Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

When a USB Flash Drive is Actually a Bomb

A journalist based in Ecuador recently used a USB flash drive that was actually a legitimate bomb.

Identifying AI-Enabled Phishing

Users need to adapt to an evolving threat landscape in which attackers can use AI tools like ChatGPT to craft extremely convincing phishing emails, according to Matthew Tyson at CSO.

The Future of Cyber Attacks? Speed, More Speed

I get asked all the time to “predict” the future of cybercrime. What will be the next big cyber attack? What will be the next paradigm platform shift that attackers will target? And so on.

An Overview of Silicon Valley Bank Themed Social Engineering

Researchers at ReliaQuest warn that organizations should continue to be on the lookout for social engineering attacks related to Silicon Valley Bank (SVB).

CyberheistNews Vol 13 #12 [Heads Up] This Week's New SVB Meltdown Social Engineering Attacks

CyberheistNews Vol 13 #12 | March 21st, 2023 [Heads Up] This Week's New SVB Meltdown Social Engineering Attacks On Saturday March 11, I warned about the coming wave of phishing attacks ...

Bill 96 in Québec Brings Up Important Point About Training in Native Language Everywhere

A new law in Québec, Canada, that goes into effect this June will require all policies and training materials assigned to employees within the province be provided in French.

[Eye Popper] The AI Genie Has Escaped: Stanford copied ChatGPT for a few hundred bucks

Yikes. Loz Blain at NewAtlas just reported that Stanford has copied the ChatGPT AI for less than $600. The article started out with: "Stanford's Alpaca AI performs similarly to the ...

Report Shows Business Email Compromise (BEC) Attacks Increase and Phishing Used as Initial Attack Vector in the Last Year

Secureworks has published a report looking at cybercrime over the course of 2022, finding that business email compromise (BEC) attacks nearly doubled last year. Additionally, attacks in ...

Warning Customers About Social Engineering.

It’s a familiar story: scam artists impersonate a trusted brand, a trusted business or a trusted authority in emails and on bogus sites designed to exploit that very trust to commit ...

[Black Eye] The Lesson We Learned. Don't Let this Happen to You. #DMARC

Mea Culpa. When you make a mistake, admit you made a mistake.

Phishing Attacks Top List of Initial Access Vectors with Backdoor Deployment as Top Objective

New data looking back at the cyber attacks observed in 2022 shows that phishing continues to dominate as initial access brokers seem to be growing their business using backdoors.

92% of Organizations Have Fallen Victim to Phishing as Nearly Every Org is Concerned with Email Security

New data shows that not only has just about every organization experienced a successful phishing attack, but that they are also paying the price in a number of impactful ways.

Understanding DMARC Better

I talk and present often about DMARC (and SPF and DKIM), including here. A lot of people who think they understand how DMARC works, do not really understand it as well as they think they ...

[FREE RESOURCE KIT] New Phishing Security Resource Kit Now Available!

Phishing emails increase in volume every month and every year, so we created this free resource kit to help you defend against attacks. Request your kit now to learn phishing mitigation ...

A 240% Rise in Dynamic Phishing

Attackers are increasingly using techniques to prevent their phishing pages from being detected by security firms, a new report from BlueVoyant has found. The report found that in 2022 ...

Three-Quarters of Organizations Have Experienced an Increase in Email-Based Threats

New data on the state of email security shows that nearly every organization has been the target of a phishing attack as attacks increase in sophistication.

79% of Employee-Reported Phishing Emails Go Completely Undetected by Cybersecurity Solutions

As cybercriminals increasingly turn to malwareless phishing attacks, the ability for security solutions to correctly identify a malicious email is becoming more and more difficult.

University of Sydney Gives Students and Staff Advice on Avoiding Social Engineering Scams

The University of Sydney has issued advice to help students and staff avoid falling for social engineering attacks.

Season 5 of ‘The Inside Man’ From KnowBe4 Is Less Than a Month Away!

We’re thrilled to announce that Season 5 of the award-winning Knowbe4 Original Series - “The Inside Man” is less than a month away!

Newest FBI Report Shows $10B in Losses Last Year Due to Internet Scams

The 2022 Internet Crime Report by the FBI reported at least $10.3 billion in losses due to internet scams last year.


Get the latest insights, trends and security news. Subscribe to CyberheistNews.