Human Risk Management Blog

Security Awareness Training

Read the latest news about security awareness training, best practices, why you need it, and what happens when you don't have it in place.

Fake News and Misplaced Trust

Fighting deepfakes and fake news requires society as a whole to treat what they see with more skepticism, according to Lisa Forte, founder of Red Goat Cyber Security. On the CyberWire’s ...

Organizations Beware! Cyberattacks are Becoming More Prevalent, Hitting More Device OSes, and are Shifting Focus to You

The latest data from Malwarebyte’s annual State of Malware Report shows increases almost across the board, showing that the bad guys are stepping on the gas into 2020.

PayPal Phishing for Passports and More

An ongoing PayPal phishing campaign is trying to steal a wide range of personal information, including Social Security numbers and passport photos, Threatpost reports. The scams were ...

FBI Internet Crime Report Released: The Evolving Threat and Importance of Reporting

The FBI's Internet Crime Complaint Center released its 2019 Internet Crime Report, and by no surprise the bad guys and new scams show no signs of stopping anytime soon. Last year the ...

Seasonal Scams: Valentine's Day Edition

Romance scams and confidence scams cause both emotional and financial pain. According to the latest FBI's Internet Crime Complaint Center (IC3) figures for 2019, confidence/romance scams ...

DOJ Charges Hackers from the Chinese People Liberation Army with 2016 Equifax Data Breach

Four hackers have been charged with hacking the U.S. credit reporting agency where data on U.S. citizens and proprietary Equifax secrets were stolen.

Email Account Takeover Attacks Get Smarter, Sophisticated, and More Patient

New data from Barracuda shows attackers take their time to leverage the credential compromise and to avoid detection when taking over email accounts.

Most British Breaches Traced to Human Error

90% of data breaches in the UK during 2019 were caused by human mistakes, Infosecurity Magazine reports. CybSafe analyzed all the data breach reports received by the UK Information ...

Safer Internet Day: What You Can Do to Stay Safe

February 11, 2020 is Safer Internet Day, a worldwide event aimed at promoting the safe and positive use of digital technology for all users, especially children and teens. This year's ...

Education is Necessary to Stay Ahead of Threats

Most people don’t realize how vulnerable they are to social engineering until they experience it, according to Anna Collard, the founder of KnowBe4’s South African security awareness ...

Another SMS Scam

A new PayPal SMS phishing campaign is making the rounds, according to Paul Ducklin at Naked Security. The text messages in this campaign purport to come from PayPal and inform recipients ...

SEC Releases Results of Cybersecurity and Resiliency Practices Examinations

The SEC’s Office of Compliance Inspections and Examinations (OCIE) published a new report on the findings from examining the methods used by market participant organizations.

January Content Update: Including the new 2020 KnowBe4 Social Engineering Red Flags Training Module

Here are a few important updates to share with you from the month of January.

Six Security Questions You Should Keep in Mind for Third Parties

Organizations are beginning to understand the consequences of a data breach or a phishing attack and the negative impact they can really have. But what are the security risks for third ...

Charities Need to Watch Out for Scammers

The UK’s National Council for Voluntary Organisations (NCVO) has warned charities to be wary of scammers, Charity Digital News reports. The NCVO’s Road Ahead 2020 report outlines trends ...

Not the Antiques Roadshow

Scammers conned a Dutch museum into sending them £2.4 million (about $3.1 million) by posing as a real London-based art dealer who planned to sell the museum a John Constable painting, ...

Law Firms Are the Latest Victims of Maze’s Ransomware and Extortion Attacks

With five law firms hit within just the last week, the Maze ransomware is making itself known and should be a warning to any and all legal firms that preventing an attack is paramount.

Unusual New Botnet-driven Phishing Attack With Tricky Downloaders

A large phishing campaign is distributing malicious Excel documents and utilizing irritating pop-ups to trick users into enabling macros, researchers at Lastline have found. The campaign ...

Your Cyber Insurance Policy Just Became Outdated

Just when we think we have a handle on our cyber insurance, the ransomware attackers have come and stirred things up again. I’m talking about the new trend in ransomware that you may not ...

Intelligence Services Get Phishing Licenses

New York Times journalist Ben Hubbard was targeted by a spear phishing attack designed to deliver NSO Group’s Pegasus spyware, researchers at the University of Toronto’s Citizen Lab have ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.