❌

Normal view

There are new articles available, click to refresh the page.
Yesterday β€” 24 July 2026KnowBe4 Security

The Open-Source Paradox: Navigating the New Frontier of AI Supply Chain Risk

24 July 2026 at 16:00

The recent developments surrounding vulnerabilities in major AI repositories like Hugging Face serve as a critical wake-up call for the cybersecurity community. As we accelerate toward an agentic future, the platforms we rely on for innovation are increasingly becoming the primary vectors for systemic risk.

Before yesterdayKnowBe4 Security

Elevating the SOC Experience: Smarter Automation, Richer Threat Intelligence, and AI-Native Investigation

23 July 2026 at 17:00

Security operations teams face a constant balancing act: stopping sophisticated email threats, maintaining visibility across their attack surface and keeping administrative workflows running smoothly. When security tools operate in silos or rely on rigid, manual processes, friction builds up quickly. This friction consumes valuable time that analysts could spend on higher-priority initiatives.

New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication

23 July 2026 at 12:00

Researchers at ReliaQuest are tracking two new phishing toolkits that are designed to bypass multifactor authentication (MFA). The first tool, called β€œJalisco,” is a device code phishing platform that pairs with AI-powered phishing-as-a-service platforms like EvilTokens to provide fresh OAuth codes in real time.

Attackers Exploit AI Hallucinations to Send Users to Phishing Sites

22 July 2026 at 16:00

Threat actors are using a new technique called β€œphantom squatting” to trick AI tools into directing users to phishing sites, according to researchers at Palo Alto Networks’ Unit 42.

Since AI models frequently hallucinate phony information, they sometimes point users to websites that don’t exist. Threat actors are now registering these AI-hallucinated domains and using them to host phishing sites.

Trust Nothing: Tips to Secure AI Tools and Agents

21 July 2026 at 16:00

So, you have some AI tools or are thinking about deploying them and want to know a bit about securing them.

You are not alone, but there are significant challenges due to the rapidly growing capabilities of AI, and the issues around new types of vulnerabilities we may not be used to thinking of. This is a very challenging area to attempt to secure, but I hope to point you in the right direction and set you up with some resources.

Report: Social Engineering Remains a Central Part of AI-assisted Attacks

15 July 2026 at 09:00

Threat actors continue to rely on social engineering as AI is incorporated into their attacks, according to ESET’s Threat Report for the first half of 2026.

ESET’s Director of Threat Prevention Labs, JiΕ™Γ­ KropÑč, stated, β€œRather than relying on entirely new methods and tools, attackers are quickly adapting established techniques to new platforms, technologies, and user behaviors. The number of AI skills within this new ecosystem is growing rapidly as we speak, further expanding the attack surface.”

Scammers Can Use AI Tools to Pinpoint Your Location Based on a Photo

14 July 2026 at 09:00

Scammers can use AI tools to find your location in photos you post to social media, according to researchers at McAfee. This information can then be used in targeted social engineering attacks. The researchers found that free AI models can correctly identify a photo’s location with around 90% accuracy.

Prompt Injection and the Rise of Agentic Risk

9 July 2026 at 09:00

Boxers will often say, the punches that hurt the most aren’t the ones which are thrown with the most force, but the ones they didn’t see coming. I think the same is true in cybersecurity. It’s not the most advanced technically efficient, 0-day utilizing attacks thatΒ have the biggest impact, but rather those quiet ones. With no malware or suspicious login at three in the morning from an IP address in a country your company has never done business with. No alert fires. No dashboard turns red.

2026 Phishing by Industry Benchmarking Report: Findings on Human Risk

7 July 2026 at 09:00

Every year, KnowBe4 analyzes millions of simulated phishing tests to measure one thing: how likely is your workforce to fall for a phishing attack? The results, published in the 2026 Phishing by Industry Benchmarking Report, paint a clear picture of where human risk concentrates β€” and what organizations can do about it.

Phishing Exposes Employee Data at 86% of Fortune 100 Companies

1 July 2026 at 12:00

A new report from SpyCloud has found that phishing attacks have exposed employee data at 86% of Fortune 100 companies over the past 12 months, with the technology, airlineΒ and automotive sectors being hit the hardest. The researchers also found that 78% of organizations experienced an increase in phishing volume over the past year.

❌
❌