Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Many Ways To Hack MFA

I have spent a lot of time thinking about how to hack multifactor authentication (MFA) solutions. I have done so my whole career, deploying dozens, if not hundreds, of MFA projects. Also, ...
Continue Reading

FBI Warns that PYSA Ransomware is Targeting Schools

The FBI has warned of a wave of ransomware attacks against schools and other entities across the United States and the UK.
Continue Reading

[NEW FEATURE] Enhance Your Users’ Learning Experience with Optional Learning

You asked, we listened! We are excited to introduce the new Optional Learning feature within your KnowBe4 platform. Optional Learning enables you to offer your users additional training ...
Continue Reading

Mom Charged in Deepfake Cheerleading Plot

Raffaela Marie Spone, a 50-year-old mom from Pennsylvania, has been arrested after allegedly leveraging deepfake technology to target several of her daughter’s cheerleading rivals.
Continue Reading

Another Tax Season, Another Opportunity for Scams

It’s the start of tax season. This is the time of year when we collect our receipts and tax forms and hope for a nice big refund from the U.S. government. Unfortunately, cybercriminals ...
Continue Reading

Researchers Have Their Eye on Malicious Clones of Android Apps That Put Devices at Risk

Researchers at Check Point have found malicious apps in the Google Play Store that will download Trojans to infected devices.
Continue Reading

FBI Releases the Internet Crime Complaint Center 2020 Internet Crime Report, Losses Exceed $4.2 Billion

The FBI’s Internet Crime Complaint Center has released their annual report. The 2020 Internet Crime Report includes information from 791,790 complaints of suspected internet crime—an ...
Continue Reading

[EYE-OPENER] USA CISA Advisory on Trickbot Campaigns: Phishing Training For Employees

March 17, 2021 — The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) have observed continued targeting through spear phishing campaigns ...
Continue Reading

Ransomware Attacks Are Growing More Costly and Effective by the Day

The availability of commodity bots and ransomware is making the business of ransomware accessible to just about every. And, according to new data, everyone’s getting in on the game.
Continue Reading

Cybercrime Officially Has Its Own Global Ecosystem

From Services, to Distribution, to Monetization, cybercriminals are getting so organized, cybersecurity experts are now beginning to see how vast the relationships and connections really ...
Continue Reading

Make No Mistake, This Changes Everything: Nation-State 2.0

Every organization needs to figure out their increased cyber risk from nation-state warfare attacks and deploy mitigations.
Continue Reading

Give Me £1,000 to Stop Calling You

Some scammers are taking a more direct approach to asking for money, according to BBC reporter Jane Wakefield. Wakefield received a call from a scammer who claimed to work for Microsoft, ...
Continue Reading

[THIS IS UGLY] A Hacker Got All My Texts for $16

VICE just revealed a 2FA hole you can drive a truck through. A gaping flaw in SMS lets hackers take over phone numbers in minutes by simply paying a company to reroute text messages. This ...
Continue Reading

6 Advanced Email Phishing Attacks

No matter how good your policies and technical defenses are, some amount of phishing will get to your end users in a given month. They must be trained to recognize social engineering ...
Continue Reading

FBI Warns Against Deepfakes' Potential for Social Engineering

The FBI has issued an advisory warning of an expected increase in the use of deepfakes for social engineering attacks. Deepfakes are images, videos, audio, or text created via AI to ...
Continue Reading

Beware: Lots of COVID-19 Vaccine-Related Attacks Are Active and Looking for Their Next Victim

From spear phishing attacks, to malicious domains, to credential-hunting – as I predicted, COVID vaccines are the hot attack theme right now from just about every angle.
Continue Reading

Exchange Exploit Attempts Surge Sixfold as Ransomware Lands

The Phil Muncaster at Info Security Mag had it first: "The number of global exploit attempts targeting vulnerable Microsoft Exchange servers has risen sixfold over the past few days, as ...
Continue Reading

The Evolving Cybercriminal Market Has Given Birth to Impersonation-as-a-Service as Attackers Seek to Impersonate at Scale

New research documents Impersonation-as-a-Service (IMPaaS) as an emerging threat where profiles of victim users are available to be used in campaigns where impersonation is critical.
Continue Reading

[On-Demand Webinar] Avoiding Business Email Compromise Phishing Scams During Tax Season

Taxes are unavoidable, and unfortunately, so are the annual tax-related phishing scams. This year, with the COVID-19 pandemic continuing to keep people working from home, cybercriminals ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews