Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Watch Out for OAuth Phishing Attacks and How You Can Stay Safe

A steadily growing phishing trend involves phishing emails which attempt to modify your OAuth permissions. Simply clicking on one Allow button or hitting ENTER by mistake can ...

Your Vishing Attack Surface Has Exploded And Voice Phishers Now Target Your Corporate VPN

Brian Krebs wrote: "The COVID-19 epidemic has brought a wave of email phishing attacks that try to trick work-at-home employees into giving away credentials needed to remotely access ...

KnowBe4 Launches New Research Arm With Its First Report on Security Culture

At KnowBe4, we’ve had some exciting news on the horizon for some time now that we’re thrilled to share with you – we’ve created a new research arm called KnowBe4 Research. When we ...

Social Media Doppelgangers Strike Again

Most people would be surprised by how easy it is to scam people online using duplicate versions of public accounts, according to Jake Moore, a security specialist at ESET. Moore describes ...

U.K. National Health Service Targeted with Over 40,000 Email Scams Aimed at Stealing Patient Data

The last few months have been very busy for cyber attackers targeting the NHS, as the number of phishing emails reported within the NHS shows a continual barrage of attacks.

Phishing Site Takes Brand Impersonation to a Whole New Level Pretending to be FINRA

Most scammers simply grab a company logo, or perhaps a logon page to make it appear like the website used as part of a scam is legitimate. But how about an entire website?

[HEADS UP] Carnival Corp. is the Next Victim of a Ransomware Attack

Carnival Corporation said it detected a ransomware attack that accessed and encrypted a portion of one brand’s information technology systems over this past weekend, according to Cruise ...

Credential Stuffing Attacks Shut Down Canada's Revenues Service

The Canada Revenue Agency is investigating two online hacking incidents affecting the personal information of thousands of Canadians, according to CBC News.

U.K. Firms Have Dismissed Employees for Breaching Cybersecurity Policy Since COVID-19 Pandemic

Almost two-fifths of business decision-makers have fired employees because of a cybersecurity policy breach since the pandemic began, a survey has found.

ABC News Interviewed Me on South Carolina Man Finding Personal Information of WWE Star and Raiding Her Home

A man in South Carolina was just arrested after finding the personal information of WWE Star Sonya Deville, and ABC Action News Tampa Bay interviewed me about how we can prevent ...

The Celebrities Don't Know You, and You Don't Know Them

Over the past four months, the UK’s National Cyber Security Centre (NCSC) has shut down more than 300,000 URLs linking to investment schemes that fraudulently claim to be endorsed by ...

RedCurl APT Uses Spear Phishing to Conduct Corporate Espionage

A previously unobserved APT group called “RedCurl” has been launching cyber espionage campaigns against organizations around the world since at least 2018, according to researchers at ...

Trying for a win, win, win game. Listen to this 5-minute interview with me.

Cyberwire has a short-form podcast called Career Notes and interviewed me recently. They said: "Founder and CEO Stu Sjouwerman takes us on a journey of how his career developed from ...

Phishing with Canva: Bad Guys Exploit Graphic Design Platform

Late last year we reported that Microsoft Sway, an online presentation program, was being exploited by malicious actors to host malicious files used in phishing attacks. Since then, ...

YIKES: Fancy Bear Linux Rootkit

Heads-Up! The CyberWire staff wrote: "The US National Security Agency and Federal Bureau of Investigation yesterday issued a joint alert concerning a new malware toolset operated by ...

43,000+ NHS Staff Hit With Phishing Emails Since March

A Freedom of Information (FOI) request revealed that over 43,000 National Health Service (NHS) staff have had phishing emails slip through the cracks and into their inboxes in the past ...

COVID-Themed Phishing Scams Are on Their Way Out While Some Scammers Use a Vaccine as a Last-Ditch Effort

The latest data on COVID-related phishing scams from security researchers at CheckPoint comes with some good news and insightful trends that may help keep you secure.

Having a Wonderful Time, Wish Your Data Were Here

The US Department of Health and Human Services (HHS) Office for Civil Rights (OCR) issued an alert warning that someone is impersonating the OCR and sending fraudulent postcards to ...

[On-Demand] The Best Ways to Stop Malware and Ransomware That No One Else Will Tell You

With malware attacks on the rise, making sure you keep your organization safe from a costly breach is a top priority. The two best things you can do to stop malware and ransomware attacks ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.