Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

New Trend In Phishing: Conversation Hijacking

Researchers see a new trend in phishing. Hackers are inserting themselves into email conversations between parties known to and trusted by one another. Once in, they exploit that trust to ...
Continue Reading

2018 Winter Olympics Phishing Campaign Hides Evil PowerShell Script In Image

Jonathan, at our friends at Barkly wrote: "Hi all, according to researchers at McAfee, a new malware campaign is targeting organizations associated with the upcoming 2018 Winter Olympics ...
Continue Reading

Tennessee Hospital Hit With Cryptojacking Attack Sends Out Databreach Notification

Decatur County General Hospital is notifying 24,000 patients of cryptomining software on its EMR system. In what may be the first report I’ve seen of a hospital having their EMR server ...
Continue Reading

KnowBe4 Introduces New Feature: Industry Benchmarking

You have probably seen our recent benchmarking study, drawn from a data set of more than six million users across over 23,000 organizations, showing real-world phishing results over time. ...
Continue Reading

The Simulated Phishing Market Enters Early Adolescence

By Perry Carpenter, KnowBe4 Chief Evangelist and Strategy Officer We certainly live in fun times: Barracuda acquiring PhishLine Microsoft adding limited phishing simulation to Office 365 ...
Continue Reading

KnowBe4 Fresh Content Update & New Features Summary Jan 2018

A lot of new modules have been added to the KnowBe4 ModStore: We refreshed 26 Language versions for our 15 min KMSAT course. (Available now). 20 language versions for Ransomware will be ...
Continue Reading

Microsoft Confirms: "Sending Simulated Phishing Attacks to Your Employees Is a Must"

Well, Microsoft just legitimized the whole new-school security awareness training market. I'm pleased to note that Microsoft has finally acknowledged that organizations need to send ...
Continue Reading

Cisco: "Cybercrime Swaps Ransomware For Cryptomining, Generating Millions"

Cisco's Talos Threat Intelligence team has a good observation. Cybercriminals can just steal CPU/GPU cycles and directly generate any cryptocurrency without infecting the system with ...
Continue Reading

Who's Behind This Massive Wave of DDoS and Phishing Attacks Targeting Dutch Banks?

Shortly after the Dutch Volkskrant newspaper story about Netherlands Intelligence agencies compromising the prominent Russsian Cozy Bear hacking group and providing the US with ...
Continue Reading

Phishing Messages from the Dark: When the Bad Guys Write Back

By Eric Howes, KnowBe4 Principal Lab Researcher. For most users the experience of dealing with phishing emails is a solitary experience, whether they recognize that they are under attack ...
Continue Reading

Which is the most dangerous global hacking cyber group? – AlienVault research

AlienVault researchers have listed Sofacy, also known as Fancy Bear or APT28, as the most capable hacking group in the world. This was based on ranking the top threat actors which have ...
Continue Reading

Scam of The Week: Wave Of Payroll Direct Deposit Phishing Attacks

Lexology had an excellent post from Ogletree Deakins by Rebecca J. Bennett and Danielle Vanderzanden, related to a crafty new phishing scam they warned for and that you should be aware ...
Continue Reading

What are “WannaMine” attacks, and how do I avoid them?

It's suddenly all over the news. In hindsight, it was a matter of "not if, but when". Sophos just warned against a new hybrid worm that combines the ETERNALBLUE exploit and cryptomining. ...
Continue Reading

KnowBe4 Welcomes Employee No. 400

Something positive for a change. This morning we welcomed employee No. 400 at the staff meeting, and for good measure we also asked employee No. 100, 200, and 300 to come on stage too!
Continue Reading

UK Warns Critical Industries to Boost Cyber Security or Face Hefty Fines

The UK government has warned that Britain's most critical industries must boost their cybersecurity or face potentially hefty fines under the EU's Networks and Information Systems ...
Continue Reading

IT Security in the enterprise: Things are looking up!

Cybersecurity is quickly becoming the number one business priority, says identity and access management company Okta. Based on the results of an analysis of authentication and ...
Continue Reading

[PHISHING ALERT] "Hey Did You See That Fake AI Porn Movie Of Yourself?"

Heads-up. I am sorry to have to bring up a very distasteful topic, but in the very near future your users will get phishing emails with something close to the ultimate click-bait, luring ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews