Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

FBI Alert: OAuth Consent Phishing is Targeting Users of Messaging Apps

The U.S. Federal Bureau of Investigation (FBI) has issued an advisory warning of a wave of OAuth consent phishing attacks targeting “prominent victims, their family members, and personal acquaintances.” OAuth phishing is an increasingly popular social engineering tactic that tricks users into granting access to their accounts without handing over their passwords.

Survey: Companies Cite Phishing as their Top AI-Enabled Fraud Concern

A recent survey from Experian found that 60% of companies report fraud losses that are “somewhat or significantly higher” than in previous years, with a majority of respondents citing AI-generated phishing attacks as their top AI-related fraud concern. “Businesses identify AI-generated phishing as the most common AI-enabled fraud risk at 53%,” the report says.

Direct Send: How Attackers Weaponize Your Infrastructure Against You

An employee at your company receives an email from hr@yourcompany.com. The domain matches. There is no warning banner. The message asks them to review a payment approval document. They click. That email was never sent by your HR team. An attacker sent it, and your own Microsoft email infrastructure delivered it, with no password and no credentials required.

The Workforce Has a Blind Spot, and It's Ringing

With inboxes increasingly well guarded, cybercriminals are turning to a more vulnerable front in their attacks against your digital workforce. Voice is the fastest-growing attack vector, and it’s because it’s dangerously effective. According to Verizon’s 2026 Data Breach Investigation Report, phone-centric attacks are 40% more successful than traditional email-based phishing.

How The Sack Company Solved "Click Happy" Employees & Reduced Risk Scores with KnowBe4

The Sack Company implemented KnowBe4 to eliminate "click happy" employee behavior and streamline phishing campaign management across its family of companies. By leveraging KnowBe4’s AI Defense Agents (AIDA) and gamified phishing security awareness training, The Sack Company reduced organizational risk scores while saving 50 to 60 hours per week in IT monitoring time. KEY HIGHLIGHTS & RESULTS: TIMESTAMPS / CHAPTERS.

Bypassing the Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure into a Trust Proxy

In addition to everyday users, Google's infrastructure is trusted by email security gateways, enterprise firewalls and automated URL detonation platforms. Threat actors know this.

New Phishing Kit Uses AI to Fully Automate Vishing Attacks

A new phishing kit is using generative AI to fully automate voice phishing (vishing) attacks, according to researchers at Group-IB. The phishing platform, called “Balonx,” includes a module dubbed “CallFlow” that the researchers say “represents a fundamental evolution” in the phishing-as-a-service market.