Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Majority of Organizations Hit by Targeted Impersonation Attacks

Fifty-three percent of organizations have had an executive or employee impersonated in targeted social engineering attacks over the past year, according to a new report from Outtake. Just over half of this impersonation activity took place on social media platforms using fake profiles, followed by video platforms.

Introducing The Hybrid Nudge Experience: Outbound Email Security Built for Your Risk Appetite

When it comes to outbound email security, every organization operates under different operational constraints and security requirements. Some security teams prioritize in-app nudges and coaching to catch risky behavior the moment an email is drafted. Others want to avoid friction, particularly for executives, sales teams or mobile-first employees who rarely interact with desktop add-ins.

The Open-Source Paradox: Navigating the New Frontier of AI Supply Chain Risk

The recent developments surrounding vulnerabilities in major AI repositories like Hugging Face serve as a critical wake-up call for the cybersecurity community. As we accelerate toward an agentic future, the platforms we rely on for innovation are increasingly becoming the primary vectors for systemic risk.

New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication

Researchers at ReliaQuest are tracking two new phishing toolkits that are designed to bypass multifactor authentication (MFA). The first tool, called “Jalisco,” is a device code phishing platform that pairs with AI-powered phishing-as-a-service platforms like EvilTokens to provide fresh OAuth codes in real time.

From Inbox to Encryption: How Ransomware Delivery Has Evolved

Ransomware and phishing have always been linked, but the old model was blunt: a phishing email carried the payload, the recipient opened it, encryption followed within hours. What the threat looks like in 2026 is fundamentally different. The email that starts the chain carries nothing dangerous. Instead, the ransomware arrives weeks later, launched by a completely different attacker. So, what can organizations do to protect themselves from these new threats?

Elevating the SOC Experience: Smarter Automation, Richer Threat Intelligence, and AI-Native Investigation

Security operations teams face a constant balancing act: stopping sophisticated email threats, maintaining visibility across their attack surface and keeping administrative workflows running smoothly. When security tools operate in silos or rely on rigid, manual processes, friction builds up quickly. This friction consumes valuable time that analysts could spend on higher-priority initiatives. At KnowBe4, we believe enterprise security should work for you, without the enterprise-grade costs.

The New Face of AI Risk

Cybercrime used to have a ‘"tell." It was the digital equivalent of a villain stroking their cat - clunky grammar, misspelt links and suspicious attachments that screamed ‘phishing’. But the arrival of AI has changed everything. Typos have been replaced by perfect prose. Generic lures have evolved into highly personalized attacks that mimic your internal language and align with your project timelines.

Attackers Exploit AI Hallucinations to Send Users to Phishing Sites

Threat actors are using a new technique called “phantom squatting” to trick AI tools into directing users to phishing sites, according to researchers at Palo Alto Networks’ Unit 42. Since AI models frequently hallucinate phony information, they sometimes point users to websites that don’t exist. Threat actors are now registering these AI-hallucinated domains and using them to host phishing sites.