Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Phishing Links Sent Via Legitimate Google Drive Notifications

Scammers are abusing a Google Drive feature to send phishing links in automated email notifications from Google, WIRED reports. By mentioning a Google user in a Drive document, the ...
Continue Reading

Cannabis Company GrowDiaries Suffers Data Breach of 3.4 Million Users

A recent report from SiliconANGLE released information that cannabis company GrowDiaries suffered a data breach with details of 3.4 million users being exposed online.
Continue Reading

Thinking Skeptically About Smishing

Organizations need to train their employees to be on the lookout for SMS phishing (smishing), according to Jennifer Bosavage at Dark Reading. Bosavage explains that attackers exploit ...
Continue Reading

[On-Demand Webinar] Top 5 IT Security Myths Your CISO Believes Are True… BUSTED!

Facts are facts, but what happens when IT security pros take myths at face value?
Continue Reading

Organizational Security Posture Effectiveness Declines by 38% Due to COVID

Remote workforces, insecure devices, a lack of multi-factor authentication, and a lack of user education all add up to a security nightmare for the average organization today.
Continue Reading

WARNING: Americans’ Password Habits are Horrible, Putting Organizations at Risk

New data shows the average American uses short, uncomplicated, and often predictable passwords, practices which only increase the insecurity of corporate user accounts.
Continue Reading

Cyber Insurers Expect to Raise Ransomware Policy Premiums as Much as 25%

The increase in the frequency of ransomware attacks, as well as the rise in the demanded ransom amounts is causing cyber insurers to change tactics to limit their risk.
Continue Reading

Manipulation by Disinformation: How Elections are Swayed

Security Serious Week 2020 focused on disinformation, and there were many talks, tweetchats, presentations, panel discussions, and blogs.
Continue Reading

Conman in the Secret World

Last week, Garrison Courtney, a former spokesman for the US Drug Enforcement Administration, was sentenced to seven years in prison for running a massive Ponzi scheme involving dozens of ...
Continue Reading

[SCAM OF THE WEEK] Sean Connery's Final Wish is Revealed

After the sad passing of famous actor Sir Sean Connery, Yahoo News released an article that revealed his final wish after he passed away peacefully with his family at his side.
Continue Reading

[HEADS UP] British Broadcasting Corporation Receives 250,000 Phishing Emails a Day

Popular public service broadcasting station British Broadcasting Corporation (BBC) has received a quarter of a million phishing emails per day, according to a Freedom of Information (FOI) ...
Continue Reading

JavaScript Obfuscation on Phishing Pages Continues to Rise by 70%

The use of JavaScript to obfuscate phishing pages increased by 70% in the ten months between November 2019 and August 2020, according to researchers at Akamai. Attackers use this ...
Continue Reading

Famous VC Firm: "The New Attack Surface is Your Life"

As a CEO with VC investors, I follow what happens in the venture capital space and what things VCs are interested in regarding their investment strategies. I was happily surprised to see ...
Continue Reading

Learn to Combat These Three Cybersecurity Monsters This Halloween and Beyond

It’s that time of year again. The air feels a bit crisper; the days are a bit shorter; and children around the world prepare to go trick or treating. Even as an adult, Halloween is ...
Continue Reading

KnowBe4 Fresh Content Updates from October: Including New SCIM Integration Support for Azure Active Directory

Here are important fresh content updates and new features to share with you for the month of October.
Continue Reading

Cybersecurity Awareness Month Lessons Learned: Out of Bounds Communication

When staying safe online, it’s important not to go “out of bounds” for communication. Simply put, going out of bounds could mean a recipe for how your users could fall victim to a ...
Continue Reading

New Ransomware, OldGremlin, Coming Soon to an Organization Near You!

Pay attention to this one. Despite only targeting Russian companies, the use of custom self-made malware and decidedly creative phishing campaigns makes them a potential danger.
Continue Reading

Phishing Attacks Can Come from an Unlimited Number of Trusted Phishing Sites Thanks to Google App Engine

Scammers are taking advantage of Google’s Trust Service Verification and the way their App Engine creates unique URLs to host trusted landing pages used in phishing scams.
Continue Reading

More Ransomware Creators Jump on the Leak Site Bandwagon as the Number of Sites and Data Breach Posts Skyrocket in Q3

The third quarter saw massive increases in activity by ransomware gangs both creating leak sites and posting to them about recent attacks on orgs that, presumably, didn’t pay the ransom.
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews