โŒ

Reading view

There are new articles available, click to refresh the page.

North Korean Job Invitation

A friend of mine, John D., received this outreach on Threads (seeย below).

At first, he thought it was the standard fake employer scam, but it is more than that. It is very likely part of a North Korean fake employee scam. ย 

Fresh Content Updates from November 2025

"Good information. Everyone who owns a computer should do this training across the country. It should be mandatory!โ€

"Wow, I had no idea of the detail and advanced interrogation these criminals use! This was the most eye-opening session I've seen in a long time and VERY timelyโ€

"This was a valuable video. I love the practical tips for how to spot the fake video images - especially the shadows and the lack of glare on the glasses. Thank you!โ€

KnowBe4 is here to help you prepare for the evolving AI security landscape. As AI becomes more prevalent in the workplace, new threats and vulnerabilities are emerging. Now is the time to train your users on AI-related security risks!

We have 80+ pieces of content in our library specifically addressing AI threats. Here are a few of our most used and highest-rated security awareness modules:

  • AI Chatbots: Understanding Their Use, Risks and Limitations in the Workplace
  • New Tools: Artificial Intelligence Scams
  • Generative AI: Seeing through the Deception

We have even more AI security content on the roadmap, so stay subscribed to this newsletter for new releases to help you protect your organization against emerging AI-driven threats.

The Ghost in the Machine: How a Multi-Stage Phishing Campaign Evades Security to Steal Microsoft 365 Credentials

Lead Analysts: Jeewan Singh Jalal, Prabhakaran Ravichandhiran and Anand Bodke

Since November 3, 2025, KnowBe4 Threat Labs has been monitoring a highly sophisticated, multi-stage phishing operation that is actively targeting organizations to steal employeesโ€™ Microsoft 365 credentials. The campaign has been engineered to bypass traditional email security defenses, such as secure email gateways (SEGs),ย  and multi-factor authentication (MFA) tools.

Scammers Are Exploiting the Holiday Shopping Season

Users should be particularly wary of holiday-themed scams over the next few weeks, according to researchers at Malwarebytes.

โ€œMobile-first shopping has become second nature, and during the holidays, itโ€™s faster and more frantic than ever,โ€ Malwarebytes says. โ€œFifty-five percent of people get a scam text message weekly, while 27% are targeted daily.

Blurred Chats, Bigger Risks

Think about your digital spaces. Youโ€™ve got your corporate email, which we all treat a bit like a high-security bank vault. We approach it with caution, we're suspicious of unfamiliar senders, and weโ€™re primed to spot a dodgy attachment. Then, you have WhatsApp. Thatโ€™s the digital equivalent of your living room. Itโ€™s comfy, familiar, and filled with people you (mostly) trust. Our guard is down.

โŒ