Today, anyone can find a picture of absolutely anybody and it is also not difficult to find a sample of their voice. By combining these it is shockingly easy to create a realistic AI deepfake video of that person. The video may not be perfect, and an experienced AI deepfake enthusiast might be able to see signs of it not being real, but it will be good enough to fool 99% of people.
Reading view
WeChat Phishing Attacks a Growing Threat Outside China
Lead analysts: Cameron Sweeney, Lucy Gee, Louis Tiley, James Dyer
βSuper-appβ WeChat offers a wealth of functionalityβfrom instant messaging, text and voice messaging, and video calls to mobile payments, ride booking, ordering food deliveries, paying bills and even accessing government services.
Phishing Campaign Targets Executives With Phony Awards
A phishing campaign is targeting executives with phony offers for awards, according to researchers at Trustwave SpiderLabs. The attackers first dupe the victims into handing over their credentials, then use the ClickFix social engineering technique to trick them into installing malware.
Your KnowBe4 Compliance Plus Fresh Content Updates from November 2025
| "Good information. Everyone who owns a computer should do this training across the country. It should be mandatory!β "Wow, I had no idea of the detail and advanced interrogation these criminals use! This was the most eye-opening session I've seen in a long time and VERY timelyβ "This was a valuable video. I love the practical tips for how to spot the fake video images - especially the shadows and the lack of glare on the glasses. Thank you!β |
KnowBe4 is here to help you prepare for the evolving AI security landscape. As AI becomes more prevalent in the workplace, new threats and vulnerabilities are emerging. Now is the time to train your users on AI-related security risks! We have 80+ pieces of content in our library specifically addressing AI threats. Here are a few of our most used and highest-rated compliance modules:
We have even more AI security content on the roadmap, so stay subscribed to this newsletter for new releases to help you protect your organization against emergingΒ AI-driven threats. |
Fresh Content Updates from November 2025
| "Good information. Everyone who owns a computer should do this training across the country. It should be mandatory!β "Wow, I had no idea of the detail and advanced interrogation these criminals use! This was the most eye-opening session I've seen in a long time and VERY timelyβ "This was a valuable video. I love the practical tips for how to spot the fake video images - especially the shadows and the lack of glare on the glasses. Thank you!β |
KnowBe4 is here to help you prepare for the evolving AI security landscape. As AI becomes more prevalent in the workplace, new threats and vulnerabilities are emerging. Now is the time to train your users on AI-related security risks! We have 80+ pieces of content in our library specifically addressing AI threats. Here are a few of our most used and highest-rated security awareness modules:
We have even more AI security content on the roadmap, so stay subscribed to this newsletter for new releases to help you protect your organization against emerging AI-driven threats. |
Report: Phishing Has Surged 400% Year-Over-Year
Researchers at SpyCloud have observed a 400% year-over-year increase in successful phishing attacks, with a disproportionate number of attacks targeting corporate accounts.
Warning: Phishing Campaign Leveraging Evilginx Targets U.S. Universities
Threat actors are using the open-source phishing framework Evilginx to target universities across the United States, according to researchers at Infoblox. The attackers have targeted at least 18 universities and educational entities since April 2025, using phishing pages that spoofed student single sign-on (SSO) portals.
Notorious Cybercrime Group is Now Targeting Zendesk Users
ReliaQuest warns that the cybercriminal collective βScattered Lapsus$ Huntersβ appears to be using social engineering attacks to target organizationsβ Zendesk instances.
Malicious AI Tools Assist in Phishing and Ransomware Attacks
Researchers at Palo Alto Networksβ Unit 42 are tracking two new malicious AI tools, WormGPT 4 and KawaiiGPT, that allow threat actors to craft phishing lures and generate ransomware code.
KnowBe4 Earns Multiple 2026 Buyer's Choice Awards from TrustRadius
KnowBe4 is proud to announce that three of its leading security products β Security Awareness Training, PhishER/PhishER Plus and Compliance Plus β have been recognized as 2026 Buyer's Choice award winners by TrustRadius, a HG Insights company and buyer intelligence platform for business technology.
The Ghost in the Machine: How a Multi-Stage Phishing Campaign Evades Security to Steal Microsoft 365 Credentials
Lead Analysts: Jeewan Singh Jalal, Prabhakaran Ravichandhiran and Anand Bodke
Since November 3, 2025, KnowBe4 Threat Labs has been monitoring a highly sophisticated, multi-stage phishing operation that is actively targeting organizations to steal employeesβ Microsoft 365 credentials. The campaign has been engineered to bypass traditional email security defenses, such as secure email gateways (SEGs),Β and multi-factor authentication (MFA) tools.