❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 16 September 2026KnowBe4 Security

Alert: AI is Accelerating Targeted Social Engineering Attacks

16 September 2026 at 12:00

AI tools are drastically improving the speed of the reconnaissance stage of targeted social engineering attacks, according to researchers at ESET. Attackers can use these tools to trawl the internet for publicly available information about potential victims, and incorporate this information into personalized spear phishing attacks.

Warning: New Phishing Kit Targets Hundreds of Organizations

16 September 2026 at 09:00

Attackers have used a new phishing platform called β€œBigBear 2.0” to target hundreds of organizations across more than forty countries, according to researchers at CloudSEK. In about 10% of cases, the phishing attacks were able to bypass multifactor authentication.

Yesterday β€” 15 September 2026KnowBe4 Security

Phishing Emails Use New Technique to Bypass Microsoft 365 Security Filters

15 September 2026 at 12:00

Threat actors are using phishing emails with blank SMTP sender fields to bypass Microsoft 365 security filters, according to researchers at ReliaQuest.

Microsoft 365 Exchange Online uses a feature called β€œRejectDirectSend” to block unauthenticated Direct Send emails from an organization’s trusted domain. If an attacker omits the domain field from these emails, however, RejectDirectSend will no longer block the messages. Attackers can therefore exploit this technique to impersonate internal users.

Before yesterdayKnowBe4 Security

Social Engineering Campaign Uses Phony NDAs to Avoid Detection

14 September 2026 at 12:00

Researchers at Gen Digital are tracking a sophisticated social engineering campaign that’s using phony NDA documents to trick employees into moving the conversation to WhatsApp and personal email accounts. The attackers targeted an employee at Gen itself, but the employee recognized that it was a scam and played along to see what the attackers would do.

Warning: β€œSlop Squatting” Directs AI Users to Phishing Pages

14 September 2026 at 09:00

Threat actors are increasingly leveraging AI hallucinations to plant phishing links and other malicious content in AI output, IEEE Spectrum reports. Large language models (LLMs) sometimes fabricate information, including web domains, when answering users’ questions. Attackers are registering these hallucinated web domains to host phishing pages.

FBI Alert: OAuth Consent Phishing is Targeting Users of Messaging Apps

11 September 2026 at 16:00

The U.S. Federal Bureau of Investigation (FBI) has issued an advisory warning of a wave of OAuth consent phishing attacks targeting β€œprominent victims, their family members, and personal acquaintances.”

OAuth phishing is an increasingly popular social engineering tactic that tricks users into granting access to their accounts without handing over their passwords.

Survey: Companies Cite Phishing as their Top AI-Enabled Fraud Concern

11 September 2026 at 12:00

A recent survey from Experian found that 60% of companies report fraud losses that are β€œsomewhat or significantly higher” than in previous years, with a majority of respondents citing AI-generated phishing attacks as their top AI-related fraud concern.

Phishing Campaign Targets Employees with Malicious SVG Files

11 September 2026 at 09:00

Researchers at INKY observed a major phishing campaign that used SVG (Scalable Vector Graphics) image files to deliver malicious JavaScript. While abuse of SVG files isn’t new, INKY says their use in phishing campaigns has exploded over the past year.

Recruitment-Themed Phishing Campaign Targets Enterprise Users

2 September 2026 at 16:30

Researchers at Zimperium are tracking widespread phishing campaigns that use Browser-in-the-Browser (BitB) attacks to trick users into handing over their enterprise credentials. The attackers impersonate real HR employees at major companies and target job seekers with extremely realistic interview processes.

New Phishing Kit Uses AI to Fully Automate Vishing Attacks

2 September 2026 at 12:00

A new phishing kit is using generative AI to fully automate voice phishing (vishing) attacks, according to researchers at Group-IB.

The phishing platform, called β€œBalonx,” includes a module dubbed β€œCallFlow” that the researchers say β€œrepresents a fundamental evolution” in the phishing-as-a-service market. This module uses four commercial AI services to conduct the attacks: OpenAI’s GPT-4o-mini, ElevenLabs’s AI voice generator, OpenAI Voice, and OpenAI Whisper.

Hacking the Healers: New KnowBe4 Whitepaper Highlights Record Security Breaches in Healthcare

2 September 2026 at 07:00

When an organization has a security breach, it can cause significant financial, reputationalΒ and logistical damage. But in healthcare, where patient lives are on the line, the consequences can be much more catastrophic.

KnowBe4’s latest whitepaper on healthcare cybersecurity, β€œHacking the Healers: How the Digital Workforce Became Cybersecurity's Frontline,” examines how decentralized clinical operations, remote staff and autonomous AI agents have dissolved traditional network perimeters, leaving healthcare organizations and patient safety vulnerable to targeted cyberattacks.

New Phishing Kit Gives Threat Actors Live View Into Attacks

28 August 2026 at 09:00

A new phishing platform called β€œJWR” gives attackers real-time control over social engineering attacks, according to researchers at Cisco Talos. The kit livestreams the phishing page to the attacker as the victim is entering information, allowing the attacker to steer the victim’s experience and maximize the damage.

❌
❌