|
By KnowBe4 Team
Researchers at Lexfo are tracking three sophisticated phishing kits that were built using open-source components, primarily based on the publicly available adversary-in-the-middle (AiTM) attack framework “Evilginx.” The phishing kits are designed to proxy “live Microsoft 365 authentication sessions to capture session cookies and OAuth tokens in real time, bypassing MFA entirely.” The kits also use AI to generate personalized phishing lures with a variety of different delivery metho
|
By Fran Roberts
I've spent my career figuring out what makes content stick, from early work for brands like Apple and onward across two decades across film, animation and generative AI. Different tools every few years, same question underneath. What makes someone lean in instead of tuning out? Turns out that question sits at the center of a problem the security industry has wrestled with for 15 years. How do you build a culture where people actually change how they behave? Not comply. Not click "complete." Change.
|
By KnowBe4 Team
Apple is warning users to be wary of unsolicited FaceTime calls amidst a wave of scams impersonating Apple Support, Malwarebytes reports. The scammers inform the user that there’s been fraudulent activity or a technical problem associated with their account, and trick the victim into handing over payment card details, banking credentials or Apple ID logins.
|
By KnowBe4 Threat Lab
Most phishing attacks pick a target and commit to a tactic. This one picks the tactic based on the target, which happens dynamically, per device, in milliseconds, without the victim ever knowing a decision was made.
|
By Javvad Malik
In business, calling something a dinosaur is meant to suggest it is slow, outdated and overdue for extinction. Which is unfair to dinosaurs, who enjoyed one of the most successful runs in the history of life. Here is what people think they mean when they use the word. Lumbering. Doomed. Obsolete. A fat target waiting for the meteor. They imagine a tar pit. They imagine extinction. They picture something huge and slow, magnificently unsuited to the world it finds itself in.
Future-proofing organizations in the face of AI requires a unified defense strategy that secures both the human workforce and autonomous AI agents. One of the key requirements is shifting security cultures from reactive compliance to proactive, measurable behavioral change. As artificial intelligence evolves from a supporting tool into an autonomous digital workforce, organizations must adapt their defense frameworks to mitigate both human and agentic risks.
|
By KnowBe4 Team
Fifty-three percent of organizations have had an executive or employee impersonated in targeted social engineering attacks over the past year, according to a new report from Outtake. Just over half of this impersonation activity took place on social media platforms using fake profiles, followed by video platforms.
|
By Haylea Reiner, MBA
When it comes to outbound email security, every organization operates under different operational constraints and security requirements. Some security teams prioritize in-app nudges and coaching to catch risky behavior the moment an email is drafted. Others want to avoid friction, particularly for executives, sales teams or mobile-first employees who rarely interact with desktop add-ins.
The recent developments surrounding vulnerabilities in major AI repositories like Hugging Face serve as a critical wake-up call for the cybersecurity community. As we accelerate toward an agentic future, the platforms we rely on for innovation are increasingly becoming the primary vectors for systemic risk.
|
By KnowBe4 Team
Researchers at ReliaQuest are tracking two new phishing toolkits that are designed to bypass multifactor authentication (MFA). The first tool, called “Jalisco,” is a device code phishing platform that pairs with AI-powered phishing-as-a-service platforms like EvilTokens to provide fresh OAuth codes in real time.
AI tools state false information with just as much credibility as the truth. Here’s what you need to know about AI hallucinations.
More summer screen time means more opportunities for gaming scammers. Watch out for fake "Free Robux" scams targeting kids online, and learn the easy red flags to teach your family today.
What is the single best piece of security advice? Pausing.
AI add-ons can automate everything from travel to banking—but are they opening backdoors to your private data? Here is what to look for before granting permissions.
What if you could build a complete, personalized security awareness course from a single prompt — in seconds? KnowBe4's AIDA Content Creation Agent does exactly that. Powered by our decade of AI innovation, it generates e-learning modules instantly — and goes far beyond basic content generation: Deepfake Face Injection — Insert real members of your team into training visuals using safe, consensual deepfake synthesis. Your people, your culture, your training.
Unexpected delivery texts are one of the most common smishing tricks out there. Here is why you should never click the link, and what to do instead!
Have you noticed a spike in sketchy job offers since starting your career search? Here is how automated bots turn your profile details against you, and the major red flags to watch out for.
POV: you finally found free cybersecurity training that doesn't make you want to fall asleep. CAPY offers bite-sized cyber safety lessons for your whole family. Under 4 minutes. No login. No cost. Just real tips that actually stick. Kids, parents, seniors — there's a path for everyone.
Creating urgency, triggering reactions, and bypassing logic—sound familiar? Whether it's a 3 a.m. meow or a fake security alert, the tactics are the same. Don't be the catch of the day. Learn to spot the "phish" before you click!
Think phishing is just a corporate email issue? Think again. Scammers use compromised accounts and lookalike profiles on social media to target you where you least expect it. Stay sharp, verify outside the app, and don't get reeled in by sketchy links!
|
By KnowBe4
Your employees are your largest attack surface. For too long the human component of cybersecurity has been neglected, leaving employees vulnerable and creating an easy target for cybercriminals to exploit. But your users want to do the right thing. Rather than a hurdle to be overcome, organizations need to think of their employee base as an asset, once properly equipped.
|
By KnowBe4
Want to read this bestseller? Register now for your free (instant 240-page PDF download) Cyberheist e-book and learn how to not be the next victim! Cyberheist was fully updated and written for the IT team and owners / management of Small and Medium Enterprise, which includes non-profits, local and state government, churches, and any other organization with more than a few thousand dollars in their bank operating account.
|
By KnowBe4
Hackers have become increasingly savvy at launching specialized attacks that target your users by tapping into their fears, hopes, and biases to get access to their data. Cybersecurity is not just a technological challenge, but increasingly a social and behavioral one. People, no matter their tech savviness, are often duped by social engineer scams, like CEO fraud, because of their familiarity and immediacy factors.
|
By KnowBe4
Spear phishing emails remain a top attack vector for cybercriminals, yet most companies still don't have an effective strategy to stop them. This enormous security gap leaves you open to business email compromise, session hijacking, ransomware and more. Don't get caught in a phishing net! Learn how to avoid having your end users take the bait. Roger Grimes, KnowBe4's Data-Driven Defense Evangelist, will cover techniques you can implement now to minimize cybersecurity risk due to phishing and social engineering attacks.
|
By KnowBe4
Anything but 100% completion on your employee compliance training is often more than simply frustrating. Compliance audits and regulatory requirements can make anything less than 100% feel like a failure. But, getting compliance on your compliance training is possible! Organizations have struggled for years with getting everyone to complete their required compliance training. This puts organizations at risk of more incidents occurring, fines or reputational damage if an employee is non-compliant.
|
By KnowBe4
All multi-factor authentication (MFA) mechanisms can be compromised, and in some cases, it's as simple as sending a traditional phishing email. Want to know how to defend against MFA hacks? This eBook covers over a dozen different ways to hack various types of MFA and how to defend against those attacks.
- July 2026 (38)
- June 2026 (39)
- May 2026 (39)
- April 2026 (28)
- March 2026 (50)
- February 2026 (26)
- January 2026 (22)
- December 2025 (31)
- November 2025 (31)
- October 2025 (42)
- September 2025 (26)
- August 2025 (24)
- July 2025 (17)
- June 2025 (26)
- May 2025 (24)
- April 2025 (31)
- March 2025 (31)
- February 2025 (24)
- January 2025 (24)
- December 2024 (21)
- November 2024 (29)
- October 2024 (37)
- September 2024 (27)
- August 2024 (33)
- July 2024 (41)
- June 2024 (32)
- May 2024 (38)
- April 2024 (34)
- March 2024 (38)
- February 2024 (42)
- January 2024 (46)
- December 2023 (41)
- November 2023 (33)
- October 2023 (45)
- September 2023 (49)
- August 2023 (49)
- July 2023 (42)
- June 2023 (45)
- May 2023 (48)
- April 2023 (44)
- March 2023 (14)
- February 2023 (3)
- January 2023 (4)
- December 2022 (3)
KnowBe4 is the provider of the world's largest integrated platform for security awareness training combined with simulated phishing attacks. Join our more than 56,000 customers to manage the continuing problem of social engineering.
The KnowBe4 platform is user-friendly and intuitive, and powerful. It was built to scale for busy IT pros that have 16 other fires to put out. Our goal was to design a full-featured, yet easy-to-use platform.
Find Out How Effective Our Security Awareness Training Is:
- Train Your Users: The world’s largest library of security awareness training content. Automated training campaigns with scheduled reminder emails.
- Phish Your Users: Best-in-class, fully automated simulated phishing attacks, thousands of templates with unlimited usage, and community phishing templates.
- See The Results: Enterprise-strength reporting, showing stats and graphs for both training and phishing, ready for management. Show the great ROI!
Human Error. Conquered.