Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

What You Need to Know About DMARC

It's true - not enough organizations utilize DMARC, SPF, and DKIM, global anti-domain-spoofing standards, which could significantly cut down on phishing attacks. But before you implement ...

BEC Attacks Nearly Doubled in 2020

A new report from Barracuda Networks found that business email compromise (BEC) attacks have nearly doubled over the past year. These attacks made up 12% of all spear phishing attacks in ...

Cybercriminals Attempt to Exploit Australian Fears on COVID-19

The bad guys are attempting to take advantage of Australian fears of COVID-19 in 2021. The National Identity and Cyber Support Service of Australia and New Zealand ID Care recently warned ...

A Friend Needs Money Urgently? You're Probably Getting Scammed

People need to be on the lookout for phishing attacks sent from legitimate but compromised social media accounts, according to Paul Ducklin at Naked Security. Ducklin describes a scam ...

KnowBe4 Fresh Content Updates from December: Including New 2021 KnowBe4 Flagship Training Modules

Here are important fresh content updates to share with you that happened in the month of December.

[Heads Up] Here's Some Powerful Ammo To Grab More Of Your End-Of-Year InfoSec Budget

OK, let's sum up where we are, here at the end of December 2020. COVID has propelled IT from 2020 to 2030 in a matter of months. However, only a few of us were ready to have the large ...

How Can You Be More at Risk With MFA?

In my recent comment on the Solarwinds’ cyber attack, I made the claim that using multifactor authentication (MFA) can sometimes make you more at risk than using a simple login name and ...

Private Online Shopping Risks Affect Businesses, Too

Consumers aren’t the only ones who can be victimized by social engineering attacks while shopping online, according to Arab News. Employees who use work devices for personal shopping are ...

FireEye's Mandia on SolarWinds hack: 'This was a sniper round'

Joe Warminsky at Cyberscoop wrote: "The foreign espionage operation that breached several U.S. government agencies through SolarWinds software updates was unique in its methods and ...

Just 8% of U.K. Firms Offer Regular Security Training

A majority of UK businesses are failing to adequately train their remote working employees to spot security threats, according to new research from iomart. The cloud services company ...

Wedbush Analyst: "Cybersecurity spending will increase 20% in 2021 Due To SolarWinds."

Wedbush senior tech analyst Dan Ives says cybersecurity spending will increase by 20% in 2021 as more companies ramp up protection following the SolarWinds hack that compromised state ...

[HACK ALERT] Here Is A Whole New Way Cyber Criminals Empty Out Your Bank Account

Researchers at IBM discovered a brand new type of massive banking fraud campaign that raked in millions of dollars over the course of a few days before it was put to a stop.

Eye-Opening Password Predictions: Remote Work Will Increase Risk for Data Breaches

Ponemon's State of Password and Authentication Security Behaviors Report analyzes password and security behaviors over time with similar trends. We wanted to deep dive into the reports of ...

No, it's not You in the Facebook Video... it's a Phishing Link

Scammers are using compromised Facebook accounts to circulate phishing attack to the hacked accounts’ friends, according to Paul Ducklin at Naked Security. The links are sent via Facebook ...

KnowBe4 is not a SolarWinds Orion Customer

More and more companies are putting out press releases that they have found malware in their networks because of the recent SolarWinds supply chain attack. Just today Microsoft admitted ...

MountLocker Ransomware Provides a Glimpse into What’s Next in Ransomware-as-a-Service

This family of ransomware is growing in popularity with affiliates, providing them with two attack variants and appears to be establishing a new “as-a-service” business model.

Beware! The Holidays Bring the Worst Out in Cyber Scammers

With emotions running high, time running out to get that last needed gift, and a returned focus on family and what’s truly important, scammers are taking advantage at every turn.

New Office 365 Credential Scam Uses a Received Fax to Trick Victims

A clever mix of brand impersonation, a supposedly received message, a thumbnail preview, and new spoofed Office 365 logon pages are all that’s needed to trick victims into giving up ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.