Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Boy have we grown... KnowBe4 Halloween 2014, 2015, 2016

Halloween 2014 15 employees. Scroll down for the later years!
Continue Reading

Scam Of The Week: Tech Support Claims Your Hard Disk Will Be Deleted

Symantec warns that tech support scams are getting more sophisticated by the month: "These scams remain one of the major and evolving forces in the computer security landscape. Between ...
Continue Reading

How Podesta got hacked: HelpDesk said 'Password' phishing email was real

John Podesta, Chairman of the 2016 Hillary Clinton presidential campaign was a victim of social engineering and rushed advice from his IT helpdesk. It's a comedy of errors. The helpdesk ...
Continue Reading

82% of Email Servers are Misconfigured, Allowing Domain Spoofing

We reviewed thousands of domains that have been through our domain spoof test and analyzed more than 10,000 email servers. We found that 82% of these are misconfigured.
Continue Reading

Insurance underwriter Beazley: "Ransomware attacks will be four times higher in 2016"

The Wall Street Journal is getting the message. They said : "For companies concerned about the soaring number of ransomware attacks–in which hackers take control of data or systems and ...
Continue Reading

Who Is Learning How to Take Down the Internet?

It was all over the news. A sustained DDoS attack that caused outages for a large number of Web sites Friday was launched with the help of hacked “Internet of Things” (IoT) devices. Jeff ...
Continue Reading

Researchers discover new malicious IoT worm

Researchers at RapidityNetworks discovered a new malicious worm using Telnet that infects IoT devices using their insecure default credentials and uses a peer-to-peer network to install ...
Continue Reading

Ransomware Strain Count Surpasses 200

Michael Gillespie tweeted: "Whew! ID #Ransomware can now identify 200 ransomware families. :) Sad such a milestone was hit so quickly..." He added a list from the malwarehunterteam site, ...
Continue Reading

The New Posterboy of CyberInsecurity: John Podesta Fell For Social Engineering Attack

Motherboard has a great article explaining just how Podesta, Chairman of the 2016 Hillary Clinton presidential campaign got hacked. (Podesta previously served as Chief of Staff to ...
Continue Reading

A Slick Phish with a Hidden Surprise

By Eric Howes, KnowBe4 Principal Lab Researcher. Yesterday one of our customers was hit with a highly targeted phishing attack -- one of the slicker attacks we've seen in a while. Once we ...
Continue Reading

"My AV blocked RanSim.exe So I'm Safe" No You Are Not

I'm noticing a lot of people saying the ransim.exe file is getting blocked by your AV. You have to actually allow the initial processes to run to do the simulation. It is the five test ...
Continue Reading

Python Ransomware Uses A Unique Key For Each File That Is Encrypted

A new ransomware strain written in Python called CryPy was disclosed by Avast malware analyst Jakub Kroustek. It seems that Pyton is getting more popular as a ransomware development ...
Continue Reading

Yahoo Hack Triggers 'Material Adverse Change' Clause

The Wall Street Journal reported that Verizon's lawyers are looking at using the "material adverse clause' to renegotiate the terms of the $4.8 billion deal they struck on July. Verizon’s ...
Continue Reading

More than 60% of US office workers are unaware of the ransomware threat

Nearly half of ransomware attacks are aimed at office workers, but almost two-thirds of those polled are unaware of the threat More than 60% of US office workers are unaware of ransomware ...
Continue Reading

[ALERT] Scam Of The Week: Brad Pitt Found Dead (Suicide)

The divorce between Brad Pitt and Angelina Jolie has been used by the bad guys for a "celebrity death hoax" which unfortunately is high-grade click bait. It's the most recent one to hit ...
Continue Reading

AI-powered ransomware is coming, and it's going to be terrifying

Business Insider started an article with the following: "Imagine you've got a meeting with a client, and shortly before you leave, they send you over a confirmation and a map with ...
Continue Reading

October Is The Time To Kill Old-School Security Awareness Training

CSO had an excellent article that states the case that you need to get rid of old-school awareness training which you do for compliance reasons only. Their photo illustration was funny as ...
Continue Reading

Scam Of The Week: Insidious New IRS Social Engineering Attack

There is a new insidious IRS scam that you need to warn your employees, friends and family about, and inform your HR department to start with. Seasoned internet criminals are sending ...
Continue Reading

KnowBe4 beats stellar Q2 and grows 369% YoY in Q3

(Tampa Bay, FL) October 9, 2016 --- KnowBe4 is excited to announce we were able to beat our stellar Q2, and maintain our explosive year over year growth, Q3 2016 being 369% over Q3 2015. ...
Continue Reading

Did You Know That Ransomware Can Stop SQL So It Can Encrypt The Database?

I have been knee deep into Ransomware since September 2013 when the granddaddy of modern ransomware CryptoLocker made well over 20 million bucks in a few months. But sometimes I learn ...
Continue Reading

The 7 Levels Of Hackers

Eric Chabrow over at the Government Info Security blog found an interesting post by Stuart Coulson, who is a director of a hosting provider in the U.K. Coulson wrote a somewhat longish ...
Continue Reading

Massive Cerber Ransomware Campaign Flooding Your Employees' Inboxes

By Eric Howes, KnowBe4 Principal Lab Researcher. This Monday morning many of our customers came in to work to find a rather rude surprise lurking in their inboxes: a massive Cerber ...
Continue Reading

KnowBe4 Is Excited To Announce Active Directory Integration

We are stoked to announce the new integration with Active Directory! The Active Directory Integration (ADI) helps you easily upload user data and eliminate manual updates by automatically ...
Continue Reading

Is Security Making The Grade? What IT And Business Pros Really Think

Great joint survey by CSO, CIO and ComputerWorld by Amy Bennett which is excelllent ammo to add to a budget request that needs to be approved by a C-level exec. Here's why: "If you sense ...
Continue Reading

Uh oh, Yahoo May Have Been COMPLETELY Pwned

We predicted that this would happen on September 23rd when the news broke that Yahoo lost "at least" 500 Million credentials. Just for a change I'm quoting myself here: :-D "Right, that ...
Continue Reading

This weird ransomware strain spreads like a virus in the cloud

Here is a ransomware horror story for you... An obscure 2-year old ransomware strain called Virlock has a nasty feature: it is capable of stealthily spreading itself via cloud storage and ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews