Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

KnowBe4 Philosophy

[caption id="" align="alignright" width="250" caption="KnowBe4 Philosophy"][/caption] We are happy to go against the grain. We’re not a massive developer that turns out bloatware year ...
Continue Reading

Bank Settles With California Cyberheist Victim

[caption id="" align="alignleft" width="300" caption="Bank Settles With Cyberheist Victim"][/caption] Finally, a positive outcome in a cyberheist lawsuit. Brian Krebs reported that a ...
Continue Reading

60 Million Euro Stolen In Biggest Cyberheist Ever

[caption id="" align="alignleft" width="390" caption="60 million Cyberheist"][/caption] This is exactly what I have been warning against in my book cyberheist. McAfee and Guardian ...
Continue Reading

Need to protect a critical machine? Use Whitelisting, not Antivirus

[caption id="" align="alignleft" width="290" caption="2002 Good vs. Bad"][/caption] And now a mainstream antivirus vendor is saying this too. First of all, I have no dog in this fight, ...
Continue Reading

Why pill pushing spam pays off

[caption id="" align="alignleft" width="290" caption="Rogue Pill Demand"][/caption] Brian Krebs is on a roll. Here is why pill pushing spam pays off. "Consumer demand for cheap ...
Continue Reading

OMG - I did not know it was THIS horrible.

[caption id="" align="alignleft" width="290" caption="Top malware email attacks in past 30 days. Source: UAB"][/caption] More from Brian Krebs's astounding blog post today. "As the chart ...
Continue Reading

A Closer Look: Email-Based Ransomware Attacks

With the increase of email phishing attacks being the primary attack vector, ransomware payments have risen to 60%, it's important to take a closer look at email-based ransomware attacks.
Continue Reading

Powerful New System Admin Tool: InstantRevert

[caption id="" align="alignleft" width="370" caption="InstantRevert, a powerful new system admin tool"][/caption] KnowBe4 has released a powerful new system admin tool: InstantRevert. ...
Continue Reading

Message From Kevin Mitnick

Kevin sent the folowing letter to 1,442 people that over the last 3 years filled out the his contact us form on the www.mitnicksecurity.com website. Of these, 1082 were delivered. Now, ...
Continue Reading

15 social media scams

From Facebook phishing lures to Twitter and Tumblr hoaxes, here are 15 scams to watch out for on social networking sites. CSO online took the time to put this slide show together and it's ...
Continue Reading

Microsoft : "Civilian casualties inevitable in government cyber war"

Alastair Stevenson at the V3 site quoted Microsoft: "Cyber attacks such as Duqu, Stuxnet and Flame will inevitably hurt private companies and innocent people as well as governments, ...
Continue Reading

Kevin Mitnick Partners With KnowBe4

[caption id="" align="alignleft" width="225" caption="Kevin Mitnick"][/caption] Kevin Mitnick Partners With KnowBe4 Kevin Mitnick, at One Time the World's Most-Wanted Hacker, Joins Forces ...
Continue Reading

Double-check that cashiers check

[caption id="" align="alignleft" width="350" caption="fake cashier's checks"][/caption] The fake cashier's check scam has gotten more sophisticated. Cathy Bussewitz at the pressdemocrat ...
Continue Reading

Scam Of The Week

[caption id="" align="alignleft" width="260" caption="LeakedIn"][/caption] Never 'check' your password. Change it! The last few weeks, it came to light that some major websites were ...
Continue Reading

Survey Says: ACH Fraud Losses Down

[caption id="" align="alignleft" width="260" caption="Tracy Kitten"][/caption]It's not all bad news! Tracy Kitten over at BankInfoSecurity reported on a positive trend. "Banks are doing a ...
Continue Reading

Half of Small Businesses Not Concerned About Security Breaches [INFOGRAPHIC]

Samantha Murphy at Mashable wrote: "Shred-It conducted a survey among 1,136 U.S. small business owners with companies of fewer than 100 employees, and 100 corporate-level executives who ...
Continue Reading

Atomic scientists compare cyberwar to development of nuclear bomb

Foxnews reported on June 15, 2012: "Cyberbombs are the new atom bombs." "The Bulletin of the Atomic Scientists warned Friday that the race to build and deploy cyberweapons -- secret ...
Continue Reading

CyberheistNews vol 2, #25

Continue Reading

Retelling a Password Nightmare in the Wake of the LinkedIn Password Leak

Alan Shimel tell us an enlightening and cautionary tale how his password was hijacked and how much time it took him to get it all back under control. This is a warmly recommended read ...
Continue Reading

Stuxnet, Duqu, Flame: What It Means For You

The cyberweapon genie is out of the bottle, and the U.S. is engaged in a cyberwar. Now it becomes clear why the Government has been trying to get private industry to agree to certain ...
Continue Reading

Google to warn users of 'state-sponsored' hacking

The Guardian reported that Google will warn users of 'state-sponsored' hacking: "Search giant says it will alert Gmail users about targeted attacks, in move that could aid human rights ...
Continue Reading

CHANGE YOUR LINKEDIN PASSWORD NOW

LinkedIn was hacked and 6.46 million encrypted passwords have been leaked on a Russian forum. This is not good, as the encrypted passwords are relatively easy to crack. If you are using ...
Continue Reading

Why antivirus companies failed to catch Flame and Stuxnet

Arstechnica picked up the blog post of F-Secure's Chief Research Officer: A/V outfits were out of their league. Mikko Hypponen is the Chief Research Officer of F-Secure. He has been ...
Continue Reading

Apple Releases Guide To iOS Security

Techcrunch wrote: "Apple has introduced a guide to iOS security, which was posted to Apple.com sometime in late May, but is just now being noticed outside the Apple developer community. ...
Continue Reading

Microsoft releases 'Anti-Flame' Update

Redmond stated: "We recently became aware of a complex piece of targeted malware known as “Flame” and immediately began examining the issue. As many reports assert, Flame has been used in ...
Continue Reading

F-Secure Cautions about Fresh Olympic-themed Spam

F-Secure the security company based in Finland has recently cautioned that spam mails themed on the Olympics are targeting Internauts while carrying web-links to one malevolent PDF file ...
Continue Reading

Fake LinkedIn Emails To Reset Your Password

Since LinkedIn had their IPO, they have been in the news a lot more, even if only to compare them with the recent Facebook IPO Debacle. But the better known you are, the bigger target you ...
Continue Reading

Free Data Loss Prevention Suite

OpenDLP is a free and open source, agent- and agentless-based, centrally-managed, massively distributable data loss prevention tool released under the GPL. Given appropriate Windows, ...
Continue Reading

Over-55s Pick Passwords Twice As Secure As Teenagers

"People over the age of 55 pick passwords double the strength of those chosen by people under 25 years old. That's according to the largest ever study of password security, which also ...
Continue Reading

Malicious PowerPoint File Contains Exploit, Drops Backdoor

TrendLabs discovered a malicious MS PowerPoint document that arrives attached to email messages. The file contains an embedded Flash file, which exploits a software bug found in specific ...
Continue Reading

Make 30 Bucks In 30 Minutes!: Beta Test

[caption id="" align="alignleft" width="260" caption="30 Bucks In 30 Minutes"][/caption]We need immediate Beta Testers for our Internet Security Awareness Training! This is a THIS WEEKEND ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews