Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Is that phone call really from Amazon?

By Eric Howes, KnowBe4 Principal Lab Researcher. Now that it's the holiday season, malicious parties across the globe are exploiting Amazon's good name and popularity with consumers to ...
Continue Reading

APWG: Phishing Remains a Constant and Effective Means of Attack

The latest report from the Anti-Phishing Working Group (APWG) highlights the prevalence of phishing and how it’s changing to remain an effective attack method.
Continue Reading

How Wellcome Trust Executives Got Whaled By Oldest Trick In The Phishing Playbook

Forbes contributor Davey Winder wrote an excellent comment: "It hasn't been the greatest week for the non-profit sector with the revelation that two well-known charities have fallen ...
Continue Reading

New Deloitte Threat Study Shows The Fantastic ROI of Cyber Crime Operations

Deloitte estimates that some common criminal businesses can be operated for as little as $34 month and could return $25,000, while others may routinely require nearly $3,800 a month and ...
Continue Reading

UK Companies Cite a Lack of Cybersecurity Support from the Government

With cyberattacks occurring at such a regular frequency, UK organizations are desiring for the government to provide guidance and support on how to prepare for and address attacks.
Continue Reading

Organizations Managing Critical Infrastructure Face a New Global Phishing Attack

According to McAfee’s Advanced Threat Research team and McAfee Labs Malware Operations Group, a new global campaign is underway, targeting key industries, potentially for espionage ...
Continue Reading

Scumbag hackers lift $1m from children's charity

The Register reported on some scumbag criminals that stole a million bucks from a charity. The editors got very upset with these criminals and freely spoke their mind. The resulting copy ...
Continue Reading

Malicious Memes Trigger Malware Functions

Cybercriminals are using steganography to deliver commands to malware via malicious memes, according to researchers at Trend Micro. Steganography is the art of hiding messages inside ...
Continue Reading

Mimecast: "Your Filters Are Missing 12 Percent Of The Unwanted Emails"

Mimecast said: "Is a false negative rate of 12% a large number or a small one? I suppose it depends on your perspective. If your email security system lets in 12 unwanted emails—whether ...
Continue Reading

CrowdStrike: Compelling Stories From The Cyber Intrusion Casebook 2018

From the Front Lines of Incident Response, the CrowdStrike Services Cyber Intrusion Casebook 2018 offers some compelling stories how threat actors are continuously adopting new means to ...
Continue Reading

These Incredibly Realistic Fake Faces Show How AI Can Now Mess With Us

This starts to be more than a bit concerning. The faces in this post look like pretty normal humans. They could be social media shots. However, they were generated by a recent type of ...
Continue Reading

New "Secured" Phishing Site Goes Up Every Two Minutes

SC Mag had an exclusive: Threat actors are "playing by the rules", or at least tricking your browser into thinking they are, in order to deliver more effective attacks.
Continue Reading

Kanye West Tops Dashlane’s List of 2018’s “Worst Password Offenders”

Dashlane today announced its third annual list of the “Worst Password Offenders.” The list highlights the high-profile individuals and organizations that had the most significant ...
Continue Reading

[Heads-up] New Email Extortion Scam Bomb Threat Demands Bitcoin

A new email extortion scam is making the rounds, threatening that someone has planted bombs within the recipient's building that will be detonated unless a hefty bitcoin ransom is paid by ...
Continue Reading

Ransomware Recovery Expert Scams Victims and Turns Out to be Nothing More than a Bitcoin Middleman

Organizations falling victim to ransomware look for any way to ensure they get their files back. One Belasurian businessman promises decryption but is merely conning victims out of more ...
Continue Reading

WARNING: Your Head of Finance May Be 1 of 50,000 Execs Targeted in BEC Scams

According to a report from email security & protection vendor Agari, the cybercriminal group dubbed London Blue are directing their latest scams at very specific finance execs.
Continue Reading

NotPetya Causes Whopping 100 Million Insurance Coverage Lawsuit

Techlawx posted news about an astounding NotPetya-related lawsuit, (link at the end). We all remember June 27, 2017, when a major global cyber attack harmed thousands of companies. The ...
Continue Reading

Giveaway Scam Offers Free Volkswagens to Generate Ad Revenue

A scam campaign is promising free Volkswagen car giveaways to trick social media users into visiting third-party ad servers, according to researchers at Sucuri.
Continue Reading

A Call for More Consumer Privacy Laws Could Spell Penalties in Your Future

In the wake of the Marriott data breach, U.S. senators are calling for tougher privacy laws and stiff fines for organizations that do not properly protect consumer data.
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews