
AI-Generated Phishing Pages Are Impersonating Antivirus Services
Scammers are using AI to generate phishing pages that impersonate antivirus products, according to Malwarebytes.
Use this page to scan recent stories from Knowbe4, see the themes that keep appearing, and jump into complete story briefs.

Scammers are using AI to generate phishing pages that impersonate antivirus products, according to Malwarebytes.

China-based cybercriminals are using a sophisticated phishing-as-a-service platform called the “Outsider Phishing Kit” to launch massive phishing campaigns around the world, according to researchers at Group-IB.

A massive phishing campaign is using invisible Unicode tag characters to evade security filters, according to researchers at Microsoft. This technique, known as “ASCII smuggling,” has grown popular over the past year for launching AI prompt injection attacks, but the same tactic can hide suspicious text in emails.

Lead Analysts : Shikhar Dalela, Maddhav Grandy and Jeewan Singh Jalal

Researchers at Microsoft are tracking an AI-assisted phishing campaign that sent over a million emails attempting to conduct payment diversion scams.

Quantum Readiness Day on September 24 is a useful reminder that the security work we do today is not only about preventing breaches tomorrow. It is about protecting data and digital trust for years to come.

AI tools are drastically improving the speed of the reconnaissance stage of targeted social engineering attacks, according to researchers at ESET. Attackers can use these tools to trawl the internet for publicly available information about potential victims, and incorporate this information into personalized spear phis

Attackers have used a new phishing platform called “BigBear 2.0” to target hundreds of organizations across more than forty countries, according to researchers at CloudSEK. In about 10% of cases, the phishing attacks were able to bypass multifactor authentication.

The U.S. Federal Bureau of Investigation (FBI) has issued an advisory warning of a wave of OAuth consent phishing attacks targeting “prominent victims, their family members, and personal acquaintances.” OAuth phishing is an increasingly popular social engineering tactic that tricks users into granting access to their a

Researchers at Microsoft are tracking a social engineering campaign that uses passkey-themed lures to trick users into granting persistent access to their accounts and online work environments.

Threat actors are using phishing emails with blank SMTP sender fields to bypass Microsoft 365 security filters, according to researchers at ReliaQuest. Microsoft 365 Exchange Online uses a feature called “RejectDirectSend” to block unauthenticated Direct Send emails from an organization’s trusted domain. If an attacker
Open the app view when you want faster scanning, saved stories, and source-focused reading in one place.