惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

AI
AI
T
Tailwind CSS Blog
雷峰网
雷峰网
人人都是产品经理
人人都是产品经理
Microsoft Azure Blog
Microsoft Azure Blog
爱范儿
爱范儿
P
Proofpoint News Feed
D
Docker
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - 【当耐特】
云风的 BLOG
云风的 BLOG
有赞技术团队
有赞技术团队
The Cloudflare Blog
Engineering at Meta
Engineering at Meta
酷 壳 – CoolShell
酷 壳 – CoolShell
U
Unit 42
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 司徒正美
博客园 - Franky
The GitHub Blog
The GitHub Blog
月光博客
月光博客
小众软件
小众软件
Martin Fowler
Martin Fowler
P
Palo Alto Networks Blog
Google DeepMind News
Google DeepMind News
Hugging Face - Blog
Hugging Face - Blog
T
Threat Research - Cisco Blogs
阮一峰的网络日志
阮一峰的网络日志
IT之家
IT之家
K
Kaspersky official blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
S
Securelist
Spread Privacy
Spread Privacy
博客园 - 聂微东
B
Blog
The Hacker News
The Hacker News
Simon Willison's Weblog
Simon Willison's Weblog
T
The Exploit Database - CXSecurity.com
S
Schneier on Security
P
Privacy International News Feed
腾讯CDC
C
Cyber Attacks, Cyber Crime and Cyber Security
T
Threatpost
T
Tenable Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Cyberwarzone
Cyberwarzone
C
Cybersecurity and Infrastructure Security Agency CISA
Stack Overflow Blog
Stack Overflow Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
H
Heimdal Security Blog

Kaspersky official blog

Real-world attacks on corporate AI agents How Google phone number verification works, and whether you should turn it off ConsentFix: a new ClickFix variation for compromising Microsoft 365 accounts How to protect your data after a breakup Email hijacking via OAuth Prompt attacks on the Gemini AI-assistant and Google Workspace with Gemini Key vulnerabilities of Microsoft’s July 2026 Patch Tuesday Meta launched and almost instantly rolled back a feature that trained its AI image generator on Instagram user content. What’s wrong with Meta's NameTag feature and why you should be wary of it Targeted phishing attacks on manufacturing companies Why CAPTCHAs are about to vanish: how AI rewrote the "prove you're human" test The unpatchable backdoor in Yarbo robot mowers | Kaspersky official blog Managing the risks of LLM aggregators and AI API proxies Social engineering: how scammers manipulate their victims How today's threat actors break into companies 250,000 misconfigurations in GitHub Actions How hackers use PowerShell scripts to steal Telegram accounts How Hola Browser was weaponized to spread a Monero miner World Cup 2026: watch out for these scams Building an autonomous SOC: core challenges and solutions The FROST attack: how SSD access delays expose users’ activity Taming shadow-AI on corporate devices Hentai games with a nasty twist XChat: what’s wrong with Elon Musk’s new messaging app? Turning off uninvited AI on corporate devices Security gateway for autonomous vehicles Is Wi-Fi safe in Mexico? The great messaging heist targeting your wallet Don’t let fake IPTV apps ruin your World Cup Attackers disguising phishing as Google AppSheet notifications Qualcomm vulnerability: phone repairs and car maintenance are no longer safe A lost art finds its way into phishing emails Is your TV box renting out your network? How to turn off unapproved AI tools across organization Subscription security: how to protect your account, your wallet… and your sanity 面向家庭和商业企业的卡巴斯基网络安全解决方案 | 卡巴斯基 What happens in the bedroom stays in the bedroom AirSnitch: attacking Wi-Fi client isolation and guest networks Fake ticket websites exploiting BTS world tour Is your security system secure? The most notable supply-chain attacks of 2025
Combating AI-powered BEC attacks
Roman Dedenok · 2026-07-13 · via Kaspersky official blog

We’ve trained our security solution to detect BEC emails generated by large language models.

Combating AI-powered BEC attacks

It’s no secret that cybercriminals have recently been leveraging large language models to optimize their operations. As a result, numerous phishing and malware campaigns targeting organizations have significantly improved in quality. These emails now contain fewer obvious errors, and their tone closely mimics legitimate business correspondence. But the methods of deploying these campaigns always have a clear giveaway: an attempt to steal credentials or execute malicious code. Business email compromise (BEC) attacks, however, present a greater challenge.

BEC attacks typically rely entirely on social engineering, effectively tricking a legitimate employee into carrying out the attackers’ requests. These attacks have also improved substantially in quality since the advent of LLMs. If the scammers’ tactics succeed — say, if they manage to convince an employee to transfer funds to a third-party account instead of a contractor’s — the company can lose substantial amounts of money in an instant. This is why we’ve developed a specialized technology to detect AI-generated BEC emails.

An example of an LLM-generated BEC email

An example of an LLM-generated BEC email

How our AI-generated BEC detection technology works

Without getting bogged down in the technical details, here’s an explanation of how this new technology operates. As you may know, large language models don’t compose text the way humans do. Instead, they predict words that are most likely to fit the task outlined in the prompt. Furthermore, cybercriminals tend to take the path of least resistance: instead of reinventing the wheel, they rely on the most widely available AI models.

Because it’s obvious what the attackers are after, we can extract BEC-specific key phrases from the text. Additionally, we’ve learned to spot when a text has been generated by a machine. These indicators are a cornerstone of our detection technology. As a result, our security solution can now identify and block attempted BEC attacks at the initial stage — before the attacker ever has a chance to mislead an employee. The technology currently detects AI-generated BEC emails in English, French, German, Italian, Portuguese, Russian, Spanish, and Turkish.

Which of our solutions feature the AI-generated BEC detection technology?

Our range of corporate security solutions includes Kaspersky Security for Mail Server, which incorporates Kaspersky Secure Mail Gateway – where our AI BEC detection technology is implemented. To be precise, the feature is available in the KSMS Plus license following the recent KSMG 3.1 update. Visit the Kaspersky Security for Mail Server official page to learn more about our email security solutions and the features added in the latest update.

Tips

AI beat CAPTCHA. What’s next?

For over a decade, internet users have had to squint at blurry fire hydrants, bridges, and bicycles — until AI came along. What’s next for the CAPTCHA?

Cracked in under a minute: (nearly) every other password

We’ve revisited our study on the crackability of real-world passwords leaked on the dark web — originally conducted two years ago. The findings are sobering: nearly every other password can be cracked in under a minute, and three out of five take less than an hour. How can we move away from insecure passwords?