Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

A Phishing Attack in the Clouds May Rain On Your Parade

According to MeriTalk, an editorial and events organization that focuses on Federal IT and government computing technologies, governments are moving some, or all of their IT to the Cloud, ...
Continue Reading

MacEwan University Victim Of $11.8M CEO Fraud

CBC News reported that an Edmonton, Canada university was the victim of a $11.8 million CEO fraud attack after staff failed to call one of its vendors to verify whether emails requesting ...
Continue Reading

Vote For KnowBe4 At The 2017 Computing Security Awards!

KnowBe4 made it as Finalist in the 2017 Computing Security Awards, and we'd be eternally grateful if you could vote for us in the category "Education and Training Provider of the Year". ...
Continue Reading

Companies Slow to Adopt Insurance As Hedge Against Ransomware Wave

Research firm Ovum for Silicon Valley analytics firm FICO, conducted a May 2017, survey about cyber insurance. And here is the head-scratcher: “The survey further concluded that “a full ...
Continue Reading

Introducing Behavioral Information Security

Ben Tomhave posted a great article on his "The Falcon's View" blog. Loved the concept and I'm cross-posting the whole thing in it's entirety without any edits with grateful ...
Continue Reading

Nigerian Phishers Have Gone to School and Gotten Their CEO Fraud Diploma

The FBI calls CEO Fraud "Business Email Compromise" (BEC) and it has become a highly lucrative threat vector for attackers. According to IC3, the FBI's Internet Crime Complaint Center, ...
Continue Reading

[ALERT] The IRS Issued An Urgent Warning Against An IRS / FBI-Themed Ransomware Phishing Attack

WASHINGTON, August 28, 2017 — The Internal Revenue Service warned people to avoid a new phishing scheme that impersonates the IRS and the FBI as part of a ransomware scam to take computer ...
Continue Reading

CyberheistNews Vol 7 #34

Continue Reading

Scam Of The Week: Hurricane Harvey Charity Fraud

Hurricane Harvey hit hard and especially Houston, TX got badly flooded. The death toll is rising and you can also count on low-life cyber-scum exploiting this disaster.
Continue Reading

New Defray Ransomware Demands $5,000 In Customized Spear Phishing Attacks

This newly discovered ransomware strain is targeting healthcare, education, manufacturing and tech sectors in the US and UK, using customized spear phishing emails. Defray is demanding a ...
Continue Reading

The RopeMaker Exploit Can CHANGE An Already Delivered Email

Our friends at Mimecast are warning against something scary! This is a sobering example of why scanners and filters will always be behind in the security arms race... They wrote: "Most ...
Continue Reading

Health Care Systems Remain Targets of Ransomware And Phishing Attacks in 2017

Health care networks and providers are squarely in the cross hairs of ransomware cyber criminals and if the current rate of attacks continue it will likely exceed last years' events ...
Continue Reading

Microsoft Wakes Up To The Fact That Cyber Security Risk Is A Business Risk [VIDEO]

The 800-pound Redmond Gorilla asks: "Should your security focus be on systems or people?" They wrote: "In the latest Modern Workplace episode, “Cyber Intelligence—The Human Element,” we ...
Continue Reading

Enigma Hacked Before ICO Date -- CEO Had Not Changed A Compromised Password

Wherever there’s a lot of money to be made cyber thieves are not far behind. Think sharks surrounding a bait ball. Enigma is a financial data marketplace founded by a team from MIT which ...
Continue Reading

Inside The New York Hospital That Was Down For 6 Weeks Due To Ransomware

If you ever needed ammo to convince budget holders that you need more IT security resources, this is the link to send them. It is a great discussion-starter how an attack like this would ...
Continue Reading

[On-Demand Webinar] How To Phish Like the Bad Guys

Despite all the spectacular news stories about advanced persistent threats and targeted hacks from nation-states, the most common security challenge facing enterprises today continues to ...
Continue Reading

SyncCrypt Uses Graphic File to Cloak Ransomware in ZIP Phishing Payload

Emisoft Security researcher xXToffeeXx discovered another new phishing threat adept at bypassing Antivirus using a variation of the game played by PowerPoint PPSX attachment phishing ...
Continue Reading

Criminals Use Social Engineering To Make Victims Install Malicious Chrome Extensions

The attackers did reconnaissance on their targets, using social networks which people inside the organization were involved in making financial transactions. These victims were then ...
Continue Reading

Here Is A Cool And Useful INFOGRAPHIC About Social Engineering

Kevin Mitnick, KnowBe4's Chief Hacking Officer retweeted a link to well-executed infographic about Social Engineering, and here it is, courtesy of the team at Smartfile.com
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews