Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

We Are In The Wrong Business. Cyber Extortionists Make $360K A Year.

Extortion scams capitalize on compromised credentials, sensitive data, and technical vulnerabilities on Internet-facing applications to pressure victims to pay up.
Continue Reading

Various Types Of Phishing Attacks Defined

The definition of phishing is a cybercrime in which potential victims are contacted via email, telephone or text message by someone posing as a legitimate institution to lure individuals ...
Continue Reading

Hackers take over Tampa Mayor Bob Buckhorn's Twitter account, make bomb threat at Tampa Airport

TAMPA, Fla. (WFLA) - Tampa police are investigating a bomb threat made against Tampa International Airport after hackers took over Tampa Mayor Bob Buckhorn’s Twitter account Thursday ...
Continue Reading

Helping Employees Not Cause Data Breaches

Untrained employees with poor security habits pose a major risk to their employers, according to Ciara O’Brien at the Irish Times. O’Brien cites recent research conducted by Amarach on ...
Continue Reading

Wendy’s to pay $50M in data breach settlement

Wendy’s has agreed to pay $50 million to settle negligence claims following its 2015-2016 data breach that affected more than 1,000 of the burger chain’s locations.
Continue Reading

KnowBe4 Releases The 2019 What Keeps You up at Night Report

Today we released the results of new research: What Keeps You up at Night – the 2019 Report. The report looks at over 350 organizations across North America and reveals the security ...
Continue Reading

New: "Targeted Training" Filter in KnowBe4 ModStore

Get your users the right training content, specific to their roles and departments. With the new “Targeted Training” filter in the KnowBe4 ModStore, you can easily find and assign ...
Continue Reading

Remote Access Credentials Are the Latest Malware Attack Target

The latest iteration of notable banking trojan, Trickbot, now includes a password grabbing module designed to provide cybercriminals with remote access to internal systems.
Continue Reading

It’s Time to Have a Security Plan Around Consumer Data Privacy

The growth in both consumer concern and laws seeking to protect consumer data means organizations need to take specific measures to ensure the safeguarding of customer data.
Continue Reading

Popular Torrents Uploader Caught Sharing ‘GandCrab’ Ransomware Strain

Torrent sites are banning CracksNow, a popular source of torrent uploads, after discovering that the uploader of cracks and keygens was distributing ransomware.
Continue Reading

8-Character Windows NTLM Passwords Can Be Cracked In Under 2.5 Hours

BeauHD posted in Slashdot: "HashCat, an open-source password recovery tool, can now crack an eight-character Windows NTLM password hash in less than 2.5 hours. "Current password cracking ...
Continue Reading

Iran indictments show even U.S. intelligence officials are vulnerable to basic phishing schemes

As the story broke about the charges against former U.S. Air Force intelligence specialist who defected to Iran and support targeted hacking against some of her former colleagues, one ...
Continue Reading

U.S. Cities Remain at Risk of Cyber Attacks

Recent attacks on city governments have not only provided their attackers with revenue from scams, data breaches, and data held ransom, but have also drawn the attention of other ...
Continue Reading

Business Email Compromise, Credential Theft, and Many Other Attack Vectors Surged as High as 5x in Q4 2018

The latest data from Proofpoint shows many types of cyberattacks making massive jumps in comparison to both previous quarters and years.
Continue Reading

Cyberheist On Bank Causes Shutdown Of All Operations

Reuters reported that the Bank of Valetta, which accounts for almost half of Malta’s banking transactions, had to shut down all of its operations on Wednesday after hackers broke into its ...
Continue Reading

New York State Education Department Proposes New Regulations to Strengthen PII Security

The new proposed amendments seek to protect the personally identifiable information for students and school personnel accessible by both educational agencies and contractors.
Continue Reading

Bogus Security Alerts Aren’t From Norton

Con artists are targeting thousands of people with tech support scams that pose as security alerts from Norton Security, researchers at Symantec have found. The phony alerts pop up in the ...
Continue Reading

Surge in Email-enabled Healthcare Fraud

Email fraud targeting healthcare professionals has spiked 453% over the past two years, according to a new report by Proofpoint. Proofpoint researchers tracked business email compromise ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews