Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

KnowBe4's Email Exposure Check Discovers Data Breach

You are probably aware of the free one-time Email Exposure Check Pro (EEC Pro) we can run for you. We find all the email addresses of your domain that are out there available on the ...

Cryptolocker Ransomware Variant Hits Synology Users: Synolocker

When your products get targeted with custom made ransomware, you know you've got it made. We're talking about NAS (network-attached storage) built by Synology in Taiwan. the malware has ...

CryptoLocker copycat Cryptoblocker encrypts differently

Scam Of The Week: eBay Password Reset Phishing Emails

Ok, unless you were on an Internet-free vacation (fat chance); you have heard that eBay managed to lose all its 145 million credentials.

WARNING Third Ransomware Strain Called CryptorBit Attacks

Welcome to the new world of malware.

80% Fail To Maintain PCI Compliance Between Assessments

OUCH. Verizon said in a report this month that nearly 80% of organizations that achieve annual compliance with the PCI Data Security Standard -fail- to maintain that status after passing ...

NIST Releases Voluntary Cybersecurity Compliance Framework

Online social engineering scams flourish around Valentine's Day

Michael Cooney at Network World summarized the current scams doing the rounds related to online dating and romance sites. A good reminder that heartless con artists use social engineering ...

Feb 1st Is National Change Your Password Day

SHOCKER: Point-Of-Failure Phishing Training Does Not Work

The Govinfosecurity site just reported on some very interesting scientific research that finds so-called "embedded training" is ineffective. Let's quickly define "embedded", they chose ...

What Is The Deep Web 101

Pierluigi Paganini wrote a great blog post today. The Deep Web (or Invisible Web) is all the information on the World Wide Web not reported by normal search engines. It's HUGE. According ...

A Serious Legal Liability: Bad or No Security Awareness Training

Please read this article and then forward it to the head of your legal department or the person in your organization who is responsible for compliance. Recently, the Department of Health ...

Scam Of The Week: "Held For Ransom"

FBI’s Internet Crime Complaint Center Ransomware

Citadel 'Shutdown' Just A Microsoft PR Move

Knowbe4 - CyberheistNews Vol 3, #14

91% of cyberattacks begin with spear phishing email

Antony Savvas at Computerworld UK had a good write-up about this quite interesting news: "Some 91% of cyberattacks begin with a "spear phishing" email, according to research from security ...

Industrial Control Systems The Next Twin Towers

[caption id="" align="aligncenter" width="588"] Shodan Network[/caption] Eugene Kaspersky a few days ago wrote a hair-raising blog post about the reality of our Industrial Control Systems ...

Scam Of The Week Payroll Phish

The nakedsecurity blog over at Sophos highlighted a new phishing scam that would be good to alert your employees about. The bad guys are pretending to be payroll processing company ADP. ...

Malware Metastasizes

A few days ago I wrote about a 60 million Euro cyberheist. I have been digging into this a bit more, as it's the most advanced attack yet. Cybercrime is not revolutionary, it clearly ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.