints?

Having been inside the AntiVirus software industry for quite a while, and building an AV tool from the ground up, when I saw Redmond start acquiring several small AV companies in 2008 and ...

GermanWiper Ransomware Hits Germany Hard, Destroys Files But Asks For A Ransom

For the past week, a new ransomware strain has been wreaking havoc across Germany. Named GermanWiper, this ransomware doesn't encrypt files but instead it rewrites their content with ...

Engineering Licensing as Phishbait

Researchers have observed a state-sponsored spearphishing campaign targeting three US utilities companies. The emails convincingly posed as exam results from the National Council of ...

Churches and Other Not-for-Profits as Targets of Scams

On this week’s episode of the CyberWire’s Hacking Humans podcast, Dave Bittner and Joe Carrigan discussed a story written by two lawyers for Church Law & Tax that warns of a type of ...