惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
人人都是产品经理
人人都是产品经理
S
Securelist
P
Proofpoint News Feed
H
Help Net Security
S
Schneier on Security
T
Tenable Blog
C
Cisco Blogs
S
Security @ Cisco Blogs
博客园 - 司徒正美
博客园 - 叶小钗
Cisco Talos Blog
Cisco Talos Blog
Google DeepMind News
Google DeepMind News
C
Cybersecurity and Infrastructure Security Agency CISA
Google Online Security Blog
Google Online Security Blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Hacker News: Ask HN
Hacker News: Ask HN
NISL@THU
NISL@THU
云风的 BLOG
云风的 BLOG
V
Vulnerabilities – Threatpost
T
The Blog of Author Tim Ferriss
aimingoo的专栏
aimingoo的专栏
W
WeLiveSecurity
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Jina AI
Jina AI
腾讯CDC
WordPress大学
WordPress大学
Simon Willison's Weblog
Simon Willison's Weblog
Vercel News
Vercel News
小众软件
小众软件
N
Netflix TechBlog - Medium
有赞技术团队
有赞技术团队
AWS News Blog
AWS News Blog
雷峰网
雷峰网
Forbes - Security
Forbes - Security
The Hacker News
The Hacker News
博客园 - 聂微东
F
Full Disclosure
量子位
Scott Helme
Scott Helme
宝玉的分享
宝玉的分享
A
About on SuperTechFans
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Schneier on Security
Schneier on Security
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
K
Kaspersky official blog
AI
AI
SecWiki News
SecWiki News
Webroot Blog
Webroot Blog
Martin Fowler
Martin Fowler

Human Risk Management Blog

The Open-Source Paradox: Navigating the New Frontier of AI Supply Chain Risk Introducing The Hybrid Nudge Experience: Outbound Email Security Built for Your Risk Appetite Elevating the SOC Experience: Smarter Automation, Richer Threat Intelligence, and AI-Native Investigation New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication From Inbox to Encryption: How Ransomware Delivery Has Evolved Attackers Exploit AI Hallucinations to Send Users to Phishing Sites Warning: ARToken Phishing Kit Automates BEC Attacks The New Face of AI Risk Trust Nothing: Tips to Secure AI Tools and Agents Beyond the Checkbox: How a Proactive Partnership Led to Turnkey Hazing Compliance Trust, Verify, Protect: Modernizing Email Security for the Cloud Report: Social Engineering Remains a Central Part of AI-assisted Attacks ClickFix Social Engineering is Now the Leading Malware Delivery Method CyberheistNews Vol 16 #28 Your 2026 Phishing by Industry Benchmarks: The Findings on Human Risk Scammers Can Use AI Tools to Pinpoint Your Location Based on a Photo Report: Attackers Are Using AI to Automate Social Engineering Your KnowBe4 Fresh Compliance Plus Content Updates from June 2026 From Awareness to Digital Workforce Security Your KnowBe4 Fresh Content Updates from June 2026 Threat Actor Uses Phishing to Breach Orgs for Ransomware Gangs Invoice Phishing Attacks Are Abusing the Shop App Phishing Campaign Impersonates Interpol to Deliver Ransomware Prompt Injection and the Rise of Agentic Risk Hyper-Targeted Social Engineering Needs Real-Time Video Response Your Email is Protected. Is Your Teams Chat? CyberheistNews Vol 16 #27 [HOW TO] Your Cybersecurity Starts at Home on World Social Media Day 2026 Phishing by Industry Benchmarking Report: Findings on Human Risk Static DLP Is Leaving You in the Dark: Why It’s Time for Intelligent, Self-Serve Outbound DLP and Misdirected Content Analysis INC Ransomware Gang Targets the Legal Sector 5 Essential Cybersecurity Defenses for Cloud Email Security Cybercriminals Are Targeting the FIFA World Cup 2026 Why Bite-Sized Security Awareness Training Matters in an Age of TikTok and Digital Distraction Happy 3rd Birthday to Our KnowBe4 Community! Phishing Exposes Employee Data at 86% of Fortune 100 Companies Shadow AI Is Not Shadow IT With a Better Marketing Budget CyberheistNews Vol 16 #26 A New Extortion Scam Uses IT Impersonation to Breach Organizations Cybersecurity Starts At Home This World Social Media Day FTC Report: Americans Lost $3.5 Billion to Imposter Scams Last Year Report: Device Code Phishing is Surging Report: Online Shoppers Increasingly Ignore Scam Warning Signs Security Training Needs Google Maps, Not Christopher Columbus Turn Account Takeover Into Real-Time Security Coaching Extortion Gang Sends In-Person Attackers to Exfiltrate Data Attackers aren’t loyal to any collaboration channel CyberheistNews Vol 16 #25 [The AI Tell] How To Expose Machine-Written Phishing Fast Social Engineering Attacks Abuse Workplace Collaboration Tools New Extortion Brand Uses IT Impersonation to Breach Organizations APWG Report: Social Media Phishing is Surging Cybersecurity Awareness Training for AI: Key Focus Areas Americans Lost $900 Million to AI-Powered Scams Last Year What AI Can’t Hide When It Writes a Phishing Email Your AI Agents Are Eager to Please And Easy to Exploit From 1% to 26%: How AIDA Orchestration Fixes the Remedial Training Gap Best AI Agent Security Tools for SMB and Enterprise in 2026 4 Hot Summer Travel Tips To Avoid Scams CyberheistNews Vol 16 #24 [FBI Alert] Lock Down Your Microsoft 365 Device Code Flows Now The Role of Agentic AI in Phishing Security Training A Credit Score for Cyber Behavior Agentic AI Security in 2026: What to Know How to Secure AI Agents: 4 Best Practices An Overview of Email Compliance Regulations and Reporting Report: AI-Assisted Fraud is Surging Attackers Use Spoofed ChatGPT Site to Deliver Malware I Love Device-Bound Session Credentials, But They Are Still Phishable and Hackable Nearly Two-Thirds of CEOs Cite Cyberattacks as Their Top Concern A Look at Spam vs. Phishing: 4 Key Differences KnowBe4 Wins Multiple 2026 TrustRadius Top Rated Awards Cyber Insurance for Mid‑Market Organizations in Southeast Asia KnowBe4 Earns Multiple 2026 Buyer's Choice Awards from TrustRadius The New Frontier: Securing Japan’s Hybrid Digital Workforce (2026 & Beyond) CyberheistNews Vol 16 #23 Now Phishing Attacks Use Real Hotel Reservations to Target Travelers Report: AI-Enabled Social Engineering Attacks Are on the Rise Your KnowBe4 Fresh Compliance Plus Content Updates from May 2026 FBI: Kali365 Phishing Kit is Targeting Microsoft 365 Accounts KB4-CON - AI Is Everything How to Secure AI Adoption In Your Organization Your KnowBe4 Fresh Content Updates from May 2026 The Silent Invitation: A Deep Dive into Calendar Invite Phishing Cyber Insurance for Mid‑Market Organizations in Southeast Asia Chinese-Language Phishing Kits Are Growing More Advanced Phishing Attacks Are Using Real Hotel Reservation Info to Target Travelers Warning: Scammers are Exploiting Geopolitical Unrest Athletes Are Increasingly Targeted by Social Engineering Attacks AI Agent Governance Part 3 - Runtime Governance: The Hidden Performance Cost of Agentic AI AI Agent Governance Part 2 - What Good Looks Like: Governing AI Agents in Practice 8 Ways to Reduce False Positives in Email Security Ransomware Attacks Drive a Surge in Cyber Insurance Claims My Favorite 5 KnowBe4 Agents Perry Carpenter KB4-CON 2026 Q&A: Deepfakes & Deception Free Gift Fallacy: How Attackers Harvest Credit Cards via Fake Surveys When Global Conflict Becomes a Cyber Weapon: How Iran Tensions and Other Stressful Events Fuel Social Engineering Attacks CyberheistNews Vol 16 #21 [Heads Up] GitHub Breach Shows Developer Tools Are Social Engineering Targets Alert: Extortion Groups Are Using Phishing Kits to Automate Their Attacks Beyond the Chatbot: Why Your AI Agents are Your Newest (and Most Vulnerable) Colleagues Report: Adversarial Use of AI is Evolving
CyberheistNews Vol 16 #29 ClickFix Social Engineering is Now the Leading Malware Delivery Method
KnowBe4 Team · 2026-07-21 · via Human Risk Management Blog

Cyberheist News


CyberheistNews Vol 16 #29  |   July 21st, 2026


ClickFix Social Engineering is Now the Leading Malware Delivery Method

The ClickFix social engineering technique is now the top malware delivery method, according to a new report from ReliaQuest. These attacks trick users into copying a malicious command, then pasting it into a terminal and running it on their computers.

"ClickFix remained the dominant delivery method this period and, for the first time, we observed it expand to macOS, delivering infostealers onto a platform many organizations still monitor less closely than Windows," the researchers write. "This means ClickFix can no longer be handled as a special case.

"Training, detection and triage for it should run continuously on both Windows and macOS." ReliaQuest notes that AI tools are enabling threat actors to scale social engineering attacks with very little added effort.

"Adversaries leaned on two strategies: social engineering at scale and attacks on unpatched, internet-facing infrastructure," the researchers write. "The leading technique 'ClickFix' drove the first, shifting delivery from compromised websites to emailed links, while 'Qilin,' the period's most active ransomware operator, continued exploiting unpatched edge devices for mass extortion.

"What's more, AI is making social engineering faster, cheaper and more convincing, accelerating familiar techniques rather than creating new ones." Organizations should ensure that their security awareness programs train employees to recognize ClickFix tactics.

[CONTINUED] Blog post with links:
https://blog.knowbe4.com/clickfix-social-engineering-top-malware-delivery-method

Custom Security Training in Minutes, Not Months

Building custom content used to mean big budgets and weeks of production time, but AI-driven threats don't wait. Your training shouldn't either.

Watch this demo to see how KnowBe4's AI agents deliver tailored content that meets your organization's exact needs, at speed. From generating custom training from your own policies to simulating deepfakes of your own executives, see what's now possible in minutes.

What you'll see in this demo:

  • Content Creation Agent: Turn simple text prompts or internal documents into custom, interactive training modules and quizzes, no instructional design team required.
  • Deepfake Training Content Agent: Safely simulate hyper-realistic executive impersonations, giving your workforce the hands-on experience needed to spot next-gen social engineering tactics before they lead to a costly mistake.
  • Studio-Quality AI Videos at Scale, Powered by Synthesia: Generate professional video training modules with realistic AI avatars and seamless localization across 130+ languages — no production budget required.

The threats targeting your organization are custom-built. Your training should be too. Watch now and see how KnowBe4 puts the power of custom, relevant security awareness training directly in your hands.

Watch Now:
https://info.knowbe4.com/kmsat-demo-3?partnerref=OD

Trust, Verify, Protect: Modernizing Email Security for the Cloud

By Dr. Kawin Boonyapredee

Picture this: Your company just fell victim to a massive data breach. The culprit wasn't a sophisticated malware strain, a zero-day exploit or a compromised firewall. It was a perfectly legitimate-looking login from a VP's account, originating from an unrecognized IP address, requesting an urgent wire transfer via a spotless, text-only email.

In the modern threat landscape, attackers have realized something crucial: Why break in when you can just log in?

As organizations shift to the cloud, the line between email security and identity management has blurred entirely. Traditional email security is failing because it's looking for bad files, while attackers are busy stealing good identities. Here is how cloud email security should work in a world dominated by identity-first attacks.

The Core Problem: The Legacy Email Security Mirage
For decades, Secure Email Gateways (SEGs) acted as the bouncers of the corporate network. They inspected incoming traffic at the perimeter, checking for known bad signatures, malicious attachments and sketchy URLs.

But in a cloud-first world (think Microsoft 365 and Google Workspace), the perimeter no longer exists.

Attackers use trusted infrastructure: Phishing pages are hosted on legitimate SharePoint or Google Drive links.

Payload-less attacks dominate: Business Email Compromise (BEC) and vendor email compromise often contain zero links and zero attachments. They rely purely on social engineering and identity impersonation.

The attack happens inside the house: If an attacker compromises a user's credentials via a session hijacking attack, they can send malicious emails internally. A traditional SEG will never even see it.

What is an Identity-First Attack?
Identity-first attacks target the human element and the authentication mechanisms protecting your users. Instead of exploiting software vulnerabilities, they exploit trust. Common tactics include:

  • Session Hijacking / Cookie Theft: Bypassing Multi-Factor Authentication (MFA) by stealing active session tokens.
  • Credential Stuffing: Using leaked passwords across multiple platforms.
  • Lookalike Domains and Display Name Spoofing: Creating an email address that closely resembles a company executive or trusted vendor (e.g., ceo@cornpany.com instead of company.com).

The Blueprint for Modern Cloud Email Security

To survive a world of identity-first threats, email security can no longer operate in a silo. It must evolve from a perimeter filter into an integrated, identity-aware behavioral engine. Here is what that looks like in practice:

[CONTINUED] Blog post with links:
https://blog.knowbe4.com/modernizing-cloud-email-security-identity-first

From Legacy SEGs to Integrated Cloud Email Security (ICES)

Nearly 87% of cybersecurity leaders are currently considering or have already completed the replacement of their SEG. This shift comes as sophisticated, payload-less threats increasingly bypass traditional defenses by exploiting human trust rather than technical vulnerabilities.

This whitepaper explores the fundamental shift from external gateways to Integrated Cloud Email Security (ICES). It provides a strategic framework to help you identify when a SEG has become obsolete and how to transition to a model that leverages deep API integration for superior visibility.

Your roadmap for modernizing email protection includes:

  • The critical blind spots of SEG architecture and why operating outside the cloud tenant leaves your organization blind to internal mail flow and behavioral anomalies
  • The power of AI-driven behavioral detection and how ICES uses machine learning to stop Business Email Compromise (BEC) and account takeovers
  • A three-phase transition strategy to assess your current performance baseline, evaluate integrated platforms and execute a migration with minimal disruption

It's time to take a good, hard look at SEGs.

Download Now:
https://info.knowbe4.com/evaluating-modern-email-security-architectures-wp-chn

Report: Social Engineering Remains a Central Part of AI-assisted Attacks

Threat actors continue to rely on social engineering as AI is incorporated into their attacks, according to ESET’s Threat Report for the first half of 2026.

ESET’s Director of Threat Prevention Labs, Jiří Kropáč, stated, "Rather than relying on entirely new methods and tools, attackers are quickly adapting established techniques to new platforms, technologies and user behaviors. The number of AI skills within this new ecosystem is growing rapidly as we speak, further expanding the attack surface."

ClickFix social engineering attacks steadily increased throughout the first half of the year, as attackers improved their techniques.

"In H1 2026, ClickFix continued to spread across new environments and leverage new lures: extending to macOS through commands that supposedly install system utilities, compromising WordPress sites to show ClickFix-style prompts to site administrators and launching AI-themed waves," the report says.

"Attackers have also refined the social engineering layer, using fake blue-screen-of-death (BSOD) prompts, frozen document viewers and service specific error messages to increase the chances of successful compromise. ESET telemetry shows that detections of ClickFix attacks…grew by 108% between H2 2025 and H1 2026."

Notably, ESET is tracking a variant of ClickFix that offers advice related to generative AI tools. "Adversaries keep the social engineering aspect of ClickFix up to date by adopting what we track as AI-fix which exploits the current hype, growing popularity and availability of generative AI tools," the researchers write.

"Attackers craft pages that abuse legitimate domains – for example, Anthropic’s Artifact pages, OpenAI’s Canvas or Microsoft’s Copilot Pages – offering troubleshooting content for nonexistent issues. The user is led to believe that the instructions are AI-generated, which plays right into the attackers’ hands, as people increasingly tend to place their trust in such tools."

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 Platform to strengthen their security culture and reduce workforce risk.

Blog Post with Links:
https://blog.knowbe4.com/social-engineering-central-ai-assisted-attacks

Phishing Security Test: Free Anti-Phishing Tool

Did you know that 91% of successful data breaches started with a spear phishing attack?

Find out what percentage of your employees are Phish-prone™ with your free Phishing Security Test. Plus, see how you stack up against your peers with the new phishing Industry Benchmarks!

IT pros have realized that simulated phishing tests are urgently needed as an additional security layer. Today, phishing your own users is just as important as having an antivirus and a firewall. It is a fun and effective cybersecurity best practice to patch your last line of defense: USERS.

Why? If you don't do it yourself, the bad actors will.

Here's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

The Phish-prone Percentage is usually higher than you expect and is great ammo to get budget. Start phishing your users now. Fill out the form, and get started immediately!

Sign Up:
https://info.knowbe4.com/phishing-security-test-em-chn

Let's stay safe out there.

Warm regards,

Stu Sjouwerman, SACP
Executive Chairman
KnowBe4, Inc.

PS: Yours Truly--Celebrating America 250!:
https://voicesof250.com/voices/stu-sjouwerman-readingminds-7b6fcc02-778d-4d87-ab71-a4132d0b51f2

Quotes of the Week  

"The whole secret of life is to be interested in one thing profoundly and in a thousand things well."
- Horace Walpole - Writer (1717-1797)


"Education is what remains after one has forgotten what one has learned in school."
- Albert Einstein - Physicist (1879 - 1955)


Thanks for reading CyberheistNews

You can read CyberheistNews online at our Blog
https://blog.knowbe4.com/cyberheistnews-vol-16-29-clickfix-social-engineering-is-now-the-leading-malware-delivery-method

Security News

Targeted Impersonation Attacks Hit a Majority of Organizations Last Year

Fifty-three percent of organizations have had an executive or employee impersonated in targeted social engineering attacks over the past year, according to a new report from Outtake.

Social media platforms accounted for just over half of the activity, followed by video platforms.

"More than half of all alerts (53.83%) of executive impersonation threats stem from social platforms," Outtake says. "Video and visual platforms follow at 35.05%, with open community forums (6.84%) and executive lookalike domains (3.57%) rounding out the remainder.

"Yet the per-executive risk profile varies sharply: most executives (76.2%) see nearly all activity concentrated on one surface, while others (23.8%) face attacks distributed thinly across social, lookalike domains, forums and broker-site PII exposure simultaneously."

Notably, threat actors are using AI tools to dramatically accelerate these attacks. AI can speed up reconnaissance to craft convincingly spoofed profiles, while deepfake technology can generate images and videos of executives that are indistinguishable from real life.

"Attackers use AI to skip your internal security tools completely," the researchers explain. "There's less need to break through data, network, cloud and endpoint security perimeters when adversaries can just impersonate an executive out on the open internet, where those tools don't watch.

"They target your most visible leaders on purpose because a trusted name gets them to the money faster than anything inside your network. And it lands on a handful of executives, not the whole team."

AI-native security awareness training gives your organization an essential layer of defense against targeted social engineering attacks.

Outtake has the story:
https://www.businesswire.com/news/home/20260707313790/en/Majority-of-Enterprises-Hit-by-Executive-Impersonation-as-C-Suite-Becomes-the-Fastest-Growing-Attack-Surface

New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication

Researchers at ReliaQuest are tracking two new phishing toolkits that are designed to bypass multifactor authentication (MFA). The first tool, called "Jalisco," is a device code phishing platform that pairs with AI-powered phishing-as-a-service platforms like EvilTokens to provide fresh OAuth codes in real time.

