Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

New articles and updates from the KnowBe4 Technical Content Team

Here are all of the major items and updates our Technical Content Engineers have added to our knowledge base and KMSAT product in the last couple of months.
Continue Reading

Specially Crafted ZIP Files Used to Bypass Secure Email Gateways

Attackers are always looking for new tricks to distribute malware without them being detected by antivirus scanners and secure email gateways. This was illustrated in a new phishing ...
Continue Reading

The Direct Deposit Phish: Revisiting the Scene of the Crime

By Eric Howes, KnowBe4 Principal Lab Researcher. Well over a year ago we reported on the rise of a new form of CEO fraud in which malicious actors persuaded unwitting employees working in ...
Continue Reading

Here Is A New Term For Your Cybercrime Glossary: Vendor Email Compromise (VEC)

Agari’s latest Email Fraud & Identity Deception Trends report highlights the growing threat of vendor email compromise (VEC), according to SecurityWeek. This is a variety of business ...
Continue Reading

The Most Fascinating Layer in a SOC: The Human Layer

During my travels, the topic of security operations comes up often. And nearly every security professional I talk to is either contemplating or already implementing some form of ...
Continue Reading

Exactly Why Is Replying to Phishing Attacks A Really Bad Idea?

PhishLabs warns that replying to a phishing email, even if you know it’s a scam, can lead to further attacks. Most phishing campaigns are automated and replying to them puts you on a ...
Continue Reading

The Cold War Was Like Being Hit With A Club. Cyber War is Being Stung With A Syringe

America's Cold War with Russia was fought with the threat of mutually assured destruction using atomic weapons. Being hit with a nuke is very much like being whacked over the head with a ...
Continue Reading

APWG Q3 Report: Phishing Attacks at Highest Level in Three Years

According to the APWG’s new Phishing Activity Trends Report, the number of phishing attacks continued to rise into the autumn of 2019. The total number of phishing sites detected by APWG ...
Continue Reading

Security in Three Keynotes

I had the pleasure of attending (ISC)2 Congress this year in Orlando with my colleague and fellow advocate James McQuiggan.
Continue Reading

You Need To Start Thinking Differently About This Whole "Insider Threat" Concept

In order to defend against insider threats, you need an accurate picture of the problem. The CyberWire’s Carole Theriault spoke to a number of industry experts about insider threats and ...
Continue Reading

Ransomware Attack Blocks Hundreds Of Law Firms From Their Trial Records

I could not come up with a better scenario to get sued by a pack of angry lawyers. Reams of digital legal documents have been held hostage under a ransomware threat to TrialWorks, a ...
Continue Reading

Healthcare Industry Names KnowBe4 As The 2019 Top Rated Platform For Cybersecurity Training & Education

Black Book Market Research LLC surveyed over 2,876 security professionals from 733 provider organizations to identify gaps, vulnerabilities and deficiencies that persist in keeping ...
Continue Reading

American Nikkei Employee Falls For Social Engineering Scam And Loses 29 Million Dollars

Phil Muncaster at InfoSec Mag had the (painful) scoop: "Media giant Nikkei has become the latest firm to suffer a humiliating Business Email Compromise (BEC), after it admitted losing ...
Continue Reading

A Transformational Rant: Why People Question the Value of Security Awareness

In my last post, I spent a bit of time discussing the “technology vs. training” debate; and based on the feedback received, I can tell that this is a debate that many of you have had to ...
Continue Reading

Phishing Kits Hosted on More than Six Thousand Domains

Akamai’s 2019 State of the Internet / Security Report found that 6,035 domains were being used to host 120 different phishing kits, according to BleepingComputer. The phishing kits ...
Continue Reading

[Heads Up] Scam Of The Week: Phishing Attacks Using Better Benefits And Pay Raise Bait

Millions of employees use KnowBe4's Phish Alert Button to report suspect emails, and thousands of organizations share these reports with us. This has become a fascinating threat source, ...
Continue Reading

KnowBe4 Fresh Content & Features Updates - October 2019

Check out the content and feature updates in the KnowBe4 platform for the month of October!
Continue Reading

Webroot Threat Researchers Take a Fresh Look at Phishing Tactics

Most people aren’t aware of how sophisticated phishing email templates and websites have become, according to David Dufour from Webroot. Dufour recently told the CyberWire that criminals ...
Continue Reading

SAVE THE DATE!! KnowBe4 User Conference - April 15-17, 2020

KnowBe4’s third annual KB4-Con user conference will be held at the Gaylord Palms Resort & Convention Center in Orlando, FL. KnowBe4 customers get twofree event passes per ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews