Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

SEA used spear-phishing in attack on NY Times

A spear-phishing attack, one of the most common and oldest cyber tricks in the book, enabled hackers to hijack and modify the DNS records for several domains on Tuesday, including The New ...

Cybercrime Automates Fake ID's For Spear-phishing

Today it was reported through several sources that a new Cybercrime-as-a-Service option is available: creation of fake scanned passports, ID cards, driver's licenses and fake scanned ...

CyberheistNews Vol 3, # 35 Security-Awareness-Training-Newsletter

CyberheistNews Vol 3, # 35

April 8, 2014: WinXPGeddon

If you still run Windows XP April 2014, you've got a timebomb on your hands if that system is still connected to the Internet. Stand-alone systems are a bit less of a risk.

Electronic ID cards join fight against phishing attacks

Phishing attacks are believed to have hit 37.3 million people last year, escalating online password theft 300%. To fight back against this type of cyberattack, a team of researchers at ...

New Cybercrime-as-a-Service: Unethical Pen-testing

I have talked about this a few times before, there is a well-developed $3 Billion underground economy specialized in cybercrime. Here is an example of a "promising" new criminal DIY ...

Cyber risk weighs heavy on minds of execs

Tony Bradley at CSO Mag has a good analysis: " There is good news and bad new stemming from the Lloyd’s of London Risk Index 2013 report. The good news is that cyber risk is gaining more ...

CyberheistNews Vol 3, 34 Security Awareness Training Newsletter

CyberheistNews Vol 3, # 34

IT Security Is Broken Bad

With the TV show Breaking Bad in its last season, this seems to be a fun title. However, the topic is not all that much fun. You should realize it's not a question of when you will be ...

Are Your Email Addresses On A Russian Phishing Site?

We are finding many U.S. commercial email addresses at the Russianemailsworld.boommer.ru website. It is really a 'staging' area for emails to be posted by the criminal underground. They ...

Spear-phishing attackers vandalize CNN, TIME and Wash Post

You would think that by now journalists and people in media and advertising would be on the alert for social engineering red flags. But no. Syrian hacktivists sent a spear-phishing attack ...

Forbes: IT Security Industry To Expand Tenfold

Richard Stiennon, Forbes contributor makes a stunning prediction. He claims that most organizations have woefully underspent for IT Security and now that governments around the world have ...

Hackers put a bull's-eye on small business

Less than 500 employees? You’ve got a 20 percent chance of being hacked, and if it happens there’s a good chance your business is finished.

CyberheistNews Vol 3, 33

CyberheistNews Vol 3, # 33

We started trusting bad code from Day One

Vint Cerf – Photo by Charles Haynes

Scam Of The Week: "Held For Ransom"

You should alert your users that a particularly effective scam is growing by leaps and bounds recently. It's not new, but it's bursting into mainline cybercrime these last few weeks. The ...

Watching Porn on a Mobile …Risky?

The Internet has its own Red Light District, and it is one of the most unsafe areas you can browse. Online porn is a profitable sideline for the adult industry, but a mainline business ...

CyberheistNews Vol 3, 32

CyberheistNews Vol 3, # 32

Debate: Security Training Effective? What's Your Opinion...

In the August issue of SC Magazine yours truly is one of the two experts that discuss whether security training is an effective strategy in the workplace. My counterpart is Dave Aitel, ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.