Ransomware and phishing have always been linked, but the old model was blunt: a phishing email carried the payload, the recipient opened it, encryption followed within hours.
![]()
Ransomware and phishing have always been linked, but the old model was blunt: a phishing email carried the payload, the recipient opened it, encryption followed within hours.
![]()
Threat actors are using a new technique called “phantom squatting” to trick AI tools into directing users to phishing sites, according to researchers at Palo Alto Networks’ Unit 42.
Since AI models frequently hallucinate phony information, they sometimes point users to websites that don’t exist. Threat actors are now registering these AI-hallucinated domains and using them to host phishing sites.
![]()
Researchers at Cisco Talos are tracking a sophisticated phishing-as-a-service operator panel called “ARToken” that’s built on the EvilTokens phishing platform. ARToken focuses on targeted social engineering attacks, allowing operators to customize phishing attempts for each victim.
![]()
Cybercrime used to have a ‘”tell.” It was the digital equivalent of a villain stroking their cat – clunky grammar, misspelt links and suspicious attachments that screamed ‘phishing’.
![]()
So, you have some AI tools or are thinking about deploying them and want to know a bit about securing them.
You are not alone, but there are significant challenges due to the rapidly growing capabilities of AI, and the issues around new types of vulnerabilities we may not be used to thinking of. This is a very challenging area to attempt to secure, but I hope to point you in the right direction and set you up with some resources.
![]()
When we formed the global steering committee for our KnowBe4 Student Edition, our primary goal was to simply listen. That listening paid off during a pivotal conversation with a private research university in Florida.
![]()
Picture this: Your company just fell victim to a massive data breach. The culprit wasn’t a sophisticated malware strain, a zero-day exploit, or a compromised firewall. It was a perfectly legitimate-looking login from a VP’s account, originating from an unrecognized IP address, requesting an urgent wire transfer via a spotless, text-only email.
![]()