Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Are Account Takeovers Driving Towards a Passwordless Future?

The bad guys will try to take over accounts all the time. Logging onto someone's account with their credentials is usually a whole lot easier than trying to compromise the website ...
Continue Reading

Voicemail-Themed Phishing Attacks on the Rise

Researchers at Zscaler warn of an increase in voicemail-themed phishing campaigns designed to steal credentials for enterprise applications. The emails purport to be automatically ...
Continue Reading

[Heads up]  CISA And NSA Urge “Immediate Action” To Secure National Critical Infrastructure

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) have issued a joint advisory warning that foreign hackers are targeting systems that ...
Continue Reading

BEC is the Largest Cyber Threat to UK Sports Entities

The UK’s National Cyber Security Centre (NCSC) released a new report revealing that sports organizations are more than twice as likely to suffer a cyberattack than organizations in other ...
Continue Reading

Third Party Digital Risk Significantly Increases as Organizations Continue to Work From Home

It's no secret that in the last year we have seen a huge shift to remote work at a rapid speed. A recent Forbes article covered that during this time third party (supply chain) risk has ...
Continue Reading

[HEADS UP] Cyber Attack at University of York Steals Personal Information from Staff and Students

In a recent report by the York Press, University of York has launched an investigation after personal information of students and staff was obtained by the bad guys.
Continue Reading

Don't Overlook Policy When Designing Security

There’s no single defense against phishing and other social engineering attacks, according to Kevin O’Brien, CEO and co-founder of email security company GreatHorn. On the CyberWire’s ...
Continue Reading

Testing 1… 2… 3…

Let’s face it, very few organizations thought they’d still be in workforce limbo as we near the six-month mark of the pandemic. This situation has stretched many organizations to adopt ...
Continue Reading

Argentinian Telecom Company is the Latest Victim of REvil Ransomware, with 18,000 Endpoints Infected

The ransom in excess of $7.5 Million is only one of many remediation issues Argentina’s largest ISP has to address, with it appearing that the entire network was compromised in the ...
Continue Reading

I Testified Before U.S. Congress About COVID-19 Phishing Scams

Yesterday, July 21, 2020 I testified before U.S. congress about COVID-19 phishing scams. I was invited by the Senate Commerce Committee's subcommittee on manufacturing, trade, and ...
Continue Reading

KnowBe4 Releases New Training Module: Face Masks At Work: 8 Essential Tips

Our team has been working on building a whole new course library of new compliance topics that will likely release sometime in 2021.
Continue Reading

“Service Desk” Phishes in Enterprise Waters

A phishing campaign is impersonating an IT help desk and abusing legitimate cloud services to fool users, according to Ax Sharma at BleepingComputer. The emails are sent from the ...
Continue Reading

Brand-New Tool: Browser Password Inspector Helps Find Risky Passwords Your Users Save in the Browser

Cybercriminals are always looking for easy ways to hack into your network and steal your users’ credentials.
Continue Reading

Emotet Returns Using Familiar Phishing Tactics

Emotet, the venerable commodity banking Trojan, is being actively distributed again, according to researchers at Malwarebytes. Emotet’s botnets began sending out phishing emails on July ...
Continue Reading

New “servicedesk.com” Phishing Attack Uses Microsoft, IBM Cloud Services to Add Legitimacy

Focused on stealing victim credentials, this new attack uses a number of tactics to establish credibility, avoid raising red flags, and ensure they get the victim’s real credentials.
Continue Reading

Phishing Attack in Finland Uncovers Sophisticated Smishing Scheme

The Helinski Police Department is investigating a sophisticated smishing scheme in which attackers were able to steal more than 200,000 euros (US$228,736), Yle reports. The scammers sent ...
Continue Reading

Phorpiex Botnet Attacks Spike So High in June, 2% of *All* Organizations Were Hit

The rise in the use of this dangerous botnet, notorious for distributing malware via phishing campaigns and responsible for fueling Sextortion scams, should put organizations on edge.
Continue Reading

Expect to See Data Theft as Part of More Ransomware Attacks in the Future

With data theft currently experienced in 10% of ransomware attacks, experts predict this trend to increase as cyber criminals look for ways to ensure ransom payment.
Continue Reading

Impermissible: Be Suspicious of Permission Requests

Users need to be wary of requests for information or permissions, even if they appear to come from legitimate sources, according to Don MacLennan, Senior Vice President of Engineering and ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews