Posts

KnowBe4 - Your KnowBe4 Fresh Content Updates from May 2026

Image
John N Just, Ed.D. - Chief Learning Officer I have said it before, and I will say it again. Every time I think the KB4 Studios UK team has peaked, they somehow manage to outdo themselves. Season 7 of The Inside Man is here, and I could not be more proud of what this team has created. We celebrated the world premiere at KB4-CON, and the reaction in that room said it all. We also had another premiere on June 1st at the iconic Odeon Cinema Leicester Square in London — the same legendary theater where we have gathered fans in the past from around the world to experience this series on the big screen. from KnowBe4 Blog https://blog.knowbe4.com/your-knowbe4-fresh-content-updates-from-may-2026

The Hacker News - Only 10% of SOCs Say They’re Getting Excellent Value From AI. Here’s What the Second Wave Has to Deliver

Eighteen months ago, the AI SOC was a marketing line. Today it's a budget item. The category has crossed over from interesting to inevitable, with billions of dollars now flowing into AI-powered security operations platforms, agentic SOC tools, and AI co-pilots built into every layer of the security stack. The data shows SOCs are buying, deploying, and standing up AI capabilities at the fastest from The Hacker News https://thehackernews.com/2026/06/only-10-of-socs-say-theyre-getting.html

KnowBe4 - The Silent Invitation: A Deep Dive into Calendar Invite Phishing

Image
Lead Analysts: Jeewan Singh Jalal, Prabhakaran Ravichandhiran and Anand Bodke from KnowBe4 Blog https://blog.knowbe4.com/silent-invitation-calendar-invite-phishing-threat-labs

The Hacker News - Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites

Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, leading to a complete site compromise. The vulnerability in question is CVE-2026-3300 (CVSS score: 9.8), a remote code execution bug impacting all versions of the plugin up to, and including, 1.9.12. A patch for the flaw was from The Hacker News https://thehackernews.com/2026/06/hackers-exploit-critical-everest-forms.html

The Hacker News - FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins

Security researchers and the FBI are warning that a wave of FIFA-themed fraud is already hitting World Cup 2026 fans, days before the June 11 kickoff. Recent reports describe thousands of lookalike FIFA domains, banking malware hidden inside pirate streaming apps, and at least one operation that copies FIFA's login page well enough to take over real accounts. It is an obvious target. More than from The Hacker News https://thehackernews.com/2026/06/fifa-world-cup-2026-scams-are-already.html

The Hacker News - PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network

The threat actor known as PCPJack has hijacked cloud servers associated with Amazon Web Services (AWS), Google Cloud, and Microsoft Azure to create a covert SMTP email relay network. "Compromised business servers across the U.S., Europe, and Asia were quietly converted into SMTP proxies, verified for mail relay capability, and synced to a downstream consumer every five minutes," Hunt.io said in from The Hacker News https://thehackernews.com/2026/06/pcpjack-hijacks-230-aws-google-cloud.html

The Hacker News - Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public

Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and, from there, climb to root. It is tracked as CVE-2026-20230, and proof-of-concept exploit code is already public. Cisco's PSIRT says it has not seen the flaw used in attacks yet. The PoC shortens that runway. The flaw is a server-side request forgery. from The Hacker News https://thehackernews.com/2026/06/cisco-patches-cve-2026-20230-in-unified.html