惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IT之家
IT之家
Recent Announcements
Recent Announcements
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The GitHub Blog
The GitHub Blog
MyScale Blog
MyScale Blog
爱范儿
爱范儿
GbyAI
GbyAI
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
美团技术团队
Y
Y Combinator Blog
博客园 - 叶小钗
Apple Machine Learning Research
Apple Machine Learning Research
Martin Fowler
Martin Fowler
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
罗磊的独立博客
M
MIT News - Artificial intelligence
博客园 - Franky
V
Visual Studio Blog
I
InfoQ
V
V2EX
Hugging Face - Blog
Hugging Face - Blog
腾讯CDC
博客园 - 司徒正美
L
LangChain Blog

Human Risk Management Blog

Future-Proofing Organizations in the Face of AI What Security Can Learn From Dinosaurs Inside the OS-Aware Phishing Kit Profiling Your Device CyberheistNews Vol 16 #30 [Protect Your Users] AI Hallucinations Are Fueling Phishing Attacks Majority of Organizations Hit by Targeted Impersonation Attacks The Open-Source Paradox: Navigating the New Frontier of AI Supply Chain Risk Introducing The Hybrid Nudge Experience: Outbound Email Security Built for Your Risk Appetite Elevating the SOC Experience: Smarter Automation, Richer Threat Intelligence, and AI-Native Investigation New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication From Inbox to Encryption: How Ransomware Delivery Has Evolved Attackers Exploit AI Hallucinations to Send Users to Phishing Sites Warning: ARToken Phishing Kit Automates BEC Attacks Trust Nothing: Tips to Secure AI Tools and Agents CyberheistNews Vol 16 #29 ClickFix Social Engineering is Now the Leading Malware Delivery Method Beyond the Checkbox: How a Proactive Partnership Led to Turnkey Hazing Compliance Trust, Verify, Protect: Modernizing Email Security for the Cloud Report: Social Engineering Remains a Central Part of AI-assisted Attacks ClickFix Social Engineering is Now the Leading Malware Delivery Method CyberheistNews Vol 16 #28 Your 2026 Phishing by Industry Benchmarks: The Findings on Human Risk Scammers Can Use AI Tools to Pinpoint Your Location Based on a Photo Report: Attackers Are Using AI to Automate Social Engineering Your KnowBe4 Fresh Compliance Plus Content Updates from June 2026 From Awareness to Digital Workforce Security Your KnowBe4 Fresh Content Updates from June 2026 Threat Actor Uses Phishing to Breach Orgs for Ransomware Gangs Invoice Phishing Attacks Are Abusing the Shop App Phishing Campaign Impersonates Interpol to Deliver Ransomware Prompt Injection and the Rise of Agentic Risk Hyper-Targeted Social Engineering Needs Real-Time Video Response Your Email is Protected. Is Your Teams Chat?
The New Face of AI Risk
Javvad Malik · 2026-07-22 · via Human Risk Management Blog

Javvad Malik, Lead CISO Advisor at KnowBe4Cybercrime used to have a ‘"tell." It was the digital equivalent of a villain stroking their cat - clunky grammar, misspelt links and suspicious attachments that screamed ‘phishing’.

But the arrival of AI has changed everything. Typos have been replaced by perfect prose. Generic lures have evolved into highly personalized attacks that mimic your internal language and align with your project timelines. These attacks don't just land in an inbox; they adapt in real-time if you engage and they can be deployed at a scale we’ve never seen before.

The once-a-year security awareness training was built for a world that no longer exists. When threats are continuous, your defense cannot be sporadic. Organizations need to move toward live coaching — real-time nudges that guide users exactly when they are about to make a high-risk decision.

The Hybrid Workforce

Your organization's directory is no longer just a list of names. It’s a complex ecosystem of humans and their AI agents, held together by APIs, SaaS integrations and a healthy dose of optimism.

These digital assistants are incredibly helpful. They’re drafting code, managing calendars and interacting with customers. But they are also vulnerable. An attacker doesn't always need to trick a human; they can trick an agent into oversharing data or overwriting critical files.

When security teams respond by simply locking everything down, it creates a "shadow AI" problem. Staff will always find a way to use the tools they need to get the job done. The real risk lives in that blurry area between what is officially permitted and what is functionally necessary.

Speed and Precision at Scale

What actually changes when AI takes the lead in cyberattacks? Two things: precision and speed.

  1. Context Over Content: Attackers can now generate thousands of tailored messages that look like routine business. Red flags are no longer about bad spelling. Today’s phish arrives mid-thread, using the correct tone to ask for a plausible favor. In this environment, understanding the context is more important than checking the content.
  2. Multichannel Conversations: These aren't slow one-off emails; they are rapid dialogues. An attack might start as an email, move to a chat app, and culminate in a quick “verification” video call on a Friday afternoon.

Setting the Controls

To counter a rising tide of risk, we need guidance that appears just at the right time and place.

Imagine a system that interrupts a dangerous action with a simple prompt: "This attachment is from an unfamiliar sender — send to security for a quick check?" or "Payment details have changed; please verify via a secondary known channel." This allows the business to move fast without removing the safety net.

We also need to govern AI agents with the same rigor we apply to colleagues.

  • Identity and Access: Give agents unique, rotating credentials.
  • Least Privilege: Keep their permissions narrow and explicit.
  • The Human Loop: If an agent wants to perform a high-risk task (like moving money or changing permissions), it should require a human sign-off.
  • Logging: Record everything. If a bot makes a mistake, you need a breadcrumb trail to figure out why it thought that action was reasonable.

Cultivating a "No-Fear" Culture

Ultimately, your strongest defense is your culture. If your security policy relies on punishment, your employees will hide their mistakes. When people fear being reprimanded, they won't report a suspicious link until it's too late.

We need to reward transparency. Praise the near misses and make the secure path the easiest one to take. When you explain the why behind a rule, people are more likely to follow it.

In an AI-augmented world, thread-hijacking is caught because someone notices a subtle shift in timing or tone. A vendor’s bank change is flagged because the workflow demands a manual callback. Sensible points of critical thinking that protect the team.

Leaning into the Workflow

AI has made cyber threats faster and more personal. The solution isn't to retreat or rely on outdated training modules. It’s to integrate security into the actual flow of work.

The modern workforce is a hybrid of human intuition and machine speed. To stay safe, we have to secure the entire team as one.