Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Warning: Compromised Hotel Routers Send Users to Phishing Sites

Attackers are using compromised hotel Wi-Fi routers to redirect users to Microsoft 365 phishing sites, according to researchers at ReliaQuest. The attacks were observed in multiple U.S. cities, as well as across India and Saudi Arabia. These types of DNS poisoning attacks can send users to phishing sites with very little evidence that something suspicious has taken place.

Shadow AI: The New Frontier of Shadow IT

As a CISO advisor, I am observing a familiar pattern gaining a new, critical dimension. What we historically identified as "Shadow IT", the use of unapproved SaaS and tools, is rapidly evolving into "Shadow AI." Employees are increasingly leveraging AI bots for drafting, analysis, code generation and strategic decision-making.

Warning: Vishing Attacks Open the Door to Ransomware Gangs

An initial access broker for ransomware gangs is targeting organizations with voice phishing (vishing) attacks through Microsoft Teams, according to researchers at Zscaler’s ThreatLabz. “From January through June 2026, ThreatLabz examined a cluster of related campaigns that used Microsoft Teams vishing and Quick Assist for initial access, followed by PowerShell-based staging,” the researchers write.

Why Securing AI Agents Is More Critical Than Ever

AI agents offer unprecedented capabilities, speed, automation, deep context, and hyper-personalization, that will transform how we work. However, these same capabilities make AI agents significantly more dangerous than traditional software when hijacked by cybercriminals. You simply cannot rely on yesterday's risk management playbooks to handle today's AI-driven threats.

Report: Employees Are Overconfident in Their Ability to Spot Scams

A survey from Trustmi found that most employees believe they’d be able to spot a social engineering attack, but those same employees still rely primarily on outdated guidance to spot red flags. Generative AI has given attackers the ability to craft extremely convincing, error-free phishing emails.

Why You Can't Arrest Your Way Out of Youth Cybercrime

Sir Robert Peel defined good policing as "the absence of crime and disorder, and not the visible evidence of police action in dealing with them." Gregory Francis of the Netherlands National Police quoted this at the INTERCOP conference held at INTERPOL headquarters, and this principle framed the entire event. Young people are increasingly drawn into cybercrime through the platforms where they already spend their time — Discord, Telegram and gaming servers.

The Blind Spot: How "Bulletproof" Phishing Redirectors Slip Past SEGs

By Shikhar Dalela and Jeewan Singh Jalal The operators named the kit themselves. Buried inside compromised legitimate websites, the hidden staging directory is sometimes literally called “/.bulletproof”, and the PHP session cookie the kit sets on every visitor is named “bp_redir_sess.” The “bp” stands for bulletproof, which is an unusual degree of candor from a threat actor whose entire design philosophy is concealment.

Introducing Real-Time Coaching in KnowBe4's AI-Native Security Awareness Training

Attackers are getting smarter. AI is making social engineering more convincing, more personalized, and harder to spot than ever before. Training the digital workforce, employees and agents, to recognize threats is necessary, but even the most security-conscious users can still make a mistake at the moment of risk. Workforce risk is a behavior change problem, and effective behavior change requires knowledge, pressure-tested application and real-time reinforcement all working together.

AI Did Not Invent Social Engineering But It Did Industrialize It.

This year National Social Engineering Day falls on Aug. 6. This day is designed to give us an opportunity to remind people that cybercriminals do not always need sophisticated malware, an undisclosed vulnerability or a dark room filled with glowing monitors, sometimes, all they need is a good story. Social engineering existed long before computers. Confidence tricks, impersonation, false authority and appeals to greed or fear have been used for centuries.