Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Organizations Need to Prepare for the Aftermath of Phishing Attacks

Phishing campaigns are growing more sophisticated as industries become increasingly aware of the threat they pose. Some of these attacks are so clever and meticulously crafted that many ...
Continue Reading

Add Wi-Fi Proximity to Your Cyberattack Concern List

The latest attack from the Russian GRU involves both traditional spear phishing and close access attacks in an attempt to thwart an investigation of the nerve agent attack in the UK.
Continue Reading

Users Sharing Passwords Put Organizations at Higher Risk

Cybercriminals thrive on misuse of credentials, and users sharing them only makes the criminal’s job easier. The latest report from LastPass shows password sharing is rampant.
Continue Reading

Don’t Be Scammed Twice: Check Your Cyber Insurance!

You’re already worried about the possibility of becoming a victim of a cyber scam. Be sure you clearly understand what your cyber insurance coverage is, or you may feel like you got taken ...
Continue Reading

Cyber Attacks Mean Double the Trouble in 2018

According to the 2018 Traveler’s Risk Index, the percentage of businesses that have been the victim of a cyberattack has doubled… and most businesses aren’t even remotely ready.
Continue Reading

Vishing Scams are Increasingly Difficult to Detect

Phone scams are becoming more convincing as attackers devise new ways to sound legitimate. KrebsOnSecurity recently spoke with several readers who'd been targeted by voice phishing, or ...
Continue Reading

KnowBe4 Introduces New Features: Virtual Risk Officer and Advanced Reporting

We are excited to announce the availability of two new features, Virtual Risk Officer and Advanced Reporting.
Continue Reading

British Government: "The Russian GRU Is Responsible For BadRabbit Ransomware And Many Other Cyber Crimes"

October 4th, 2018. Announced by the UK National Cyber Security Centre (NCSC), the UK and its allies exposed a ransomware campaign by the GRU, the Russian military intelligence service, of ...
Continue Reading

KnowBe4's Phish Alert Button Now Works With Outlook Mobile!

Do your users know what to do when they receive a suspicious email? Should they call the help desk, or forward it? Should they forward to IT including all headers? Delete and not report ...
Continue Reading

KnowBe4's Chief Hacking Officer Kevin Mitnick demonstrates the USB Ninja cable attack

Over the last few months, Kevin has been talking about this possibility: embedding malicious code in cables. This is a brand new demo where he shows this is now technically feasible! See ...
Continue Reading

KnowBe4 Fresh Content and New Features Update September 2018

Check out the new features and training content in the KnowBe4 platform for September! So how much security awareness training content do you have access to with a Diamond subscription? ...
Continue Reading

KnowBe4’s Year-Over-Year Sales Nearly Double for Q3 2018

I'm excited to announce our incredible year-over-year sales increase, nearly doubling 2017's third quarter sales in this third quarter of 2018, breaking records with new corporate ...
Continue Reading

Retail is Unprepared for Social Engineering

The latest data from SecurityScorecard shows the retail industry’s security stance is at an all-time low, and is particularly susceptible to social engineering attacks. The retail ...
Continue Reading

Bleeding Edge Phishing Attack Uses Decoy PDF with Microsoft-issued SSL Cert

TL,DR: A recent phishing attack posing as a PDF decoy from a Denver law firm was stealing clients' Office 365 credentials. The phishing bait was hosted in Azure blob storage and contained ...
Continue Reading

Hackers: Social Engineering is Easier

Despite the presence of application and OS vulnerabilities – both new and old – hackers prefer to leverage social engineering as their preferred attack method.
Continue Reading

Worry About Phishing, Not Malware!

With so many security strategies revolving around the detection of malware, organizations forget the primary source of all their worries – phishing.
Continue Reading

[Heads-up] Now In The Wild: New Super Evil Rootkit Survives Even "Nuke From Orbit" And HD Swap

This thing is a nightmare that escaped into daylight. The Russian GRU—aka Fancy Bear—probably was riveted reading the Wikileaks CIA Vault 7 UEFI Rootkit docs (PDF) and built one of these ...
Continue Reading

Kevin Mitnick weighs in on Facebook's big security breach

It was all over the news, and CNBC interviewed KnowBe4's very own Chief Hacking Officer Kevin Mitnick (note the StreetCred box on the right).
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews