Anatomy of an Agent Tesla BEC Attack: From Inbox to In-Memory Infostealer
Lead Analysts: Prabhakaran Ravichandhiran and Jeewan Singh Jalal
Search fresh public links, source activity, and ready-to-use post angles for Knowbe4 Threat Lab.
Fresh curated links around KnowBe4 Threat Lab are collected here so marketers can spot useful updates and turn timely ideas into posts faster.
Recent items include:
Recent curated links from global sources. Generate one free draft from any story, then use SocialBu to schedule and refine your content calendar.
Lead Analysts: Prabhakaran Ravichandhiran and Jeewan Singh Jalal
Lead Analysts: Prabhakaran Ravichandhiran and Jeewan Singh Jalal The lure email has been received. This is a fabricated iCloud sign-in alert designed to feel like an official sec...
By Shikhar Dalela and Jeewan Singh Jalal The operators named the kit themselves. Buried inside compromised legitimate websites, the hidden staging directory is sometimes literall...
Fran Roberts - Studios General Manager, KnowBe4 Twenty years across studios, agencies and global production environments, sitting through more fire drills and real fires than I...
Security controls can block a familiar attack method while missing quieter ways to achieve the same objective. Picus Security's Blue Report 2026 shows how prevention rates can vary...
Picture this: Your company just fell victim to a massive data breach. The culprit wasn't a sophisticated malware strain, a zero-day exploit, or a compromised firewall. It was a per...
KnowBe4 delivers customizable voice simulations that mirror real attacker tactics
Every year, KnowBe4 analyzes millions of simulated phishing tests to measure one thing: how likely is your workforce to fall for a phishing attack? The results, published in the 20...
Your mission, should you choose to accept it: Equip your team with the intel they need to stay ahead of global threat actors and threats such as social engineering and AI deepfakes...
Security operations teams face a constant balancing act: stopping sophisticated email threats, maintaining visibility across their attack surface and keeping administrative workflo...
Threat actors are actively exploiting CVE-2026-0257, an authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect, to gain remote access and deploy Qilin ranso...
Researchers at Cisco Talos are tracking a sophisticated phishing-as-a-service operator panel called “ARToken” that’s built on the EvilTokens phishing platform. ARToken focuses on t...
Somewhere right now, an attacker is testing stolen passwords against a company that assumes its firewall has things covered. It doesn’t. Attacks move too fast for that now; ransomw...
For years, security teams have poured resources into locking down the inbox, and for good reason. Email has always been the front door for phishing and social engineering. Unfortun...
Fran Roberts - Studios General Manager, KnowBe4 Bribery and corruption do not always look the way people expect. They rarely show up as a suitcase of cash or an obvious quid pro...
When we think about email security, our minds almost always jump to the inbound threats: the sophisticated phishing lures, the AI-generated business email compromise (BEC) attacks,...
The State of Threat Management Report reveals that fragmented tools and manual processes are widening the gap between threat awareness
Learn how attackers abuse Entra ID through a free hands-on Capture the Flag. Varonis created the Breach at the Beach CTF to teach defenders how to investigate Entra ID attack techn...
Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is...
CERT-UA has identified an ongoing campaign in which threat group UAC-0099 distributes trojanized Notepad++ bundles that install malware on Windows systems. The campaign primarily t...
Attackers are getting smarter. AI is making social engineering more convincing, more personalized, and harder to spot than ever before. Training the digital workforce, employees an...
2026 Mid-Year Threat Report webinar, experts from the Cofense Phishing Defense Center shared how attackers are evolving their tactics and why organizations must rethink how they de...
An active adversary-in-the-middle (AiTM) phishing campaign that clones Microsoft authentication pages to intercept credentials, Multi-Factor Authentication (MFA) codes, and session...
Use SocialBu to discover ideas, generate post drafts, and schedule them across your social channels.