❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 22 July 2026KnowBe4 Security

Attackers Exploit AI Hallucinations to Send Users to Phishing Sites

22 July 2026 at 16:00

Threat actors are using a new technique called β€œphantom squatting” to trick AI tools into directing users to phishing sites, according to researchers at Palo Alto Networks’ Unit 42.

Since AI models frequently hallucinate phony information, they sometimes point users to websites that don’t exist. Threat actors are now registering these AI-hallucinated domains and using them to host phishing sites.

Warning: ARToken Phishing Kit Automates BEC Attacks

22 July 2026 at 12:00

Researchers at Cisco Talos are tracking a sophisticated phishing-as-a-service operator panel called β€œARToken” that’s built on the EvilTokens phishing platform. ARToken focuses on targeted social engineering attacks, allowing operators to customize phishing attempts for each victim.

Yesterday β€” 21 July 2026KnowBe4 Security
Before yesterdayKnowBe4 Security

Report: Social Engineering Remains a Central Part of AI-assisted Attacks

15 July 2026 at 09:00

Threat actors continue to rely on social engineering as AI is incorporated into their attacks, according to ESET’s Threat Report for the first half of 2026.

ESET’s Director of Threat Prevention Labs, JiΕ™Γ­ KropÑč, stated, β€œRather than relying on entirely new methods and tools, attackers are quickly adapting established techniques to new platforms, technologies, and user behaviors. The number of AI skills within this new ecosystem is growing rapidly as we speak, further expanding the attack surface.”

Scammers Can Use AI Tools to Pinpoint Your Location Based on a Photo

14 July 2026 at 09:00

Scammers can use AI tools to find your location in photos you post to social media, according to researchers at McAfee. This information can then be used in targeted social engineering attacks. The researchers found that free AI models can correctly identify a photo’s location with around 90% accuracy.

Your KnowBe4 Fresh Compliance Plus Content Updates from June 2026

13 July 2026 at 09:30

Fran Roberts - Studios General Manager, KnowBe4

This is my first message to you as KnowBe4's new Studios General Manager, and I am excited to introduce myself. Drawing on over two decades of experience in creative and AI-driven content leadership, I believe immersive, well-crafted learning is the most effective way to build a strong compliance culture.

Your KnowBe4 Fresh Content Updates from June 2026

10 July 2026 at 10:00

Fran Roberts - Studios General Manager, KnowBe4

I am thrilled to be writing my first message to you as KnowBe4's new Studios General Manager. I joined KnowBe4 because I believe that one of the most impactful areas for next-level storytelling is in security awareness β€” content that genuinely changes behavior and protects people.

Threat Actor Uses Phishing to Breach Orgs for Ransomware Gangs

10 July 2026 at 09:00

An initial access broker associated with the Payouts King ransomware group is using Microsoft Teams phishing to deploy a malicious Microsoft Edge web browser extension, according to researchers at Zscaler. Once the hackers have a foothold within an organization, they sell the access to the ransomware gang to conduct follow-on attacks.

Invoice Phishing Attacks Are Abusing the Shop App

9 July 2026 at 16:00

Threat actors are abusing Shop, a legitimate app developed by Shopify, to launch phishing attacks, according to researchers at Gen Digital. Shop is used for making purchases and tracking orders, but threat actors are exploiting the platform to generate in-app notifications for phony invoices.

2026 Phishing by Industry Benchmarking Report: Findings on Human Risk

7 July 2026 at 09:00

Every year, KnowBe4 analyzes millions of simulated phishing tests to measure one thing: how likely is your workforce to fall for a phishing attack? The results, published in the 2026 Phishing by Industry Benchmarking Report, paint a clear picture of where human risk concentrates β€” and what organizations can do about it.

INC Ransomware Gang Targets the Legal Sector

3 July 2026 at 09:00

The INC ransomware-as-a-service (RaaS) operation has grown into one of the premier ransomware offerings, claiming hundreds of victims in 2026 alone, according to researchers at Acronis. The attackers target a broad range of industries, but have recently prioritized entities in the legal sector.

Phishing Exposes Employee Data at 86% of Fortune 100 Companies

1 July 2026 at 12:00

A new report from SpyCloud has found that phishing attacks have exposed employee data at 86% of Fortune 100 companies over the past 12 months, with the technology, airlineΒ and automotive sectors being hit the hardest. The researchers also found that 78% of organizations experienced an increase in phishing volume over the past year.

❌
❌