Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Baffling FBI silence about Russian phishing attacks on US officials

WASHINGTON – The Associated Press revealed a baffling FBI silence about spear phishing attacks by Russian hackers on US officials like the former head of cybersecurity for the U.S. Air ...
Continue Reading

Something funny happened on the way to repealing Net Neutrality rules...

Sorry to interrupt your Thanksgiving, but this one has had me laughing all afternoon. You might have seen the news that the Trump-era FCC is planning to repeal the Net Neutrality rules ...
Continue Reading

Massive Phishing Attack On Businesses with Evil New Ransomware Strain

The Scarab ransomware strain is updated again and spreads via Necurs botnet in a massive 12.5 million campaign, mostly targeting .com domains. Scarab was spotted June 2017 for the first ...
Continue Reading

Spam was nearly dead, then it became an essential tool for crime and came roaring back

John Christian at TheOutline wrote a post that made me take notice because it neatly summarized the current state of affairs and confirms our own experience: spam has morphed and is back ...
Continue Reading

URGENT - If IT and Marketing are not freaking out about GDPR compliance, you are not paying attention

I found an article about GDPR compliance written by the fine folks of HubSpot, which we use ourselves here at KnowBe4 use for marketing automation. We have customers in Europe, so our ...
Continue Reading

Uber Total Loss: 57 Million Records Stolen But Data Breach Was Hidden For A Year

Oh boy. Uber is known for pushing the limits of the law and has dozens of lawsuits pending against it, but this one went too far and now comes the reckoning. Bloomberg was first to report ...
Continue Reading

[ALERT] Zombie Remote Access Phishing Trojan Kills Antivirus

Almost two years ago we took note of two different write-ups on the Adwind (aka AlienSpy) remote access trojan (RAT), one by McAfee and the other by Fidelis Security. Those pieces caught ...
Continue Reading

We're Still Not Ready for GDPR? What is Wrong With Us?

Sara Peters, Senior Editor at Darkreading wrote an excellent article about GDPR. It is both reprimanding and encouraging to get off our collective butts and do something about GDPR very ...
Continue Reading

‘Grey’s Anatomy’ Fall Finale Cliffhanger: Hospital Shut Down By Ransomware Attack

Ransomware goes prime time: TV Show Grey's Anatomy characters Bailey and Arizona are unable to access medical records on the computer and an I.T. specialist named Tim notes that cardiac ...
Continue Reading

The future of cyberwar: ​Weaponised ransomware, IoT attacks and a new arms race

Steve Ranger at TechRepublic did a good job summarizing the direction of future threats we are going to have to deal with. "After at least a dozen years in the shadows, cyberwarfare is ...
Continue Reading

Ransomware recovery methods: What does the NIST suggest?

Knowing what ransomware recovery methods are available is important as the threat continues to grow. Expert Judith Myerson at TechTarget outlines what the NIST recommends for enterprises. ...
Continue Reading

Antivirus Software Doing The Complete Opposite And Spreading Malware

Nicknamed AVGater by Austria-based security consultant Florian Bogner, he discovered an exploit within Antivirus software that takes advantage of the “restore from quarantine” function ...
Continue Reading

Skeleton in the closet: 17-year old MS office flaw allows malware install when user opens file

Here is a new pain in the neck! Fix this one ASAP. While the world is still dealing with the threat of 'unpatched' Microsoft Office's built-in DDE feature, researchers have uncovered a ...
Continue Reading

[On-Demand Webinar] Six Cybersecurity Trends Organizations Need to Watch for in 2018

Watch this insider’s perspective of cybersecurity trends to expect in 2018 from our founder Stu Sjouwerman. The list of six predictions are founded on KnowBe4’s deep insight into threats ...
Continue Reading

Watch Out For Black Newsjacking: FOSCAM camera poisoned search results

Security researchers frequently report on vulnerable IoT devices. Cisco's Talos group just reported that Foscam video cams have a security risk. We did a Google search on Foscam Indoor ...
Continue Reading

Scam of the Week: "Cyber Monday Is Scammer Heaven"

The majority of consumers aware of online phishing scams, but still may fall victim this cyber Monday... So here is your Scam Of The Week! DomainTools, a leader in domain name and ...
Continue Reading

[VIDEO] New Smart Groups Put Your Phishing, Training And Reporting On Autopilot.

Automate the path your employees take to smarter security decisions. With the powerful new Smart Groups feature, you can use each employees’ behavior and user attributes to tailor ...
Continue Reading

[ALERT] This Scary New Phishing Attack Is Very Hard To Detect

You need to know about a new phishing attack vector reported by our friends at Barkly. It utilizes a new technique that's just plain nasty. This week, users at one of their customers ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews