Two days at INTERPOL on youth cybercrime, why offender prevention is real police work and why it has to out-recruit rather than out-threaten.
![]()
![]()
Your mission, should you choose to accept it: Equip your team with the intel they need to stay ahead of global threat actors and threats such as social engineering and AI deepfakes.
![]()
Attackers are getting smarter. AI is making social engineering more convincing, more personalized, and harder to spot than ever before. Training the digital workforce, employees and agents, to recognize threats is necessary, but even the most security-conscious users can still make a mistake at the moment of risk.
![]()
By Shikhar Dalela and Jeewan Singh Jalal
The operators named the kit themselves.
Buried inside compromised legitimate websites, the hidden staging directory is sometimes literally called “/.bulletproof”, and the PHP session cookie the kit sets on every visitor is named “bp_redir_sess.” The “bp” stands for bulletproof, which is an unusual degree of candor from a threat actor whose entire design philosophy is concealment.
![]()
Fran Roberts – Studios General Manager, KnowBe4
Bribery and corruption do not always look the way people expect. They rarely show up as a suitcase of cash or an obvious quid pro quo. More often, they arrive as a favor, a gift, a “just this once” that feels trivial in the moment and catastrophic in hindsight. That gap between perception and reality is where training matters most.
![]()
Fran Roberts – Studios General Manager, KnowBe4
Twenty years across studios, agencies and global production environments, sitting through more fire drills and real fires than I can count, has taught me this: it’s never luck. It’s rehearsal.
Most disruptions aren’t dramatic. They’re a ransomware attack on a Friday afternoon, a key system going down mid-quarter, a vendor failing at the worst possible moment. Nobody sees those coming. You either drill for them, or you don’t.
![]()
This year National Social Engineering Day falls on Aug. 6. This day is designed to give us an opportunity to remind people that cybercriminals do not always need sophisticated malware, an undisclosed vulnerability or a dark room filled with glowing monitors, sometimes, all they need is a good story.
![]()