"Jalisco is a device code phishing toolkit that provisions fresh OAuth codes in real time via a backend API and manages captured sessions through a web portal," ReliaQuest says. "Its use of lure-generation—a recent evolution that bypasses the 15-minute time-to-live (TTL) on device codes—neutralizes one of the core security assumptions defenders rely on to limit device code phishing.

"Its presence in the wild signals that lure-generation is highly likely to become a standard feature across a wider range of phishing kits."

The second tool, dubbed "OmegaLord," is a credential harvester that also captures phone numbers in order to intercept MFA codes. "OmegaLord is a newly discovered JavaScript-based credential harvester that goes beyond standard tools by deliberately collecting phone numbers alongside credentials, likely to intercept or hijack MFA—a signal that even traditional credential theft phishing is being engineered around modern authentication defenses," the researchers write.

"OmegaLord displays a fake PDF reader login page that prompts the user for their email address, password and phone number. Collecting phone numbers is unusual for credential harvesters and is likely intended to help the attacker intercept or hijack MFA requests during authentication."

Both of these toolkits indicate that attackers are increasingly interested in automating techniques to bypass MFA. "Neither tool exists in isolation," the researchers explain. "Device code phishing tricks users into authenticating on behalf of an attacker, bypassing MFA without exposing credentials and has surged in 2026—driven by AI-powered PhaaS kits that let any attacker impersonate any brand with minimal skill.

"Once inside a compromised Microsoft 365 account, attackers establish persistence by pairing multiple attacker-controlled devices to the victim's Entra ID tenant, then move quickly to exfiltrate sensitive data from software-as-a-service (SaaS) platforms for extortion."

ReliaQuest has the story:
https://reliaquest.com/blog/threat-spotlight-jalisco-toolkit-and-ai-powered-phishing-surge

What KnowBe4 Customers Say

"Claire and Griffin, thank you so much for the fantastic call today. You answered many questions that I had that I hadn't even verbalized on the call. It has been a good experience working with KnowBe4 for about 9 years now and you two have continued that great working relationship. I greatly appreciate you!"

- T.M., Executive Director, Information Technology Services

The 10 Interesting News Items This Week

  1. EU sanctions Russian GRU military hackers over cyberattacks:
    https://www.bleepingcomputer.com/news/security/eu-and-uk-hit-russia-with-first-joint-cyber-sanctions-package/
  2. US and security allies warn Russian attacks on critical infrastructure are ramping up against 'poorly configured and vulnerable networking devices worldwide':
    https://www.ic3.gov/CSA/2026/260713.pdf
  3. VPN service favored by ransomware groups is sanctioned by US:
    https://therecord.media/first-vpn-administrator-us-sanctions-ransomware-groups
  4. [LEGAL INDUSTRY] The Rising Tide of AI-Enabled Social Engineering Scams: What Orgs Need to Know:
    https://www.jdsupra.com/legalnews/the-rising-tide-of-ai-enabled-social-8157586/
  5. Attackers are targeting Celine Dion fans with phony ticket scams:
    https://www.group-ib.com/blog/fake-concert-ticket-scam-celine-dion/
  6. Dutch police bust investment fraud ring stealing over €100 million:
    https://www.bleepingcomputer.com/news/security/dutch-police-bust-investment-fraud-ring-stealing-over-100-million/
  7. Now, even Russia’s most elite hackers are using ClickFix to infect devices:
    https://arstechnica.com/security/2026/07/now-even-russias-most-elite-hackers-are-using-clickfix-to-infect-devices/
  8. Iranian APTs are using AI to enhance their operations:
    https://www.recordedfuture.com/research/iran-ai-asymmetric-playbook
  9. Ransomware activity continues to increase:
    https://www.cybersecuritydive.com/news/ransomware-concentrated-ai-guidepoint/824828/
  10. Russian criminal group uses Trojanized software applications to target users in the US and Europe:
    https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/

Cyberheist 'Fave' Links

This Week's Links We Like, Tips, Hints and Fun Stuff