Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

We Are At War In The Digital World

I just read an opinion editorial in the Wall Street Journal that really did clarify the new threat we are faced with this last decade. "Ten years ago, the 9/11 Commission Report triggered ...
Continue Reading

Cyber Criminals Use AEA-256 Crypto To Obfuscate Phishing Sites

The Register said: "Well, at least someone listened to Snowden about privacy... Phishing fraudsters have begun using industry-standard AES-256 encryption to disguise the content of ...
Continue Reading

CyberheistNews Vol 4, 36 Scam Of The Week: Bitcoin Wallet Theft

CyberheistNews Vol 4, # 36
Continue Reading

Five Reasons Why Clicking "Unsubscribe" May Be A Bad Idea

When you get on a mailing list you don't want to be on, it's easy to get off – just click on the "unsubscribe" link. But should you? Sophos Naked Security says maybe not. When you ...
Continue Reading

New Ransomware Discovered Called CryptoGraphic Locker

Panda researcher BartBlaze discovered a new strain of ransomware called CryptoGraphic Locker. Bleepingcomputer wrote: "Just like other encrypting ransomware, this infection will scan your ...
Continue Reading

CyberheistNews Vol 4, # 35 Scam Of The Week: Jennifer Lawrence

CyberheistNews Vol 4, # 35
Continue Reading

Is The Home Depot Hack Really Russian Retaliation?

Brian Krebs blogged: "Multiple banks say they are seeing evidence that Home Depot stores may be the source of a massive new batch of stolen credit and debit cards that went on sale this ...
Continue Reading

Scam Of The Week: Jennifer Lawrence Nude Pictures Phishing

There is a new (true) Current Event which unfortunately is the ultimate click bait. A hacker got into the Apple iCloud and hacked the account of Jennifer Lawrence and many other celebs.
Continue Reading

Meet CryptoWall, The New Ransomware Leader (with heatmap)

Malware comes in waves. CryptoLocker was the first major, vicious ransomware, and set off a bunch of copycats. Recently 16 competing ransomware gangs were identified. After CryptoLocker ...
Continue Reading

Chase Is Asking For Phishing Trouble

Chase bank says to click links if you suspect phishing. Huh? Yup, they do. Check out this email from Chase, scratch your head, and do not make this error in your own organization. If you ...
Continue Reading

J.P. Morgan Hacked Because Malware Infects Employee PC

This morning, the Wall Street Journal reported on the front page that J.P. Morgan was hacked and suffered a cyberheist called "a significant breach of corporate computer security".
Continue Reading

Bitcoin Phishing Click Rate Higher Than Regular Scams

The Proofpoint Threatinsight blog reported on something curious. They called their posting "Curiosity Clicks: Using Bitcoin’s hype for phishing fun" and came up with some interesting ...
Continue Reading

CyberheistNews Vol 4, # 34 Cryptolocker Being Spread Via YouTube Ads

CyberheistNews Vol 4, # 34
Continue Reading

A cybersecurity video you should really watch

Cybersecurity as Realpolitik by Dan Geer at Black Hat USA 2014
Continue Reading

900,000 Android Phones Hit by Ransomware in 30 days

August 22, 2014 - Nicole Perlroth at the New York Times wrote: "You are guilty of child porn, child abuse, zoophilia or sending out bulk spam. You are a criminal. The Federal Bureau of ...
Continue Reading

Not news: Windows Store is full of scam apps

Paul Thurrott over at WindowsIT Pro wrote:
Continue Reading

Workers At U.S. Nuclear Regulator Fooled By Phishing

Antone Gonsalves at CSO reported something that worries me, and this SHOULD NOT BE at this day and age.
Continue Reading

Cryptolocker Being Spread On YouTube Ads

VirusBulletin reported that cyber criminals now spread around Cryptolocker / CryptoWall via YouTube. The cyber criminals purchase advertising space and use exploit kits to infect ...
Continue Reading

Reveton Ransomware Adds Powerful Password Stealer

The Avast Blog reports a new "password stealer" feature in the Reveton ransomware. Reveton is the type of "police" lock/screen ransomware which falsely alerts users they've broken some ...
Continue Reading

Hacking Into Traffic Lights With a Plain Old Laptop Is Scary Simple

Gizmodo reported yesterday about a new study from the University of Michigan on the vulnerabilities of traffic lights which is shocking proof that we need to make some major changes, and ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews