Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Is Security Making The Grade? What IT And Business Pros Really Think

Great joint survey by CSO, CIO and ComputerWorld by Amy Bennett which is excelllent ammo to add to a budget request that needs to be approved by a C-level exec. Here's why: "If you sense ...
Continue Reading

Uh oh, Yahoo May Have Been COMPLETELY Pwned

We predicted that this would happen on September 23rd when the news broke that Yahoo lost "at least" 500 Million credentials. Just for a change I'm quoting myself here: :-D "Right, that ...
Continue Reading

This weird ransomware strain spreads like a virus in the cloud

Here is a ransomware horror story for you... An obscure 2-year old ransomware strain called Virlock has a nasty feature: it is capable of stealthily spreading itself via cloud storage and ...
Continue Reading

InfoArmor: The Yahoo Hackers Were Not State-sponsored

Eastern European organized crime, not state-sponsored hackers, were behind the record breaking 2014 Yahoo data breach that exposed information about hundreds of millions of Yahoo user ...
Continue Reading

Brazen: Phishing Attacks The Bad Guys Send When No One's Looking

When we talk with folks outside the security industry about what we see from the bad guys on a daily basis, we often get the response, "Wow! That's really sneaky." And it's true. The bad ...
Continue Reading

Ransomware Is Now Officially Extortion Under California Law

Of course everyone knows that hacking into a computer is a federal crime, and infecting a system with ransomware already falls into that bucket. However, California’s SB-1137, signed into ...
Continue Reading

Gang Uses Social Engineering To Steal 147 Million Dollars

Police have arrested a 147 million international fraud and money laundering ring, and jailed nine fraudsters jailed for over 27 years The gang targeted thousands of Lloyds and RBS ...
Continue Reading

What is the Necurs Botnet And How Does It Spread Locky Ransomware?

In Short: The Necurs botnet is one of the world's largest botnets with more than 6 million zombie machines tied into it. It's run by Russian organized cybercrime and responsible for ...
Continue Reading

Don't Make These Two Major Multi-Factor Security Mistakes

An employee sent this recent horror story to me (thanks Rachel). Remember there are three ways of learning. :-D Read it in a book, blog (or training session) understand it and apply it ...
Continue Reading

Price Discrimination: The Fantom Menace of Ransomware

By Eric Howes, KnowBe4 Principal Lab Researcher. Over the past few months we've discussed the rising use of price discrimination among purveyors of ransomware to maximize their returns on ...
Continue Reading

New KnowBe4 Phishing Campaign Creation Screen

You asked and we listened! We’ve enhanced our Phishing Campaign creation options to give you more flexibility and customization when phishing your users! You can now: Phish your users ...
Continue Reading

These 500 Million Hacked Yahoo Accounts Are A Phishing Paradise. Warn Your Users!

It's all over the press. Here is a quote from Reuters: "Yahoo Inc said on Thursday information associated with at least 500 million user accounts was stolen from its network in 2014 by ...
Continue Reading

New Version of iSpy Trojan Steals Your Software Licenses

Earlier this year we posted about Jsocket, a highly malicious Trojan that we spotted being delivered through phishing emails shared with us via the Phish Alert Button (PAB). Although ...
Continue Reading

Scam Of The Week: Apple Store Phishing Attack Goes For Whole Enchilada

Phishing attacks using false Apple Store email messages, fake landing pages and sometimes fake login pages are still a very popular attack vector. They still make it through all the ...
Continue Reading

Bad Guy FAIL! or, When a Simple Credentials Phish Goes Horribly Wrong

By Eric Howes, KnowBe4 Principal Lab Researcher. Anyone who works a job in the computer security industry inevitably develops a kind of dark appreciation for the mad skills so often ...
Continue Reading

As Neutrino takes a hit, RIG Exploit Kit jumps at the opportunity and spreads ransomware

Andra Zaharia (the picture is really her) from the Danish Heimdal Security wrote something interesting this morning that I thought you'd like to know:
Continue Reading

Reported Phishes of the Week

KnowBe4's Templates Mistress Katie has been busy again adding a new batch of phishing templates to the collection of "System Templates" available to active subscribers.
Continue Reading

A new "long con" Scam Of The Week: Binary Options

Most scams on the internet are "short con" scams, compare them to hit & run. However, "long con" scams have started to show up that can take a few months to finally steal the money. ...
Continue Reading

Investment fund loses $6 million in CEO Fraud and shuts down

CNBC reported some pretty stunning breaking news. I cannot come up with a better case for new-school security awareness training for employees in accounting and HR. A lawsuit filed on ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews