Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Double-check that cashiers check

The fake cashier's check scam has gotten more sophisticated. Cathy Bussewitz at the pressdemocrat site reported on this one: "It usually starts when a seller posts a big-ticket item on ...

Retelling a Password Nightmare in the Wake of the LinkedIn Password Leak

Alan Shimel tell us an enlightening and cautionary tale how his password was hijacked and how much time it took him to get it all back under control. This is a warmly recommended read ...

Why antivirus companies failed to catch Flame and Stuxnet

Arstechnica picked up the blog post of F-Secure's Chief Research Officer: A/V outfits were out of their league. Mikko Hypponen is the Chief Research Officer of F-Secure. He has been ...

Apple Releases Guide To iOS Security

Techcrunch wrote: "Apple has introduced a guide to iOS security, which was posted to Apple.com sometime in late May, but is just now being noticed outside the Apple developer community. ...

Microsoft releases 'Anti-Flame' Update

Redmond stated: "We recently became aware of a complex piece of targeted malware known as “Flame” and immediately began examining the issue. As many reports assert, Flame has been used in ...

F-Secure Cautions about Fresh Olympic-themed Spam

F-Secure the security company based in Finland has recently cautioned that spam mails themed on the Olympics are targeting Internauts while carrying web-links to one malevolent PDF file ...

Fake LinkedIn Emails To Reset Your Password

Since LinkedIn had their IPO, they have been in the news a lot more, even if only to compare them with the recent Facebook IPO Debacle. But the better known you are, the bigger target you ...

Over-55s Pick Passwords Twice As Secure As Teenagers

"People over the age of 55 pick passwords double the strength of those chosen by people under 25 years old. That's according to the largest ever study of password security, which also ...

Malicious PowerPoint File Contains Exploit, Drops Backdoor

TrendLabs discovered a malicious MS PowerPoint document that arrives attached to email messages. The file contains an embedded Flash file, which exploits a software bug found in specific ...

Aaaugh! 1 in 5 U.S. Windows PCs Lack Antivirus Defenses

Un-friggin-believable but true. Don't be one of them! Gregg Keizer at ComputerWorld was the first with this story. "Nearly a fifth of Windows PCs in the U.S. lack any active security ...

VIDEO The Top 5 Online Security Traps And How To Avoid Them

GFI is one of the few antivirus vendors that understands the importance of prevention and end-user training. They produced this useful video that in two minutes illustrates the top 5 ...

Gmail Security Hole Allows Hackers To Automate Social Engineering Trick

Christopher Mims over at Technology Review was the first one to report on this. A large Gmail security hole could lead to mass harvesting of accounts, as hackers can automate this social ...

Fake Facebook “Account Cancelation Requests” Lead to Malware

Softpedia reported: "A shady-looking email, apparently originating from Facebook, has been seen in inboxes, informing users that the social media network has received an account ...

How to Start an IT Security Awareness Program

Mike Chapple is an IT professional and assistant professor of computer applications at the University of Notre Dame. He wrote at biztechmagazine:"Are your users aware of their ...

Weak passwords STILL subvert IT security

Jaikumar Vijayan over at Computerworld observed correctly: "A recent data breach that exposed the Social Security numbers of more than 280,000 people served as yet another reminder of the ...

Cost of penetration testing < cost of security incident :)

The Cost of a Security Incident Is Usually Much Greater Than Preventing It This is a blog post by John Pescatore, July 24, 2009, and still as valid today as it was then. "A few years ago ...

RSA Post-mortem: Massive Human Component To Security

George Hulme wrote on the CSO site: "There was an unusual level of gloom at the RSA Conference this year, and for good reason: a number of the biggest and most respected security firms ...

Message For The Owner: "Your Bank Account Emptied By Cyber Thieves"

Editor's Corner

Facebook Malware Scam Of The Week

Editor's Corner Facebook Malware Scam of the Week A "worrying number" of Facebook users are sharing a link to a malware-laden fake CNN news page reporting the U.S. has attacked Iran and ...

The Security Earthquake That Nobody Felt

Editor's Corner


Get the latest insights, trends and security news. Subscribe to CyberheistNews.