❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayKnowBe4 Security

The Blind Spot: How β€œBulletproof” Phishing Redirectors Slip Past SEGs

10 August 2026 at 12:00

By Shikhar Dalela and Jeewan Singh Jalal

The operators named the kit themselves.

Buried inside compromised legitimate websites, the hidden staging directory is sometimes literally called β€œ/.bulletproof”, and the PHP session cookie the kit sets on every visitor is named β€œbp_redir_sess.” The β€œbp” stands for bulletproof, which is an unusual degree of candor from a threat actor whose entire design philosophy is concealment.

Inside the OS-Aware Phishing Kit Profiling Your Device

30 July 2026 at 09:00

Lead Analysts: Prabhakaran Ravichandhiran and Jeewan Singh Jalal

Most phishing attacks pick a target and commit to a tactic. This one picks the tactic based on the target, which happens dynamically, per device, in milliseconds, without the victim ever knowing a decision was made.

Cybercriminals Are Targeting the FIFA World Cup 2026

2 July 2026 at 09:00

Lead Analysts: Jeewan Singh Jalal and Louis Tiley

KnowBe4 ThreatLabs tracked phishing campaign activity from the first week of April through June 22, 2026 β€” covering the pre-tournament build-up, tournament kickoff and the first twelve days of live match play. Our latest intelligence adds crucial mid-tournament telemetry (June 15-22), a newly identified reply-back campaign track and additional infrastructure intelligence.

❌
❌