![]()
A survey from Trustmi found that most employees believe they’d be able to spot a social engineering attack, but those same employees still rely primarily on outdated guidance to spot red flags. Generative AI has given attackers the ability to craft extremely convincing, error-free phishing emails.
![]()
“Someone online shows them a ‘trick’ that feels harmless at first. Then the community pulls them in. Everyone’s doing it. It feels like skill, not crime.“
![]()
AI agents offer unprecedented capabilities, speed, automation, deep context, and hyper-personalization, that will transform how we work. However, these same capabilities make AI agents significantly more dangerous than traditional software when hijacked by cybercriminals.
![]()
![]()
Your mission, should you choose to accept it: Equip your team with the intel they need to stay ahead of global threat actors and threats such as social engineering and AI deepfakes.
![]()
Attackers are getting smarter. AI is making social engineering more convincing, more personalized, and harder to spot than ever before. Training the digital workforce, employees and agents, to recognize threats is necessary, but even the most security-conscious users can still make a mistake at the moment of risk.
![]()
By Shikhar Dalela and Jeewan Singh Jalal
The operators named the kit themselves.
Buried inside compromised legitimate websites, the hidden staging directory is sometimes literally called “/.bulletproof”, and the PHP session cookie the kit sets on every visitor is named “bp_redir_sess.” The “bp” stands for bulletproof, which is an unusual degree of candor from a threat actor whose entire design philosophy is concealment.
![]()