Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Make sure 'challenge questions' aren't a backdoor into your account!

The Lookout Mobile Security Blog pointed out something important. Patty talked about the man who hacked hollywood: "Finding a working e-mail address was a simple process of trial and ...
Continue Reading

Omaha cast net that caught cyberthieves

Matthew Hansen, World-Herald Staff Writer just wrote a great article that illustrates what I have been warning about these last years. It starts out like this: "Imagine for a moment that ...
Continue Reading

Hacking The Hackers: A Counter-Intelligence Operation

Marc Weber Tobias, a contributor to Forbes Magazine wrote a very interesting article: "One of our security lab team members is an ex-cyberspook who spent his career in the military doing ...
Continue Reading

2012 Doomsday Scam Continues to Serve up Doom, Giftcards

Chris Boyd over at GFI wrote: "If we survive the Mayan Apocalypse of 2012, does that mean we’re technically immortals? I’ve no idea, but it will probably mean we don’t see quite as many ...
Continue Reading

How to Start an IT Security Awareness Program

Mike Chapple is an IT professional and assistant professor of computer applications at the University of Notre Dame. He wrote at biztechmagazine:"Are your users aware of their ...
Continue Reading

If PCI Is Your Whole Security Program, You’re Not Doing Your Job Right

Steve Ragan at the SecurityWeek site, wrote: "Painless PCI assessments are possible if you work for them. For most CISOs, the pain of an audit is part of the job, but it doesn’t have to ...
Continue Reading

Check Out This NY Traffic Ticket Phish!

Kevin Mitnick sent this phish over. It's a classic attempt to get you to avaid a problem, but the moment you click this link, life will become a lot more painful. So... Stop. Look. Think ...
Continue Reading

The Latest Anti-Phishing Working Group Report

This week, the new APWG Global Phishing Report is being today at the Anti-Phishing Working Group meeting in Prague. This report is published every six months, detailing how phishers are ...
Continue Reading

New 2011 Report on Russian Cybercrime

Group-IB, a leading Russian cybercrime investigation and computer forensics company and LETA Group subsidiary, this week announced a 28-page report on the Russian cybercrime market in ...
Continue Reading

Antivirus 10-Second Flash Survey: Is this bonus attractive?

You're in the market to replace your existing Antivirus. One of the vendors on your shortlist has a Special Bonus they are offering. They are going to give you a free high-quality ...
Continue Reading

CyberheistNews vol 2, #19

Continue Reading

This is cool. USB drive uses voice recognition security

Fingerprint recognition has long been used to protect sensitive data on USB drives - here’s another approach. This 8GB USB storage device uses voice recognition software to detect a ...
Continue Reading

Bogus Olympics 2012 Email Warning Blindside Users With Malware

The upcoming London Olympics is undoubtedly one of the most highly-anticipated sports event of the year. It is also a favorite social engineering ploy among cybercriminals. Just recently, ...
Continue Reading

Weak passwords STILL subvert IT security

Jaikumar Vijayan over at Computerworld observed correctly: "A recent data breach that exposed the Social Security numbers of more than 280,000 people served as yet another reminder of the ...
Continue Reading

CyberheistNews vol 2 #18

Continue Reading

8 Dirty Secrets Of The IT Security Industry

Bill Brenner at CSO Magazine is quoting IBM ISS Security Strategist Joshua Corman who has been on a crusade with his 8 Dirty Secrets campaign. Here they are and I'm quoting Dirty Secret ...
Continue Reading

Scam Of The Week: 'The Evil Unsub'

An ordinary piece of spam slips through the filters, and you see a gorgeous sandy beach with palm trees. It's an enticing ad for a vacation to a tropical island, basically a big picture ...
Continue Reading

Six Steps To Successful Security Awareness Training

Continue Reading

You Got Hacked! What Now?

Neil Rubenking, who has been writing about antivirus for 30 years now, came up with an excellent article about what to do when your personal email or social media account. This is a ...
Continue Reading

BYOD: 'the inmates of the asylum have control'

IT pros surveyed by Network World and SolarWinds shared a range of tactics for handling the mobile device management challenge. Mobile devices are multiplying and -- sanctioned or ...
Continue Reading

Spoiler alert: Your TV will be hacked

Last week you may have read a headline that blared "100 million TVs will be Web-connected by 2016." Regular readers of this blog know I'm always on the lookout for new threats, so the ...
Continue Reading

Pinpoint Unsavory Elements In Your Neighborhood

The Criminal Tracker app by U.S. Publications Inc says that a study by the U.S. Department of Justice has revealed that sex offenders are four times more likely to re-offend than other ...
Continue Reading

CyberheistNews vol 2, #17

Continue Reading

Antivirus is 30 years old

[caption id="" align="alignleft" width="260" caption="Vaccine"][/caption] Simon Edwards created a great blog post about this April 12, 2012. He started out with: " Once upon a time, ...
Continue Reading

Blast from the Antivirus Past

[caption id="" align="alignleft" width="250" caption="MS DOS 6.0"][/caption] Remember MS-DOS Version 6? It was released March 1993. The new 6.0 had a lot of new stuff including a basic ...
Continue Reading

Video: How a crimepack works

Cybercriminals are as organized and industrious as any legitimate business. Case in point: exploit kits, also known as crimepacks, which bad guys can purchase and which make infecting ...
Continue Reading

SMS-controlled Malware Hijacks Android Phones

Researchers at NQ Mobile, working alongside researchers at North Carolina State University, have discovered new Android malware that is controlled via SMS that can do a number of things ...
Continue Reading

99 Percent Of Malicious Action Starts On Workstations

Roger Grimes made this remark on InfoWorld when he commented on the 2012 Verizon Data Breach Investigations Report that was released last week. What he said was: "You should enable event ...
Continue Reading

AV Vendor claims 600,000 Infected Macs in Botnet

The CSO website reported: "A Mac trojan horse spotted by security analysts since last year has infected more than 600,000 Apple computers, says Dr. Web, a Russian antivirus vendor. Apple ...
Continue Reading

Remove Hidden Data And Personal Information By Inspecting Documents

This is a good hint for your users from the Microsoft website: "If you plan to share an electronic copy of a Microsoft Word document with clients or colleagues, it is a good idea to ...
Continue Reading

If You Do The Cyber Crime, Expect To Do The Time

Roger Grimes at InfoWorld observes something encouraging..."Every public speaker and writer likes a good catchphrase or refrain that will grab the audience's attention. One of mine: ...
Continue Reading

CyberheistNews Vol 2, #15

Continue Reading

Finally Defined: 'Advanced Persistent Threat'

[caption id="" align="alignleft" width="650" caption="Advanced Persistent Threat"][/caption]
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews