Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

InfoSec Analyst: "We Make People Suck At IT Security"

IT Security analyst Ben Tomhave calls himself an infosec obsessive and I admire his insightful analyses when they appear. This time he commented on the recent attacks that followed the ...
Continue Reading

Prince Death Overdose Caught On Video! Stolen out of a spear phishing attack?

Our CTO was picking up some groceries and saw this at the check-out, stolen straight out of a spear phishing email... or was it? LOL.
Continue Reading

The Hidden Dangers of .HTML Attachments

By Eric Howes, KnowBe4's Principal Lab Researcher Over the past six to nine months .DOC and .JS file attachments have dominated the news surrounding the rise in phishing attacks. The ...
Continue Reading

Troy, Mich Investment Firm Loses $500,000 in CEO Fraud

An employee at a Troy, Mich., investment firm fell for a CEO Fraud attack and was social engineered into transferring almost $500,000 to a Hong Kong bank. The error was noticed eight days ...
Continue Reading

New KnowBe4 Feature: Vulnerable Browser Plugin Detection

How Can I See If My Users Have Vulnerable Browser Plugins Installed? Within your console, you can automatically detect what vulnerable plugins any clickers on your phishing tests have ...
Continue Reading

Verizon 2016 Data Breach Report: "Phishing Tops The List Of Increasing Concerns"

Verizon yearly does a comprehensive report on security and data breaches. It is excellent ammo to get budget approval for new-school security awareness training. Why? Hundreds of security ...
Continue Reading

[ALERT] 2016 Is A Ransomware Horror Show. Here's The Roundup Of 32 New Strains!

If you've been in the IT trenches over the past year, you've probably noticed the announcements of new strains of ransomware are accelerating. The research team at Proofpoint just ...
Continue Reading

The Phishing Attack That Came Out Of Zendesk

Yesterday, April 25 2016, we encountered a new phishing email being delivered through Zendesk. The credentials phish itself is a straightforward social engineering attack. The email body ...
Continue Reading

Scary New CryptXXX Ransomware Also Steals Your Bitcoins

Now here's a new hybrid nasty that does a multitude of nefarious things. Proofpoint researchers found that it was built by the same cyber mafia that's behind the Reveton malware. A few ...
Continue Reading

Scam Of The Week: Secure Document Phishing Attacks Trap Employees

In this Scam Of The Week we are warning against a new wave of phishing scams. In the industry this is called the "secure doc" theme. It's getting very popular with the bad guys. We see a ...
Continue Reading

Scam Of The Week: Prince Last Words On Video

Today, news broke that Prince Rogers Nelson was found dead in his home in Minneapolis at age 57. He was found unresponsive in an elevator and was declared dead shortly after. He performed ...
Continue Reading

[ FTC ALERT ] Don't Get Scammed By Earthquake Phishing Emails

It's the old story. A disaster strikes and 24 hours later you get emails with urgent request for help as hundreds of wounded victims need food, water and shelter. And the bad guys are at ...
Continue Reading

CyberheistNews Vol 6 #16 FBI: "Ransomware On Pace To Be A 1 Billion Dollar Business In 2016"

CyberheistNews Vol 6 #16 FBI: "Ransomware On Pace To Be A 1 Billion Dollar Business In 2016" CNN Money reports about new estimates from the FBI show that the costs from ransomware have ...
Continue Reading

A Short History & Evolution of Ransomware

Ransomware attacks cause downtime, data loss, possible intellectual property theft, and in certain industries a ransomware attack is now looked at as a possible data breach. Ransomware is ...
Continue Reading

CTB-Locker Ransomware Uses Blockchain to Store & Deliver Decryption Keys

A mysterious update in the behavior of the CTB-Locker ransomware strain alerted security researchers to pull some strings and see what was going on. The CTB-Locker ransomware family, ...
Continue Reading

Ransomware On Pace To Be A 2016 $1 Billion Dollar Business

CNN Money reports about new estimates from the FBI that show the costs of ransomware have reached an all-time high this year. Threat actors made $209 million in the first quarter of 2016 ...
Continue Reading

Phishing Attacks Hit the C-Suite With High Value Scams [INFOGRAPHIC]

OK, here is great ammo to get more IT security budget. Why? This article and infographic make it real to the C-suite that they themselves have a big phishing target on their back. You all ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews