Normal view

There are new articles available, click to refresh the page.
Today — 14 September 2026KnowBe4 Security

Social Engineering Campaign Uses Phony NDAs to Avoid Detection

14 September 2026 at 12:00

Researchers at Gen Digital are tracking a sophisticated social engineering campaign that’s using phony NDA documents to trick employees into moving the conversation to WhatsApp and personal email accounts. The attackers targeted an employee at Gen itself, but the employee recognized that it was a scam and played along to see what the attackers would do.

Warning: “Slop Squatting” Directs AI Users to Phishing Pages

14 September 2026 at 09:00

Threat actors are increasingly leveraging AI hallucinations to plant phishing links and other malicious content in AI output, IEEE Spectrum reports. Large language models (LLMs) sometimes fabricate information, including web domains, when answering users’ questions. Attackers are registering these hallucinated web domains to host phishing pages.

Before yesterdayKnowBe4 Security

Phishing Campaign Targets Employees with Malicious SVG Files

11 September 2026 at 09:00

Researchers at INKY observed a major phishing campaign that used SVG (Scalable Vector Graphics) image files to deliver malicious JavaScript. While abuse of SVG files isn’t new, INKY says their use in phishing campaigns has exploded over the past year.

Recruitment-Themed Phishing Campaign Targets Enterprise Users

2 September 2026 at 16:30

Researchers at Zimperium are tracking widespread phishing campaigns that use Browser-in-the-Browser (BitB) attacks to trick users into handing over their enterprise credentials. The attackers impersonate real HR employees at major companies and target job seekers with extremely realistic interview processes.

New Phishing Kit Uses AI to Fully Automate Vishing Attacks

2 September 2026 at 12:00

A new phishing kit is using generative AI to fully automate voice phishing (vishing) attacks, according to researchers at Group-IB.

The phishing platform, called “Balonx,” includes a module dubbed “CallFlow” that the researchers say “represents a fundamental evolution” in the phishing-as-a-service market. This module uses four commercial AI services to conduct the attacks: OpenAI’s GPT-4o-mini, ElevenLabs’s AI voice generator, OpenAI Voice, and OpenAI Whisper.

Hacking the Healers: New KnowBe4 Whitepaper Highlights Record Security Breaches in Healthcare

2 September 2026 at 07:00

When an organization has a security breach, it can cause significant financial, reputational and logistical damage. But in healthcare, where patient lives are on the line, the consequences can be much more catastrophic.

KnowBe4’s latest whitepaper on healthcare cybersecurity, “Hacking the Healers: How the Digital Workforce Became Cybersecurity's Frontline,” examines how decentralized clinical operations, remote staff and autonomous AI agents have dissolved traditional network perimeters, leaving healthcare organizations and patient safety vulnerable to targeted cyberattacks.

Warning: Replying to a “Wrong Number” Text Marks You as a Target for Scams

28 August 2026 at 16:00

Attackers are using “wrong-number” texts to identify potential targets for scams, according to researchers at Malwarebytes.

These texts appear to be harmless messages meant for another person, such as “Are we still on for dinner tomorrow?” or “Where’s the PowerPoint?” Recipients often try to be helpful by replying to let the person know they’ve got the wrong number. This reply, however, informs the threat actor that the phone number is active and marks it for future scams.

Attackers Use Vishing Attacks to Distribute New Android Malware

26 August 2026 at 09:00

Attackers are distributing a new Android malware called “WindRelay” via phone-based social engineering attacks, according to researchers at Group-IB. The attackers call the victims, impersonating bank employees and instruct them to install a malicious app. In one instance observed by Group-IB, the scammers carried out the entire attack in just thirteen minutes.

Report: AI Chatbots Are More Effective at Building Trust Than Human Scammers

24 August 2026 at 16:00

A study has found that AI chatbots can be more effective at social engineering than human scammers, WIRED reports. The researchers looked at a form of romance scam commonly known as “pig butchering,” in which scammers spend weeks or months building a relationship with the victim before tricking them into sending money for a phony investment scheme.

Securing the Tip of the Spear: Guam’s Path to Human and AI Resilience

21 August 2026 at 04:00

Securing the Tip of the Spear: Guam’s Path to Human and AI Resilience

As the Asia-Pacific and Japan (APJ) region continues its rapid digital acceleration, Guam stands at a unique strategic intersection. Serving as a critical hub for telecommunications, government services and regional defense, the island’s cybersecurity posture is no longer just a local concern, it is a cornerstone of regional stability.

Vietnam’s Cybersecurity Evolution: Classrooms to Digital Resilience

19 August 2026 at 09:00

Navigating the Paradigm Shift in Human Risk Management

Vietnam has emerged as a cornerstone of the global digital economy, but this rapid digitization has come with a significant surge in sophisticated cyber threats. As the country transitions into a more mature technological landscape, the methods used to protect its most critical asset, the workforce, must also evolve. We are witnessing a pivotal move away from traditional, checkbox in-person training toward modern, automated and AI-driven digital resilience.

Report: Employees Are Overconfident in Their Ability to Spot Scams

12 August 2026 at 16:00

A survey from Trustmi found that most employees believe they’d be able to spot a social engineering attack, but those same employees still rely primarily on outdated guidance to spot red flags. Generative AI has given attackers the ability to craft extremely convincing, error-free phishing emails.

❌
❌