With inboxes increasingly well guarded, cybercriminals are turning to a more vulnerable front in their attacks against your digital workforce.
Reading view
Recruitment-Themed Phishing Campaign Targets Enterprise Users
Researchers at Zimperium are tracking widespread phishing campaigns that use Browser-in-the-Browser (BitB) attacks to trick users into handing over their enterprise credentials. The attackers impersonate real HR employees at major companies and target job seekers with extremely realistic interview processes.
New Phishing Kit Uses AI to Fully Automate Vishing Attacks
A new phishing kit is using generative AI to fully automate voice phishing (vishing) attacks, according to researchers at Group-IB.
The phishing platform, called “Balonx,” includes a module dubbed “CallFlow” that the researchers say “represents a fundamental evolution” in the phishing-as-a-service market. This module uses four commercial AI services to conduct the attacks: OpenAI’s GPT-4o-mini, ElevenLabs’s AI voice generator, OpenAI Voice, and OpenAI Whisper.
Hacking the Healers: New KnowBe4 Whitepaper Highlights Record Security Breaches in Healthcare
When an organization has a security breach, it can cause significant financial, reputational and logistical damage. But in healthcare, where patient lives are on the line, the consequences can be much more catastrophic.
KnowBe4’s latest whitepaper on healthcare cybersecurity, “Hacking the Healers: How the Digital Workforce Became Cybersecurity's Frontline,” examines how decentralized clinical operations, remote staff and autonomous AI agents have dissolved traditional network perimeters, leaving healthcare organizations and patient safety vulnerable to targeted cyberattacks.
Attackers Abuse Enterprise Collaboration Tools to Avoid Detection
Threat actors’ abuse of enterprise collaboration tools increased fourfold over the past twelve months, according to researchers at Palo Alto Networks’ Unit 42.
Warning: Replying to a “Wrong Number” Text Marks You as a Target for Scams
Attackers are using “wrong-number” texts to identify potential targets for scams, according to researchers at Malwarebytes.
These texts appear to be harmless messages meant for another person, such as “Are we still on for dinner tomorrow?” or “Where’s the PowerPoint?” Recipients often try to be helpful by replying to let the person know they’ve got the wrong number. This reply, however, informs the threat actor that the phone number is active and marks it for future scams.
Attackers Use Vishing Attacks to Distribute New Android Malware
Attackers are distributing a new Android malware called “WindRelay” via phone-based social engineering attacks, according to researchers at Group-IB. The attackers call the victims, impersonating bank employees and instruct them to install a malicious app. In one instance observed by Group-IB, the scammers carried out the entire attack in just thirteen minutes.
Report: AI Chatbots Are More Effective at Building Trust Than Human Scammers
A study has found that AI chatbots can be more effective at social engineering than human scammers, WIRED reports. The researchers looked at a form of romance scam commonly known as “pig butchering,” in which scammers spend weeks or months building a relationship with the victim before tricking them into sending money for a phony investment scheme.
Securing the Tip of the Spear: Guam’s Path to Human and AI Resilience
Securing the Tip of the Spear: Guam’s Path to Human and AI Resilience
As the Asia-Pacific and Japan (APJ) region continues its rapid digital acceleration, Guam stands at a unique strategic intersection. Serving as a critical hub for telecommunications, government services and regional defense, the island’s cybersecurity posture is no longer just a local concern, it is a cornerstone of regional stability.
Vietnam’s Cybersecurity Evolution: Classrooms to Digital Resilience
Navigating the Paradigm Shift in Human Risk Management
Vietnam has emerged as a cornerstone of the global digital economy, but this rapid digitization has come with a significant surge in sophisticated cyber threats. As the country transitions into a more mature technological landscape, the methods used to protect its most critical asset, the workforce, must also evolve. We are witnessing a pivotal move away from traditional, checkbox in-person training toward modern, automated and AI-driven digital resilience.
Warning: Vishing Attacks Open the Door to Ransomware Gangs
An initial access broker for ransomware gangs is targeting organizations with voice phishing (vishing) attacks through Microsoft Teams, according to researchers at Zscaler’s ThreatLabz.
Introducing Real-Time Coaching in KnowBe4’s AI-Native Security Awareness Training
Attackers are getting smarter. AI is making social engineering more convincing, more personalized, and harder to spot than ever before. Training the digital workforce, employees and agents, to recognize threats is necessary, but even the most security-conscious users can still make a mistake at the moment of risk.
Your KnowBe4 Fresh Compliance Plus Content Updates from July 2026
Fran Roberts - Studios General Manager, KnowBe4
Bribery and corruption do not always look the way people expect. They rarely show up as a suitcase of cash or an obvious quid pro quo. More often, they arrive as a favor, a gift, a "just this once" that feels trivial in the moment and catastrophic in hindsight. That gap between perception and reality is where training matters most.