Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

KnowBe4 Moves From #38 to #6 On Cybersecurity 500

The Cybersecurity 500 / Q2 2017 list of the world's hottest security companies was officially released June 21, 2017. In their press release they said: "Worldwide spending on ...
Continue Reading

Web Hosting Provider Pays $1 Million to Ransomware Attackers

South Korean web hosting company Nayana agreed to pay $1 million in Bitcoin after a ransomware attack hit 153 Linux servers. The attack took place June 10 and resulted in over 3,400 ...
Continue Reading

[BREAKING] Scam Of The Week: Your Politics Have Been Breached

Gizmodo reported on a blog post by IT Security company UpGuard which revealed the largest US voter data leak to date. Political data gathered on more than 198 million US citizens was ...
Continue Reading

KnowBe4 May 2017 New Training Modules Released

Here are the May releases, with an indication on the subscription levels which give access to these modules: For May we released the following: Common Threats (standalone module) - Level ...
Continue Reading

[ALERT] New Fileless, Code-injecting Ransomware Bypasses Antivirus

Security researchers have discovered a new fileless ransomware in the wild, which injects malicious code into a legitimate system process (svchost.exe) on a targeted system and then ...
Continue Reading

See Me On Video At The NYSE Cyber Investing Summit Pitching KnowBe4

The CyberWire wrote: Pitches: "Innovation from Young Companies The Pitch Panel was the Cyber Investing Summit's fast round of innovation pitches, moderated by Allegis's Bob Ackerman and ...
Continue Reading

FIN10: Anatomy of a Ransomware Phishing Extortion Operation

Cyber security firm FireEye reported that that a number of Canadian mines and casinos were hacked by a group named FIN10 – FireEye labels FIN10 to be “one of the most disruptive threat ...
Continue Reading

CIA Director Brennan: "Russia's Cyber Capability Increasingly Sophisticated And Not Bound By Law"

I was at the Gartner Security & Risk Management Summit at National Harbor, in DC this week. One of the keynotes was by CIA Director George Brennan, who was sworn in as director of the ...
Continue Reading

Did WannaCry Ransomware Escape North Korean Containment?

Mike Mimoso at Kaspersky's Threatpost blog raised the theory that the ransomware wasn’t contained properly and spread before it was meant to be unleashed. Malware expert Jake Williams, ...
Continue Reading

Southern Oregon University Lost $1.9 Million Due To CEO Fraud

Mail Tribune reported that Southern Oregon University is just the latest victim of CEO fraud (which the FBI calls Business Email Compromise or BEC) after hackers tricked university ...
Continue Reading

ICO less likely to issue fines for data breaches if they show staff training

The UK's Information Commissioner's Office has said that in the event of a data breach it would be less likely to issue a monetary penalty to charities which had taken “reasonable steps” ...
Continue Reading

CyberheistNews Vol 7 #24

Continue Reading

This Ransomware Targets HR Departments With Fake Job Applications

I missed this one a few months ago, but it's a great example how focused the bad guys are getting with their attacks, and you need to watch out for this social engineering attack vector ...
Continue Reading

Windows 10 Stops Ransomware Cold... Or Does It?

OK, finally there is some good news in the fight against ransomware!
Continue Reading

New PowerPoint Social Engineering Attack Installs Malware Without Requiring Macros

Researchers at Security firm SentinelOne reported that a group of hackers is using malicious PowerPoint files to distribute 'Zusy,' a banking Trojan, also known as 'Tinba' (Tiny Banker). ...
Continue Reading

Federal Contractor? Insider Threat Training Deadline June 1- Don't Lose Your Clearance

Insider Threat Training Requirement for US Gov't Contractors (Deadline May 31, 2017) SANS just alerted US federal contractors that wish to maintain their clearances must have completed an ...
Continue Reading

ITIC / CyberheistNews Top 10 IT Security Recommendations May 2017

By Laura DiDio There is no such thing as a 100% fully secure environment. And there never will be. Security is not static; it is an ongoing work in progress. Organizations must be ...
Continue Reading

Netflix, ABC Hacker Promises More Phishing: "Hollywood Is Under Attack"

The Hollywood Reporter (THR) talked directly to TheDarkOverlord hacking collective that claims to have studio films. They said: "We're in the business of earning vast amounts of internet ...
Continue Reading

Top Secret NSA Doc Shows Russians Spear-Phishing Election Officials

The Intercept reported that the GRU (Russian Military Intelligence, the FSB's counterpart) executed a cyberattack on at least one U.S. voting software supplier and sent spear-phishing ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews