Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Wanting to Stream the Italian Grand Prix This Weekend? It Might Be a Scam.

With so many fans worldwide wanting to watch the race online, cybercriminals have stepped up to meet the demand with fraudulent websites intent on stealing credit card details.
Continue Reading

5 Ways to Recognize Social Engineering

Social engineering can come in many different forms: via email, websites, voice calls, SMS messages, social media and even fax. If it is a communication method, scammers and criminals are ...
Continue Reading

A Look at Phishing Keywords

Researchers at Expel offer a useful list of the top keywords used in phishing emails. First on the list is the word “invoice,” which is a general term that will be relevant to most ...
Continue Reading

The Number of Daily Ransomware Attacks Increase Nearly 1000% in 2021

New analysis of cyberattack data by security vendor Fortinet sheds light on not only how much ransomware is really being experienced, but who’s being attacked the most.
Continue Reading

The Amount of Weekly New Phishing URLs Has Grown Nearly 2.5x Since 2020

The increase in remote users mixed with a lack of adjusting to cloud-based security services likely created the perfect opportunity for cybercriminals.
Continue Reading

BEC, Fraud, and Ransomware Attacks Are All on the Rise and Costing More Than Ever

New data from cyber insurer Coalition puts the spotlight on not only how much worse attacks are getting, but claim data paints the picture that organizations just aren’t ready.
Continue Reading

Phishing for the German Bundestag

The German government has called out Russia for carrying out phishing attacks against German politicians ahead of the country’s upcoming parliamentary elections, the Associated Press ...
Continue Reading

Windows 11 Phishbait by Active Threat Group Now Delivers Malware

Researchers at Anomali warn that the financially motivated threat group FIN7 is using Windows 11-themed phishing documents to deliver malware. The documents claim to have been created on ...
Continue Reading

Conti's Ransomware Playbook Includes Recon for Users with Privileged Access

Researchers at Cisco Talos have translated a playbook used by the ransomware-as-a-service group Conti. The playbook contains detailed instructions for how to gain administrator access, ...
Continue Reading

Be Wary of Unrequested Disc Images

Microsoft’s recent announcement that the new version of Microsoft Windows, Microsoft Windows 11, will be released soon is capturing headlines around the world. Microsoft will allow ...
Continue Reading

Email-Based Cyberattacks Double Between January and June

Over 2.9 Billion email-based threats were detected in the first half of 2021. Business Email Compromise, obfuscation, and living off the land reigned, according to new data from Zix.
Continue Reading

CISA: Ransomware Attacks Favor Holidays and Weekends

In preparation for Labor Day, a new alert from the U.S. Government’s Cybersecurity & Infrastructure Security Agency (CISA) warns of an increase in ransomware attacks.
Continue Reading

Ransomware Attacks in 2021 Have Increased Nearly Three-fold in the First Half of the Year

New data analyzed by NCC Group’s Research Intelligence and Fusion Team highlights a massive uptick in the number of ransomware attacks, further establishing it as the number one security ...
Continue Reading

Your KnowBe4 Fresh Content Updates from August

With 18 new pieces of training content added this month, check out the always fresh content update highlights and new features from the month of August.
Continue Reading

BEC and the Underworld's Resources

Researchers at Intel 471 have observed cybercriminals outsourcing talent for business email compromise (BEC) attacks. This tactic lowers the bar of entry for BEC attacks, which are ...
Continue Reading

Large Phishing Campaign Abuses Open Redirects

Researchers at Microsoft have observed a widespread phishing campaign that’s abusing open redirectors to fool users into visiting credential-harvesting pages. Open redirects are often ...
Continue Reading

When the URL Domain Is Not Enough To Avoid a Phish

One of the most common mantras in security awareness training is “Examine the URL to determine if it points to the legitimate vendor or not!”
Continue Reading

U.K. Organizations See Double the Number of Ransomware Attacks in the First Half of 2021

New analysis of ransomware incidents reported to the UK's Information Commissioner's Office (ICO) in the first half of 2021 show a massive rise when compared to 2020.
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews