KnowBe4, Friday, November 7th, 2025
Phishing Emails Use Invisible Hyphens To Avoid Detection
A phishing campaign is using invisible characters to evade security filters, according to Jan Kopriva at the SANS Internet Storm Center.
more →
246 articles · page 4 of 5
KnowBe4, Friday, November 7th, 2025
A phishing campaign is using invisible characters to evade security filters, according to Jan Kopriva at the SANS Internet Storm Center.
more →
KnowBe4, Tuesday, October 28th, 2025
Block Attackers Who Abuse Grok to Spread Phishing Links
more →
KnowBe4, Monday, October 27th, 2025
This story happened a decade ago, when I was working at a Fortune 10 company. 'Smartest' is subjective, but most of my former coworkers and external customers agreed the guy involved in this story was seen as the 'smartest' guy around.
more →
KnowBe4, Thursday, October 23rd, 2025
A phishing campaign is impersonating LastPass and Bitwarden with phony breach notifications, BleepingComputer reports.
more →
KnowBe4, Wednesday, October 22nd, 2025
Threat actors are abusing X's generative AI bot Grok to spread phishing links, according to researchers at ESET. The attackers achieve this by tricking Grok into thinking it's answering a question, and providing a link in its answer.
more →
KnowBe4, Wednesday, October 22nd, 2025
Cybernews warns that threat actors will likely take advantage of the recent AWS outage to launch phishing attacks against affected users.
more →
KnowBe4, Monday, October 20th, 2025
Ransomware is the gift that keeps on giving. and taking. I've been tracking ransomware for almost nine years now, and I've seen it progress from simple and annoying malware to an organization-ending threat for many.
more →
KnowBe4, Thursday, October 16th, 2025
Google's Mandiant has published guidance on defending against an ongoing wave of social engineering attacks targeting organizations' Salesforce instances.
more →
KnowBe4, Monday, October 13th, 2025
We've come a long way. We've deconstructed the problem, explored the complexity of humans, and laid out a strategic framework and a practical map-all of which can be explored in more detail in our Human Risk Management (HRM) whitepaper.
more →
KnowBe4, Monday, October 13th, 2025
Deepfakes are easier to create than ever and are being used to attack organizations, families and individuals.
more →
KnowBe4, Friday, October 10th, 2025
The conversation about AI in cybersecurity is missing the point. While the industry has been focused on the emergence of AI-generated phishing emails, perhaps a far more profound shift has been somewhat ignored.
more →
KnowBe4, October 1,2025
The calendar has flipped into October, so now it's time to let the Cybersecurity Awareness Month games begin!
more →
KnowBe4, September 30,2025
Law firms really are under constant pressure to meet tight deadlines, maintain client confidentiality and protect privileged communications.
more →
KnowBe4, Thursday, September 25th, 2025
Researchers at Varonis warn of a new phishing automation platform called "SpamGPT" that 'combines the power of generative AI with a full suite of email campaign tools.'
more →
KnowBe4, Thursday, September 25th, 2025
Attackers are abusing AI-powered development platforms like Lovable, Netlify and Vercel to create and host captcha challenge websites as part of phishing campaigns, according to researchers at Trend Micro.
more →
KnowBe4, Tuesday, September 23rd, 2025
Protecting humans means protecting the tools humans use.
more →
KnowBe4, Tuesday, September 23rd, 2025
Hackread reports that attackers are abusing Google's AppSheet platform to send phishing emails.
more →
KnowBe4, September 19,2025
Let's be brutally honest. For years, our industry has been locked in a civil war. In one camp, the technologists have been building higher walls and smarter traps, arguing that the right AI-powered, next-gen firewall will solve all our problems.
more →
KnowBe4, September 18,2025
AI-assisted phishing attacks pose a significant and increasing threat to organizations, according to Matt Weidman, partner and vice president of Commercial Property & Casualty at USIA.
more →
KnowBe4, September 18,2025
North Korean hackers behind the 'Contagious Interview' campaign are using the ClickFix social engineering tactic to target job seekers with phony employment offers, according to researchers at SentinelOne.
more →
KnowBe4, September 16,2025
Shadow AI Threats Are Increasing. Here's How to Spot Them
more →
KnowBe4, September 15,2025
Protecting humans means protecting the tools humans use
more →
CyberheistNews, Wednesday, September 10th, 2025
One of the biggest enduring mysteries for me in cybersecurity is why most cybersecurity curricula don't teach secure coding to programmers.
more →
KnowBe4, Tuesday, September 9th, 2025
KnowBe4's new HRM framework guides organizations to transform employees into an active layer of defense through data-driven insights, cultural understanding and targeted interventions
more →
KnowBe4, Thursday, September 4th, 2025
Threat actors can now use AI tools to automate entire attack operations, according to a new report from Anthropic.
more →
KnowBe4, Wednesday, September 3rd, 2025
KnowBe4 launches its seventh resource kit for cybersecurity awareness month to empower individuals & organisations to "Secure Our World" with practical tools and training
more →
KnowBe4, Thursday, August 28th, 2025
KnowBe4 launches its seventh resource kit for cybersecurity awareness month to empower individuals & organizations to "Secure Our World" with practical tools and training
more →
KnowBe4, Friday, August 22nd, 2025
Cybercriminals are increasingly abusing AI-assisted website generators to quickly craft convincing phishing sites, according to researchers at Palo Alto Networks' Unit 42.
more →
KnowBe4, Friday, August 22nd, 2025
Below is an example of a sophisticated survey scam phishing email that KnowBe4's Threat Lab team has been monitoring as discussed in 'The Hidden Cost of "Free" Gifts: How Survey Scams Are Evolving to Steal Financial Data'.
more →
KnowBe4, Friday, August 22nd, 2025
You've probably seen them: enticing online offers for free products from brands you trust, like a Yeti beach chair from Costco or an emergency car kit from AAA.
more →
KnowBe4, Thursday, August 21st, 2025
Social engineering attacks are a growing threat to operational technology (OT) environments, Industrial Cyber reports.
more →
KnowBe4, Thursday, August 21st, 2025
In this series, we first explored the psychology that makes HR phishing so effective, then showcased the real-world lures attackers use to trick your employees. Now, we're going under the hood to answer the critical question: How do these attacks technically bypass security defenses?
more →
KnowBe4, Thursday, August 21st, 2025
Phishing attacks impersonating HR are on the rise. Between January 1 - March 31, 2025, our Threat Lab team observed a 120% surge in these attacks reported via our PhishER product versus the previous three months. These attacks have remained at elevated levels since peaking in February.
more →
KnowBe4, Wednesday, August 20th, 2025
We all trust HR - or at least we do when we think they're emailing us! Data from KnowBe4's HRM+ platform reveals that phishing simulations with internal subject lines dominate the list of most-clicked templates in 2025.
more →
KnowBe4, Tuesday, August 19th, 2025
AI is getting eerily good at mimicking Iron Man's Jarvis: these so-called "OS agents" can now watch your screen, click buttons, fill out forms and manage apps on your computer or phone-all on their own.
more →
KnowBe4, Friday, August 15th, 2025
The Better Business Bureau (BBB) has warned that scammers are targeting high-profile employees and influencers with fake invitations to appear as a guest on popular celebrity podcasts.
more →
KnowBe4, Thursday, August 7th, 2025
The FBI has issued an advisory warning that scammers are distributing QR code phishing (quishing) links via unsolicited packages sent by snail mail.
more →
KnowBe4, Thursday, August 7th, 2025
I hear about a ton of similar-sounding scam calls, where the scammer is pretending to be from a service you use (or used), offering you a substantial monthly discount (30% or more) if you pay some fee ahead of time.
more →
KnowBe4, Wednesday, August 6th, 2025
Cybersecurity incidents nearly tripled in the first half of 2025, jumping from 6% in the second half of 2024 to 17% in 2025, according to a new report from LevelBlue.
more →
KnowBe4, Wednesday, August 6th, 2025
In today's world, cyberattacks are a constant threat. While technical defenses are crucial, people often remain the easiest attack vector for cybercriminals.
more →
KnowBe4, Tuesday, August 5th, 2025
A phishing campaign is targeting Instagram users with phony notifications about failed login attempts, according to researchers at Malwarebytes. Notably, the emails contain "mailto" links rather than traditional URLs, which help the phishing messages avoid being flagged by security filters.
more →
KnowBe4, Tuesday, August 5th, 2025
ClickFix attacks have been around for decades; only the name is new. ClickFix attacks use social engineering to trick users into clicking on buttons and links that the user is told are needed so their browser or computer can perform some desired action.
more →
KnowBe4, Monday, August 4th, 2025
There is no other way to say it clearer, social engineering is going to be a lot, lot worse soon and far more successful than it is today. And that's saying a lot. It's already pretty bad.
more →
KnowBe4, Monday, August 4th, 2025
Attackers are using Microsoft Teams calls to trick users into installing the Matanbuchus malware loader, which frequently precedes ransomware deployment, according to researchers at Morphisec.
more →
KnowBe4, Thursday, July 31st, 2025
Most Microsoft 365 users aren't aware of this recently growing serious email threat vector.
more →
KnowBe4, Wednesday, July 30th, 2025
A global retail and wholesale company transformed their security posture after implementing KnowBe4's Phish Alert Button (PAB) and security awareness training, achieving an astonishing 50-fold increase in user reporting of phishing attacks.
more →
KnowBe4, Tuesday, July 29th, 2025
I've been following ransomware since the first one, the AIDS Cop Trojan, was released in December 1989. It locked up victim computers and asked for $300 to be sent to a Panama P.O. Box. A lot has changed since then.
more →
KnowBe4, Tuesday, July 29th, 2025
Managing the security gap between your technical defenses and user behavior just got easier!
more →
KnowBe4, Sunday, July 27th, 2025
Bob Fabien wrote on X: "While some are still paying over a grand for AI courses, the biggest players are giving away high-value resources at no cost. From prompt engineering to agent frameworks, it is all here."
more →
KnowBe4, Friday, July 25th, 2025
Ransomware attacks increased by 63% year-over-year in the second quarter of 2025, with a total of 276 publicly disclosed incidents, according to a new report from BlackFog.
more →