Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

What happens when you type in a URL in an address bar in a browser?

I saw this post on twitter with a fun and educational infographic that shows it's quite a complicated affair where lots of things can go wrong. Here is the infographic, and if you click ...
Continue Reading

Watch Out! Cybersecurity and Infrastructure Security Agency Warn of New VBA Attack Designed to Deploy KONNI Remote Administration Tool

A new alert from CISA outlines just how dangerous and intrusive the KONNI malware is in organizations that fall for phishing attacks using Word attachments with malicious VBA code.
Continue Reading

[Heads Up] Weaponized Disinformation Campaigns Skyrocket; KnowBe4 Releases New Spot & Stop DisInfo Training Module

Disinformation is a potent weapon in the current cold cyberwar arsenal. DisInfo attacks are skyrocketing and the number of countries using organized social media manipulation is going up ...
Continue Reading

New Vishing Attacks Pretend to Be Internal IT to Scam Users from Financial Firms Out of Their Credentials

Dozens of banks, cryptocurrency exchanges, and web hosting firms have experienced vishing attacks aimed at eventually stealing cryptocurrency from high net-worth customers.
Continue Reading

[HEADS UP] There's No Beta for Cyberpunk 2077

Scammers are sending phishing emails purporting to offer beta access to the highly anticipated video game Cyberpunk 2077, Eurogamer reports. These scams have been occurring for at least a ...
Continue Reading

Phishing Summit - Mitigation, Forensics and Eye-opening Phishing Research

Looks like things are getting crazier by the month, right? The recent Twitter attack shows that all organizations are susceptible to social engineering attacks. Unfortunately, very few ...
Continue Reading

An Embarrassment of Riches: Malicious Actors Target AWS Accounts

Amazon is an obvious target for malicious actors looking to leverage the trust and authority enjoyed by a widely known online service or brand in malicious emails and social engineering ...
Continue Reading

Conversations with a Phisher

Phishing campaigns display varying levels of sophistication depending on how much time and effort the attackers are willing to invest in a particular target, according to Steven Murdoch, ...
Continue Reading

[Heads Up] DarkSide: Sophisticated New Customized Ransomware Strain Demands Millions Of Dollars

Breaking News: A new ransomware operation named DarkSide began attacking organizations earlier this month with customized attacks that have already earned them million-dollar payouts. But ...
Continue Reading

Ukrainian Gang Responsible for Laundering More Than $42 Million Arrested as Part of Operation “Bulletproof Exchanger”

A group of cybercriminals responsible for helping ransomware gangs convert their cryptocurrency into cash were arrested in June, according to new details released this week.
Continue Reading

New Vishing Scam Targets Diners at London’s Prestigious Ritz Hotel

Aimed at stealing credit card details from restaurant patrons, this new scam feels like it’s something we’re going to hear about a lot more.
Continue Reading

The Seven Dimensions of Security Culture: Attitudes

KnowBe4’s Security Culture Report is the result of data collected from 120,000 global employees in the following industries: Banking, Financial Services, Insurance, Consulting, Business ...
Continue Reading

The Most Effective Attacks Are Often the Simplest

The recent Twitter hack shows that devastating security breaches don’t always involve sophisticated actors or methods, according to Rachel Tobac, CEO of SocialProof Security. On the ...
Continue Reading

Watch Out for OAuth Phishing Attacks and How You Can Stay Safe

A steadily growing phishing trend involves phishing emails which attempt to modify your OAuth permissions. Simply clicking on one Allow button or hitting ENTER by mistake can ...
Continue Reading

Your Vishing Attack Surface Has Exploded And Voice Phishers Now Target Your Corporate VPN

Brian Krebs wrote: "The COVID-19 epidemic has brought a wave of email phishing attacks that try to trick work-at-home employees into giving away credentials needed to remotely access ...
Continue Reading

KnowBe4 Launches New Research Arm With Its First Report on Security Culture

At KnowBe4, we’ve had some exciting news on the horizon for some time now that we’re thrilled to share with you – we’ve created a new research arm called KnowBe4 Research. When we ...
Continue Reading

Social Media Doppelgangers Strike Again

Most people would be surprised by how easy it is to scam people online using duplicate versions of public accounts, according to Jake Moore, a security specialist at ESET. Moore describes ...
Continue Reading

U.K. National Health Service Targeted with Over 40,000 Email Scams Aimed at Stealing Patient Data

The last few months have been very busy for cyber attackers targeting the NHS, as the number of phishing emails reported within the NHS shows a continual barrage of attacks.
Continue Reading

Phishing Site Takes Brand Impersonation to a Whole New Level Pretending to be FINRA

Most scammers simply grab a company logo, or perhaps a logon page to make it appear like the website used as part of a scam is legitimate. But how about an entire website?
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews