Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

John Scimone, SVP and Chief Security Officer at Dell Technologies, says “security is everyone's job.”

Organizations need to build a culture of security in order to defend themselves against cyberattacks, according to John Scimone, Senior Vice President and Chief Security Officer at Dell ...

FBI: Cyber Attacks Target Organizations Involved in Mergers and Acquisitions

A new notification from the FBI warns organizations of attacks at the perfect time when organizations are spending money, new people are being introduced, and operations are in flux.

Email Classified as ‘Malicious’ by Employees Has Increased by 35% in the Last Year

New data shows Phishing, Vishing, Social Media attacks, and Microsoft 365 credential attacks are all on the rise as more users are demonstrating savviness around identifying malicious ...

Phishing Attacks Impersonating Amazon Continue, Raising Concerns on the Cusp of Black Friday and the Holidays

New phishing attacks in the form of impersonated Amazon order confirmation emails cause potential victims to make phone calls and give up credit card details.

Planning on Relaxing During the Holiday? Think Again – Ransomware Attacks May Have You Working Over a Holiday Break!

New data shows a majority of organizations experience ransomware attacks during holiday breaks, disrupting operations and your time away from work!

Avoid Donating to Charity Scammers During Giving Tuesday 2021

Giving Tuesday is a great way for organizations and people to give back. However, this gives cybercriminals opportunities to take advantage of you with charity scams.

[Scam of the Week] Black Friday & Cyber Monday Cybersecurity Tips 2021

Cybercriminals are at it again with holiday phishing scams. Because of the popularity of online shopping, retailers' online Black Friday deals attract more and more scammers every year. ...

SEC Warns of Spoofed Emails Impersonating Their Employees

Scammers are impersonating the US Securities and Exchange Commission (SEC) with spoofed phone calls and other communications that attempt to steal money and personal information from ...

New Dangerous and Persistent "Metamorphic" Malware Strain Called Tardigrade

Michael Kan at PCMag reported on this new strain of Windows malware. It can constantly adapt to avoid detection and was first found targeting the biotech industry, including the ...

Phishing Campaign Targets TikTok Influencers

Phishing emails are targeting large TikTok accounts with phony copyright warnings or offers for account verification, according to researchers at Abnormal Security.

Microsoft Exchange Server Flaws Now Exploited for BEC Attacks

Threat actors are using a couple of dangerous, new tactics to exploit the so-called ProxyShell set of vulnerabilities in on-premises Exchange Servers that Microsoft patched earlier this ...

'Fake Ransomware' as a Form of Social Engineering

Attackers are exploiting a vulnerability in a WordPress plugin to deface several hundred websites with phony warnings of ransomware, the Record reports. Researchers at Sucuri found that ...

Social Engineering, Persistence, and a Few Phone Calls is All it Takes to Steal $1 Million

The story of a Swiss investor who was convinced they were purchasing pre-IPO shares of AirBnB is the cautionary tale of how little it really takes to turn someone into a victim.

Ransomware Gangs Now Have Enough Money to Afford Zero-Day Exploits

Normally so expensive that they are only associated with nation-states, zero-day vulnerabilities are now within reach of ransomware gangs that have amassed fortunes to continue attacks.

Malicious Retail Phishing Sites Spike Ahead of Shopping Holidays

Researchers at Check Point have observed a record number of malicious phishing shopping websites that have been set up over the past two months. The researchers assume these sites were ...

Trends in Cybercrime Report Phishing, Non-Payment Scams, and Extortion

Social engineering attacks account for the vast majority of cybercrime in the US, according to researchers at SEON. The security firm found that phishing, non-payment or non-delivery ...

Rosa Smothers is Featured in the Women Know Cyber Documentary

Our very own Rosa Smothers, SVP of Cyber Operations, has been featured in the Women Know Cyber documentary by Cybercrime Magazine.

Phishing Emails Use Small Font Size to Bypass Security Filters

Researchers at Avanan have spotted phishing emails that use a font size of one to fool email security scanners. The emails appear to be password expiration notifications from Microsoft ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.