Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Sandboxed Defender: Game-Changing Antivirus

With Microsoft’s latest release of Windows Defender running in a virtual sandbox (the first of its kind), it may be time to focus your energies – and budget – on other parts of your ...
Continue Reading

Security Rule-Breaking from Ignorance, Convenience, Curiosity

Ignorance of security policies and security threats is one of the primary reasons why employees break cybersecurity rules, says Ericka Chickowski at Dark Reading. A study conducted by ...
Continue Reading

School Daze: Clever Phishing Emails Target Educational Organizations

By Eric Howes, KnowBe4 Principal Lab Researcher. It will surprise few people to learn that during our daily review of suspicious emails forwarded to us by users of the Phish Alert Button ...
Continue Reading

Replica Phishing Sites Prey on User Trust

Attacks leveraging look-alike federated logon pages are more dangerous than malware-laden attachments in email.
Continue Reading

That Saudi oil and gas plant that got hacked. You'll never guess who could... OK, it's Russia

FireEye thinks it found the evil genius behind a nasty cyber-infection at a Saudi Oil refinery.
Continue Reading

Everything is Negotiable… Including Ransomware Payments

Should you find yourself in the situation where paying the ransom is your only out, it’s important to know how to navigate – and minimize – the payment. Cyber attacks are the new reality ...
Continue Reading

KnowBe4 Top-Clicked Phishing Email Subjects for Q3 2018 [INFOGRAPHIC]

The latest results of KnowBe4's quarterly top-clicked phishing email subjects is now available. We report on three different categories: general emails, social media related subjects, and ...
Continue Reading

Everyone’s Cyber-Worried; No One’s Cyber-Prepared

New data from the 2018 Chubb Cyber Risk Survey shows people and companies have a false sense of cybersecurity and aren’t really doing much about it.
Continue Reading

Scam Of The Week: Sextortion With A RATty Twist

Sextortion is a form of blackmail where the extortionist claims to have photos or video of the victim watching adult entertainment on their computer. The criminal threatens to send the ...
Continue Reading

[Heads-up] U.S. Government: "Your Weak Cyber Security Violates Federal Law"

Reuters just made me aware of a U.S. Securities and Exchange Commission report about a recent SEC investigation of nine companies that had been victims of CEO fraud had sufficient ...
Continue Reading

[Heads-up] Here Is Some New Powerful Ammo To Get InfoSec Budget Approval!

The team at Forbes Magazine's Tech Council asked me to write up the lessons we have learned over the last 8 years of helping you keep the bad guys out of your network. It took me a while, ...
Continue Reading

212 Million Exposed Contacts Would Be a Scammer’s Dream

A recent discovery of exposed data on a web-facing server owned by data aggregator and analytics provider Apollo demonstrates how data breaches empower scammers.
Continue Reading

CEOs and Boards are Unprepared for Cyber Risk

Deloitte’s CEO and Board Risk Management Survey shows organizations are unprepared for the future of cyberattack at the highest levels.
Continue Reading

75% of Users Don’t Know Cyber Security Best Practices

New data from MediaPRO’s third annual State of Privacy and Security Awareness Report shows users are less prepared this year to address the risk of cyberthreat.
Continue Reading

It Only Takes One Phish: 37K Records and a Month of Access

The attack on California-based Gold Coast Health Plan went undetected, allowing attackers access to healthcare data serving as fuel for fraud.
Continue Reading

Three Out of Ten People Would Fall for Impersonation Scams

Phony police calls in the US have been telling people they need to pay a fine for missing jury duty. In the UK the scams take a different form: the bogus police are asking for the ...
Continue Reading

UK publishers warn of global phishing scams targeting manuscripts

A succession of global phishing scams targeting publishers and agents has prompted responses from several global publishers, reports the Bookseller.
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews