Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Spotting Retail Scams During the Holiday Season

People need to be particularly vigilant for scams as we approach the holiday shopping season, according to Laura Brooks at Tessian. Scammers always take advantage of seasonal trends, and ...

[HEADS UP] Allowing Site Notifications Can be Very Costly

Krebs on Security reported that there have been an increasing number of websites asking visitors to approve 'notifications'. In most cases these notifications are not malicious, but ...

Nearly Half of Spear Phishing Emails Bypass Security Filters

47% of payloadless phishing emails are able to bypass the most popular secure email gateways (SEGs), according to researchers at IronScales. These are emails that don’t contain malicious ...

Why Use Malware When Cybercriminals Can Use Social Engineering?

Researchers at Malwarebytes warn that a malvertising campaign they call “malsmoke” has stopped deploying exploit kits and is now using social engineering attacks to trick users into ...

KnowBe4 is Named Cybersecurity Company of the Decade

We're pleased to announce that KnowBe4 has been named the Cybersecurity Company of the Decade (2010 - 2020) by Cybersecurity Ventures!

[HEADS UP] Ransomware Gangs Partner to Extort Victims

According to Bleeping Computer, several ransomware crews are teaming up to split profits obtained in malicious attacks targeting public and private companies.

Phishing in Facebook's Pond

A scam targeting Facebook users duped hundreds of thousands of people out of their money and information, according to researchers at vpnMentor. The researchers discovered an exposed ...

KnowBe4 Wins Tampa Bay Tech's 2020 Company of the Year Award

We have officially won the Tampa Bay Tech's 2020 Tech Company of the Year Award!

Ransomware Attacks Officially Hit a New Low and Go Where No Cyberattack Has Gone Before: Death

The past few months have seen ransomware quickly evolve to a place of ingenious sophistication, rampant greed, indifferent destruction, and the sad loss of life.

Cybercriminals Can Now Bypass Security Solutions and Implant Malicious Emails Directly into Inboxes with Email Appender

Taking advantage of IMAP functionality a new tool now available on the dark web empowers cybercriminals to circumvent mail scanners, virtual sandboxes, and other security solutions.

Scammers Target Singles Day Shoppers

Shoppers need to be on the lookout for scammers as Singles Day begins in China and other countries around the world, the BBC reports. Singles Day is the world’s largest online shopping ...

Emotet Makes Another Comeback with New Tactics, Techniques and Procedures

New analysis of Q3 shows Emotet attacks on the rise, complete with new methods and features that have impacted governments and enterprise businesses alike.

New “Election Interference” Phishing Scams Infect Victims with Qbot Trojan

At a time when tensions are high with questionable election results, lawsuits, and an apparent “president-elect”, makers of Qbot are taking full advantage of the opportunity.

University Research Shows Security Awareness Training is a Necessary Layer of Defense

A research paper in the Journal of Computer Information Systems says that security awareness training is a necessary complement to technical defenses and security policies, SC Magazine ...

Britain's Government Will Tackle Online Misinformation Claims on Anti-Vaccine

In a recent article by Reuters, the article covers a story from The Times on Britain's eavesdropping agency GCHQ is starting a plan to take on anti-vaccine propaganda that is being spread ...

Twitter Hack Only Took 24 Hours from Start to Takeover

A report from the New York Department of Financial Services covering the high-profile Twitter account hack from earlier in the year reveals how little time an attack takes to be ...

BEC Incidents Intent on Invoice or Payment Fraud Increase 155% Across All Industries

Business Email Compromise appears to be back in the saddle again, as attackers use simple social engineering and domain impersonation to trick victims into paying up.

Ryuk Ransomware Takes a Single Victim for $34 Million in Ransom

A new report from Security Researcher Vitali Kremez puts the spotlight on exactly how the group behind Ryuk ransomware is successful in infecting and obtaining payment from its victims.


Get the latest insights, trends and security news. Subscribe to CyberheistNews.