Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Shadow AI: The New Frontier of Shadow IT

As a CISO advisor, I am observing a familiar pattern gaining a new, critical dimension. What we historically identified as "Shadow IT", the use of unapproved SaaS and tools, is rapidly evolving into "Shadow AI." Employees are increasingly leveraging AI bots for drafting, analysis, code generation and strategic decision-making.

Warning: Vishing Attacks Open the Door to Ransomware Gangs

An initial access broker for ransomware gangs is targeting organizations with voice phishing (vishing) attacks through Microsoft Teams, according to researchers at Zscaler’s ThreatLabz. “From January through June 2026, ThreatLabz examined a cluster of related campaigns that used Microsoft Teams vishing and Quick Assist for initial access, followed by PowerShell-based staging,” the researchers write.

Why Securing AI Agents Is More Critical Than Ever

AI agents offer unprecedented capabilities, speed, automation, deep context, and hyper-personalization, that will transform how we work. However, these same capabilities make AI agents significantly more dangerous than traditional software when hijacked by cybercriminals. You simply cannot rely on yesterday's risk management playbooks to handle today's AI-driven threats.

Report: Employees Are Overconfident in Their Ability to Spot Scams

A survey from Trustmi found that most employees believe they’d be able to spot a social engineering attack, but those same employees still rely primarily on outdated guidance to spot red flags. Generative AI has given attackers the ability to craft extremely convincing, error-free phishing emails.

Why You Can't Arrest Your Way Out of Youth Cybercrime

Sir Robert Peel defined good policing as "the absence of crime and disorder, and not the visible evidence of police action in dealing with them." Gregory Francis of the Netherlands National Police quoted this at the INTERCOP conference held at INTERPOL headquarters, and this principle framed the entire event. Young people are increasingly drawn into cybercrime through the platforms where they already spend their time — Discord, Telegram and gaming servers.

The Blind Spot: How "Bulletproof" Phishing Redirectors Slip Past SEGs

By Shikhar Dalela and Jeewan Singh Jalal The operators named the kit themselves. Buried inside compromised legitimate websites, the hidden staging directory is sometimes literally called “/.bulletproof”, and the PHP session cookie the kit sets on every visitor is named “bp_redir_sess.” The “bp” stands for bulletproof, which is an unusual degree of candor from a threat actor whose entire design philosophy is concealment.

Introducing Real-Time Coaching in KnowBe4's AI-Native Security Awareness Training

Attackers are getting smarter. AI is making social engineering more convincing, more personalized, and harder to spot than ever before. Training the digital workforce, employees and agents, to recognize threats is necessary, but even the most security-conscious users can still make a mistake at the moment of risk. Workforce risk is a behavior change problem, and effective behavior change requires knowledge, pressure-tested application and real-time reinforcement all working together.

AI Did Not Invent Social Engineering But It Did Industrialize It.

This year National Social Engineering Day falls on Aug. 6. This day is designed to give us an opportunity to remind people that cybercriminals do not always need sophisticated malware, an undisclosed vulnerability or a dark room filled with glowing monitors, sometimes, all they need is a good story. Social engineering existed long before computers. Confidence tricks, impersonation, false authority and appeals to greed or fear have been used for centuries.

Agent Risk Manager Moves into Early Access

When we first introduced Agent Risk Manager, the response was clear: many security teams are actively looking for a way to secure the AI agents already running in their environment and how they can confidently adopt AI across their organization. AI agents now operate inside organizations with real access to email, files and business systems, often with little visibility for the teams responsible for securing them. That’s exactly the problem Agent Risk Manager was built to solve.