Posts

KnowBe4 - Navigating Human and Agentic Risks for Financial Institutions in the APJ Region

Image
Introduction The Asia-Pacific and Japan (APJ) region, with its dynamic economic growth and technological advancements, presents unique challenges and opportunities in the realm of human risk management and agentic risk management, particularly within the financial services sector. As financial institutions strive to protect themselves from increasing cyber threats, they must align their security practices with the regulations set forth by central banks across the countries. from KnowBe4 Blog https://blog.knowbe4.com/navigating-human-agentic-risks-apj-financial-institutions

The Hacker News - New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution

Exim has released security updates to address a severe security issue affecting certain configurations that could enable memory corruption and potential code execution. Exim is an open-source Mail Transfer Agent (MTA) designed for Unix-like systems to receive, route, and deliver email. The vulnerability, tracked as CVE-2026-45185, aka Dead.Letter, has been described as a use-after-free from The Hacker News https://thehackernews.com/2026/05/new-exim-bdat-vulnerability-exposes.html

The Hacker News - RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded

RubyGems, the standard package manager for the Ruby programming language, has temporarily paused account sign ups following what has been described as a "major malicious attack." "We're dealing with a major malicious attack on Ruby Gems right now," Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, said in a post on X. "Signups are paused for the time being. from The Hacker News https://thehackernews.com/2026/05/rubygems-suspends-new-signups-after.html

KnowBe4 - Report: Most Phishing Attacks Abuse Trusted Services

Image
Phishing attacks are increasingly abusing trusted services to evade security filters, according to VIPRE’s Email Threat Trends Report for Q1 2026. The two primary methods of delivery were compromised accounts at 33% and free email services 32%. Additionally, just under 90% of attacks abused open redirects to mask phishing links. from KnowBe4 Blog https://blog.knowbe4.com/phishing-attacks-abuse-trusted-services-vipre-q1-2026

The Hacker News - New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots

Cybersecurity researchers have flagged a new version of the TrickMo Android banking trojan that uses The Open Network (TON) for command-and-control (C2). The new variant, observed by ThreatFabric between January and February 2026, has been observed actively targeting banking and cryptocurrency wallet users in France, Italy, and Austria. "TrickMo relies on a runtime-loaded APK  (dex.module), from The Hacker News https://thehackernews.com/2026/05/new-trickmo-variant-uses-ton-c2-and.html

KnowBe4 - CyberheistNews Vol 16 #19 Crafty Criminals Continue to Pose as Help Desks in Social Engineering Attacks

Image
from KnowBe4 Blog https://blog.knowbe4.com/cyberheistnews-vol-16-19-crafty-criminals-continue-to-pose-as-help-desks-in-social-engineering-attacks

The Hacker News - OpenAI Launches Daybreak for AI-Powered Vulnerability Detection and Patch Validation

OpenAI has launched Daybreak, a new cybersecurity initiative that brings together frontier artificial intelligence (AI) model capabilities and Codex Security to help organizations identify and patch vulnerabilities before attackers find a way in using the same issues. "Daybreak combines the intelligence of OpenAI models, the extensibility of Codex as an agentic harness, and our partners across from The Hacker News https://thehackernews.com/2026/05/openai-launches-daybreak-for-ai-powered.html