Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Gigabyte Firmware Flaws Allow the Installation of Ransomware

Now, here is an interesting one. Gigabyte BRIX are very small computers, similar to Intel NUCs, that can be used to replace those bulky desktop towers. I am using Intel NUCs myself at the ...
Continue Reading

Samas Ransomware Deletes Veeam Backups, And Maybe Yours Too...

This month, a user on the Atlanta-based 500 million-dollar backup company Veeam community forums reported that they were hit with Samas ransomware. I am giving you the short version here: ...
Continue Reading

Scam Of The Week: The Evil Airline Phishing Attack

Our friends at Barracuda run their Email Threat Scanner over hundreds of thousands of customer mailboxes and discovered a highly effective phishing attack that tricks a whopping 90% of ...
Continue Reading

SecureWorks Exposes Phishing Russian Hacker Gang APT28

Atlanta-based SecureWorks has a Counter Threat Unit which has been closely watching the Russian hacker gang APT28 over the last few years and released brand new research. This group of ...
Continue Reading

KnowBe4 Appoints Former Gartner Research Analyst Perry Carpenter as Chief Evangelist and Strategy Officer

Perry Carpenter, former Research Director, Security & Risk Management and esteemed analyst at Gartner, has joined KnowBe4 as Chief Evangelist and Strategy Officer. As the provider of ...
Continue Reading

Chinese Hackers Use Fake Cellphone Tower to Spread Android Banking Trojan

Check Point Software blogged about Chinese hackers who have taken smishing to the next level, using a rogue cell phone tower to distribute Android banking malware via spoofed SMS messages.
Continue Reading

Does DoubleAgent Turn Antivirus Into Malware? We Are Calling BS On That.

It was all over the press. Initially reported by Bleepingcomputer and picked up by sites like Endgadget, they all went gaga over a new technique that allows the bad guys to take over your ...
Continue Reading

Ransomware Is Skyrocketing, But Where Are All The Breach Reports?

More than 4,000 ransomware attacks occur daily and healthcare is the largest target. However, despite disclosure requirements and the risk of late or no HIPAA notification at all, breach ...
Continue Reading

Who Were The Two Big US Tech Companies That Lost $100 Million In CEO Fraud?

4/28/2017 UPDATE: Facebook and Google confirmed as victims of $100M phishing scam. Story at The Verge. In an update on an earlier post of April 2016, more detail came known about this ...
Continue Reading

CyberheistNews Vol 7 #12 A Single Spear Phishing Click Caused the Yahoo Data Breach

CyberheistNews | KnowBe4
Continue Reading

Mandiant M-Trends 2017: "Cybercrime Skills Now On Par With Nation States"

There was some good news reported in Mandiant's M-Trends 2017 report, but this was heavily outweighed by a lot of very bad news. Mandiant, which is a Fireye company, found that in 2016 ...
Continue Reading

A Single Spear Phishing Click Caused The Yahoo Data Breach

A single click was all it took to launch one of the biggest data breaches ever. One mistaken click. That's all it took for a Canadian hacker aligned with rogue Russian FSB spies to gain ...
Continue Reading

Scam Of The Week: New FBI and IRS Alerts Against W-2 Phishing

There is a wave of W-2 phishing attacks going on. We see these coming in through thousands of reported scam attempts via our Phishing Alert Button. The FBI and the IRS have repeatedly ...
Continue Reading

Petya MFT Ransomware Returns, Wrapped In Extra Nastiness

Kasperky researchers discovered a new variant of last year's Petya Master File Table (MFT) ransomware, with "new and improved" crypto and ransomware models. Remember, MFT ransomware only ...
Continue Reading

Verizon Wanted A 925 Million Discount Because Of Yahoo Hacking. CEO Mayer gets 23 Million Parachute

A newly filed Schedule A proxy statement at the Securities and Exchange Commission shows that Verizon requested a discount of 925 million dollar off the original 4.83 billion purchase ...
Continue Reading

SEC Phishing Emails Target Execs For Inside Info

A sophisticated phishing attack is trying to get confidential corporate information. Bad guys are sending spoofed emails claiming to be from the Security and Exchange Commission, and ...
Continue Reading

Heads-Up. New Ransomware phishing scheme lets wannabe cybercrims get in for free...

Danny Palmer at ZDNet reported on a new scheme for aspiring cyber criminals that lets them into the ransomware racket for free, but at a steep 50/50 split with the people that provide ...
Continue Reading

Scary new malware hides in memory, uses DNS to communicate, and spreads through phishing

Cisco has a separate threat research group called Talos. They just published a report on a scary new form of malware that’s hard to detect. They called it DNSMessenger, and the malicous ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews