Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Your CFO Just Left You a Voice Note. It Wasn't Her.

A voice note from your CFO on WhatsApp. Her cadence, her urgency—and a reference to a confidential acquisition discussed in a real meeting last Tuesday. North Korea's Blue Noroff builds these backwards: compromise a junior employee's calendar or inbox first, then train a voice model on the stolen context. By the time anyone thinks to verify, the emergency transfer is already sitting in an offshore account.

How to Reduce Payment Fraud Risk Without Adding Customer Friction

Reducing payment fraud risk requires giving existing fraud controls enough context to distinguish higher-risk interactions from routine activity, rather than applying more checks to every customer. That distinction matters. UK Finance reported that criminals stole almost £1.3 billion through authorized and unauthorized fraud in the UK during 2025. Authorized push payment fraud alone accounted for £576.4 million, up 19% year over year.

How AI Phone Calling Is Changing Voice Phishing Defense

Phone scams have been around for decades, but the last few years have brought a sharp shift in how convincing they've become. Voice phishing, often called vishing, used to rely on generic scripts and a scammer's ability to sound believable. Today, the same technology that powers helpful tools like AI phone calling is also being studied and used to fight back against these scams.

Twitter Brand Impersonation: How Security Teams Detect Fake Accounts and Phishing on X

Most brand impersonation starts in public. A lookalike support handle appears, replies to real customers under your official account, and links to a credential-harvesting page. By the time it reaches a takedown vendor's weekly report, the damage window has been open for hours.

Why slow fraud investigations cost more than you think: The ROI case for AI-assisted investigation

Fraud doesn’t wait for your investigation queue. Every minute an alert sits unresolved gives fraudsters more time to move the money. Yet at most financial institutions, a single case still takes an analyst 10 to 30 minutes to investigate — pulling transaction history, checking device and behavioral data, weighing risk signals and documenting a decision. Multiply that by hundreds or thousands of alerts a day, and slow investigation isn’t just an inconvenience.

Warning: Replying to a "Wrong Number" Text Marks You as a Target for Scams

Attackers are using “wrong-number” texts to identify potential targets for scams, according to researchers at Malwarebytes. These texts appear to be harmless messages meant for another person, such as “Are we still on for dinner tomorrow?” or “Where’s the PowerPoint?” Recipients often try to be helpful by replying to let the person know they’ve got the wrong number.

The .vu Surge: How Threat Actors Are Exploiting Vanuatu's Domain Extension

Phishing infrastructure is built to be thrown away. When a domain gets blocklisted, scrutinized, or too hot to handle, the attackers don't stop. They just move. To them, a domain extension is just a cheap tool. They go wherever it is easiest to strike. That pattern is visible in our own telemetry. In late 2024 and early 2025, KnowBe4 Threat Lab documented a 98% spike in phishing campaigns abusing.ru domains. 1,500 unique domains, over 13,000 malicious emails, with an average domain age of just 7.4 days.

Brand Impersonation Protection Software: What to Look For Beyond Domain Takedown

Brand Impersonation protection software should do more than find and remove impersonating assets. Buyers should also examine what a platform helps their organization understand and do about the customer and business risk created while the campaign remains active. The Anti-Phishing Working Group recorded 971,181 phishing attacks in Q1 2026, up 13.8% from the previous quarter. Across monitored social platforms, impersonation accounted for 43.8% of threats. Takedown is necessary.

Report: AI Chatbots Are More Effective at Building Trust Than Human Scammers

A study has found that AI chatbots can be more effective at social engineering than human scammers, WIRED reports. The researchers looked at a form of romance scam commonly known as “pig butchering,” in which scammers spend weeks or months building a relationship with the victim before tricking them into sending money for a phony investment scheme.