Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

U.K. Snack Manufacturer Expects Months of Delays After Ransomware Attack

Orders of top-selling snack brands from KP Snacks are on hold in the aftermath of a Conti ransomware attack that includes data theft of confidential information.

Your KnowBe4 Fresh Content Updates from January 2022

Check out the 20 new pieces of training content added in January, alongside the always fresh content update highlights and new features.

Web Trackers Collect Much More Info About Your Users’ Browsing Activity Than Previously Believed

Researchers at Norton LifeLock have found that web trackers are collecting much more information about users’ browsing activity than had previously been believed. Such trackers can follow ...

[New Feature] Give Your Users Additional Learning Opportunities Driven By AI with New AI-Recommended Optional Learning Feature

We are excited to announce that the power of AI has been brought to the KnowBe4 Optional Learning feature to offer users suggestions for additional training opportunities.

1 in 7 Ransomware Extortion Leaks Include Sensitive Operational Technology Details

New analysis of published data from ransomware attacks puts the spotlight on the potential that some of your most critical data stolen puts you materially at risk of another attack.

Opinion: Is Your Cyber Insurance Going To Cover “Cyber War”?

With the lines increasingly blurred between whether a cyber attack is “state sponsored” or just a malicious group of individuals, we’re likely going to see more denials of claims.

KnowBe4 Unveils Official Trailer for ‘The Inside Man’ Season 4

We’re excited to announce the release of the official trailer for Season 4 of the award-winning Knowbe4 Original Series - ‘The Inside Man’!

COVID-19 Test-Related Phishing Scams Jump 521% Into January

New data shows a massive increase between October 2021 and January 2022 in phishing attacks focusing on one of the world’s current concerns for home and in-office testing.

8 New Malware Payloads Spotted As Part of Attacks Against Ukrainian Targets

Security Threat Researchers at Symantec have published details about malware being put out by the “Gamaredon” threat group (who have been tied to Russian Federal Security Service), ...

New Phishing Campaign is Impersonating Zoom to Steal Credentials

A phishing campaign is impersonating Zoom in order to steal users’ Microsoft credentials, according to Lauryn Cash at Armorblox. The emails landed in about 10,000 inboxes, and targeted “a ...

CyberheistNews Vol 12 #05 [Heads Up] DHS Sounds Alarm on New Russian Destructive Disk Wiper Attack Potential

CyberheistNews Vol 12 #05 | Feb. 1st., 2022 [Heads Up] DHS Sounds Alarm on New Russian Destructive Disk Wiper Attack Potential CNN just reported on a Jan 23 Intelligence Bulletin from the ...

Beware of QuickBooks Payment Scams

Many small and mid-sized companies use Intuit’s very popular QuickBooks program. They usually start out using its easy-to-use base accounting program and then the QuickBooks program ...

Increased “Shipping Delays” Now Served as Phishbait

Attackers are exploiting pandemic-related supply-chain disruptions to launch phishing campaigns, according to Troy Gill, senior manager of threat intelligence at Zix. In an article for ...

KnowBe4 Continues to be One of Okta's Most Popular Apps in the 2021 Businesses at Work Report

We're pleased to announce that we have been featured in Okta's eighth edition of the "Business at Work" report. This report is an in-depth look into how organizations and people work ...

[On-Demand Webinar] A Data-Driven Approach for Your Third-Party Risk Management Processes

As organizations have increased their scope of vendors and partners, they have also increased their digital risk surface and are facing new challenges regarding vendor risk management. By ...

Microsoft Warns of Latest “Consent Phishing” Attack Intent on Reading Your Email

Rather than steal your user’s credentials, this latest attack takes the OAuth route to gain access to the victim’s mailbox. This gives cybercriminals continual access, regardless of ...

Dark Web Service Sells Access to Compromised Accounts and Browser Sessions

When we hear about compromised credentials, there’s always the question of “How are they used post-compromise?” In one case, they are fully on display for sale to the highest bidder.

Malicious Office Documents Jump to 37% of All Malware Downloads at the End of 2021

With the ubiquitous use of Microsoft Office today, it should come as no surprise that malicious macro-laden documents continue to reign, with PPT files delivering AgentTesla taking the ...

[Heads Up!] DHS Sounds Alarm on New Russian Destructive Disk Wiper Attack Potential

CNN just reported on a Jan 23 Intelligence Bulletin from the US Department of Homeland Security (DHS) that warned state and local governments and critical infrastructure operators about ...

Ransomware Operators Try to Recruit Insiders

Sixty-five percent of organizations report that their employees have been contacted by ransomware attackers in an attempt to recruit insider threats, according to researchers at Pulse and ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.