Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

What is the Necurs Botnet And How Does It Spread Locky Ransomware?

In Short: The Necurs botnet is one of the world's largest botnets with more than 6 million zombie machines tied into it. It's run by Russian organized cybercrime and responsible for ...

Don't Make These Two Major Multi-Factor Security Mistakes

An employee sent this recent horror story to me (thanks Rachel). Remember there are three ways of learning. :-D Read it in a book, blog (or training session) understand it and apply it ...

Price Discrimination: The Fantom Menace of Ransomware

By Eric Howes, KnowBe4 Principal Lab Researcher. Over the past few months we've discussed the rising use of price discrimination among purveyors of ransomware to maximize their returns on ...

New KnowBe4 Phishing Campaign Creation Screen

You asked and we listened! We’ve enhanced our Phishing Campaign creation options to give you more flexibility and customization when phishing your users! You can now: Phish your users ...

These 500 Million Hacked Yahoo Accounts Are A Phishing Paradise. Warn Your Users!

It's all over the press. Here is a quote from Reuters: "Yahoo Inc said on Thursday information associated with at least 500 million user accounts was stolen from its network in 2014 by ...

New Version of iSpy Trojan Steals Your Software Licenses

Earlier this year we posted about Jsocket, a highly malicious Trojan that we spotted being delivered through phishing emails shared with us via the Phish Alert Button (PAB). Although ...

Scam Of The Week: Apple Store Phishing Attack Goes For Whole Enchilada

Phishing attacks using false Apple Store email messages, fake landing pages and sometimes fake login pages are still a very popular attack vector. They still make it through all the ...

Bad Guy FAIL! or, When a Simple Credentials Phish Goes Horribly Wrong

By Eric Howes, KnowBe4 Principal Lab Researcher. Anyone who works a job in the computer security industry inevitably develops a kind of dark appreciation for the mad skills so often ...

As Neutrino takes a hit, RIG Exploit Kit jumps at the opportunity and spreads ransomware

Andra Zaharia (the picture is really her) from the Danish Heimdal Security wrote something interesting this morning that I thought you'd like to know:

Reported Phishes of the Week

KnowBe4's Templates Mistress Katie has been busy again adding a new batch of phishing templates to the collection of "System Templates" available to active subscribers.

A new "long con" Scam Of The Week: Binary Options

Most scams on the internet are "short con" scams, compare them to hit & run. However, "long con" scams have started to show up that can take a few months to finally steal the money. ...

Investment fund loses $6 million in CEO Fraud and shuts down

CNBC reported some pretty stunning breaking news. I cannot come up with a better case for new-school security awareness training for employees in accounting and HR. A lawsuit filed on ...

CyberheistNews Vol 6 #38 [ALERT] FBI Warns Ransomware Attacks Are Getting More Dangerous And Expensive

*|CyberHeistNews|* CyberheistNews Vol 6 #38 [ALERT] The FBI Warns That Ransomware Attacks Are Getting More Dangerous And Expensive In an alert published this week, the U.S. Federal Bureau ...

McAfee: Ransomware Has Grown 128 Percent Over 2015

Intel Security's McAfee Labs Threat Report for September 2016 provides insight into the latest security statistics and trends, ranging from botnets to ransomware to malware "zoos." Large ...

Meet Mamba: New Full Disk Encryption Ransomware

SecurityAffairs just published a new discovery that you need to know about. A Brazilian Infosec research group, Morphus Labs, just discovered a new Full Disk Encryption (FDE) ransomware ...

[ALERT] FBI Warns Ransomware Attacks Get More Targeted And Expensive

In an alert published today, the U.S. Federal Bureau of Investigation (FBI) warned that recent ransomware variants have targeted and compromised vulnerable business servers (rather than ...

New Vicious And Highly Targeted Ransomware Attacks Made Public

Here’s an example of a highly targeted ransomware attack, with bad guys using a phony Bank of Montreal (BMO) template to social engineer possible victims into clicking on a malicious ...

A Single Ransomware Gang Made $121M In 2016

Intel Security today released its McAfee Labs Threats Report: September 2016, which assesses the growing ransomware threat; surveys the “who and how” of data loss; explains the practical ...

Targeted Lawsuit Phishing Attack With Sophisticated Payload

We are seeing a big phishing wave with a social engineering attack that threatens with a personalized lawsuit using the domain name of the targeted victim. This is an interesting payload ...

Adding Insult To Injury: The Ginsu Knives Approach To Ransomware

Kaspersky has a fascinating blog post on a new strain of ransomware called RAA that is not only fairly sophisticated, but incredibly abusive:


Get the latest insights, trends and security news. Subscribe to CyberheistNews.