Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

FIN10: Anatomy of a Ransomware Phishing Extortion Operation

Cyber security firm FireEye reported that that a number of Canadian mines and casinos were hacked by a group named FIN10 – FireEye labels FIN10 to be “one of the most disruptive threat ...

CIA Director Brennan: "Russia's Cyber Capability Increasingly Sophisticated And Not Bound By Law"

I was at the Gartner Security & Risk Management Summit at National Harbor, in DC this week. One of the keynotes was by CIA Director George Brennan, who was sworn in as director of the ...

Did WannaCry Ransomware Escape North Korean Containment?

Mike Mimoso at Kaspersky's Threatpost blog raised the theory that the ransomware wasn’t contained properly and spread before it was meant to be unleashed. Malware expert Jake Williams, ...

Southern Oregon University Lost $1.9 Million Due To CEO Fraud

Mail Tribune reported that Southern Oregon University is just the latest victim of CEO fraud (which the FBI calls Business Email Compromise or BEC) after hackers tricked university ...

ICO less likely to issue fines for data breaches if they show staff training

The UK's Information Commissioner's Office has said that in the event of a data breach it would be less likely to issue a monetary penalty to charities which had taken “reasonable steps” ...

CyberheistNews Vol 7 #24

This Ransomware Targets HR Departments With Fake Job Applications

I missed this one a few months ago, but it's a great example how focused the bad guys are getting with their attacks, and you need to watch out for this social engineering attack vector ...

Windows 10 Stops Ransomware Cold... Or Does It?

OK, finally there is some good news in the fight against ransomware!

New PowerPoint Social Engineering Attack Installs Malware Without Requiring Macros

Researchers at Security firm SentinelOne reported that a group of hackers is using malicious PowerPoint files to distribute 'Zusy,' a banking Trojan, also known as 'Tinba' (Tiny Banker). ...

Federal Contractor? Insider Threat Training Deadline June 1- Don't Lose Your Clearance

Insider Threat Training Requirement for US Gov't Contractors (Deadline May 31, 2017) SANS just alerted US federal contractors that wish to maintain their clearances must have completed an ...

ITIC / CyberheistNews Top 10 IT Security Recommendations May 2017

By Laura DiDio There is no such thing as a 100% fully secure environment. And there never will be. Security is not static; it is an ongoing work in progress. Organizations must be ...

Netflix, ABC Hacker Promises More Phishing: "Hollywood Is Under Attack"

The Hollywood Reporter (THR) talked directly to TheDarkOverlord hacking collective that claims to have studio films. They said: "We're in the business of earning vast amounts of internet ...

Top Secret NSA Doc Shows Russians Spear-Phishing Election Officials

The Intercept reported that the GRU (Russian Military Intelligence, the FSB's counterpart) executed a cyberattack on at least one U.S. voting software supplier and sent spear-phishing ...

CyberheistNews Vol 7 #23

Have We Reached "Peak Ransomware"?

There was an article with the title: "Don’t panic: We’ve reached ‘peak ransomware’" in a publication called The Memo. They decided to ask an expert: Rik Ferguson, VP of security research ...

Scam Of The Week: DMV Warns Drivers About Traffic Ticket Phishing

Online reporter Doug Olenick at SC Media was the first to point to a press release from the NY State Department of Motor Vehicles warning about a phishing scam where New York drivers are ...

Did you know how the word Phishing came to be?

I found this at ComputerWorld: "The word phishing was coined around 1996 by hackers stealing America Online accounts and passwords. By analogy with the sport of angling, these Internet ...

Powerful New KnowBe4 Feature: Training Notifications Are Here!

We have a powerful new feature that you can use now. Here is the data about the training notifications and how they work. This feature is for all subscription levels that have training, ...

Vladimir Putin Approves Of Patriotic Russian Hackers

The WSJ just posted a very interesting article by Nathan Hodge confirming what we have been saying here for the last few years. Russian President Vladimir Putin suggested in St Petersburg ...

Florida Governor Rick Scott sent KnowBe4 a Congrats Letter

KnowBe4 received a very nice letter from Florida Governor Rick Scott, saying: "Dear Mr. Sjouwerman, Congratulations on KnowBe4, Inc. recently being included in the Tampa Bay Business ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.