Human Risk Management Blog

Security Awareness Training

Read the latest news about security awareness training, best practices, why you need it, and what happens when you don't have it in place.

Freight Forwarding Email Scams are Business Killers

The Australian Cyber Security Centre (ACSC) has warned that multiple Australian IT suppliers have permanently closed their doors after falling victim to procurement scams, CRN reports. ...

Scam Of The Week: Equifax Settlement Phishing

Well, that did not take long! The Equifax Data Breach resulted in a settlement and those affected have a choice between free credit monitoring or a $125 payment.

Buyers of Facebook’s Libra Cryptocurrency are the Latest Target in Phishing Scams

Scammers are impersonating Facebook to trick potential buyers of Facebook’s new cryptocurrency into parting with their money.

Russian Phishing: Swiss-based Email Provider ProtonMail Hit By Cyber Attack

Reporters investigating Russian military intelligence have been targeted by highly sophisticated cyber attacks through their encrypted email accounts, with evidence suggesting Moscow was ...

CEO Fraud Phishing Scams Versus The U.K. Solicitors

The UK’s Solicitors Regulation Authority (SRA) has warned of another email scam that impersonated a real law firm in order to hijack a real estate transaction, according to Martin Parrin ...

15-year old MyDoom Remains a Common Phish Hook

The destructive email worm MyDoom is still very active more than fifteen years after it was first spotted, according to ZDNet. Researchers at Palo Alto Networks’ Unit 42 observed 663,000 ...

New Ransomware Strain Spreads Via SMS

A new Android ransomware strain was discovered by ESET researchers. It uses the victim's contact list to spread further using SMS messages that have malicious links.

Iranian Hacker Group APT34 Use New ‘Tonedeaf’ Malware over LinkedIn in Latest Phishing Campaign

Targeting several key industries, this new campaign likely seeks to aid the Iranian government with information that could be of use to further Iran’s economic and security goals.

[Heads-up] Nationwide Bomb Threat Extortion Phishing Attack Campaign With A Twist

IN OFFICES AND universities all across the country Thursday, the same threat appeared in email inboxes: Pay $20,000 worth of bitcoin, or a bomb will detonate in your building. Police ...

Reuters: "BlackRock in talks to take over Cofense after U.S. security concerns - sources"

(Reuters) July 28, 2019 — "BlackRock Inc (BLK.N), an investor in Cofense Inc, is in advanced talks to take over the U.S. cyber security firm, after a U.S. national security panel asked ...

Schools In Both The US And UK Victim Of Recent Phishing Attacks

A number of educational institutions have recently fallen victim to cyberattacks, highlighting the need for increased awareness training for students and faculty. SC Media UK has ...

Here Is Some Great InfoSec Budget Ammo From UBS

A KnowBe4 employee forwarded this PDF to me. There is a very interesting point in here: your cybersecurity practices affect the valuation of your company. That should get the attention of ...

OSINT – a Hacker’s First Asset in Targeted Attacks

Before a cybercriminal wants to engage in a targeted attack against a particular organization or individual, they’d like to know a few things first. That’s where OSINT comes into play.

New Study Finds Employees Pose the Greatest Cybersecurity Risk

While historically being seen as an organization’s greatest asset, the latest report from the analyst firm Ponemon cites humans as the weakest link.

Netflix's New "The Great Hack" Reminds Us -- If you Don't Pay For the Product You *Are* The Product

Last night, Netflix premiered “The Great Hack” which is based on the Cambridge Analytica scandal. They reminded us of the golden expression: “If you don't pay for the product you are the ...

BEC = “Because it’s Easy Cash” Scammers Trick Employees Into Giving Away Customer Info

Business Email Compromise—also known as CEO Fraud—scammers are now targeting a company's customers using a new indirect attack method designed to collect information on future scam ...

This Year, Phishing Causes Losses of $17,700 per minute And Ransomware Attacks Will Cost $22,184 Per Minute

Global losses to cybercrime total $1.5 trillion per year, which amounts to $2.9 million per minute, a new report by RiskIQ shows. Some of the largest companies are losing $25 each minute ...

A Phishing Campaign Evades Email Gateways via WeTransfer

A phishing campaign is abusing the legitimate file hosting site WeTransfer to get malicious links through email filters, according to Jake Longden at Cofense. The attackers send real ...

80% of Organizations Don’t Use DMARC Making Them Susceptible to Email Spoofing

DMARC’s ability to confirm a sending domain’s identity seems like a no-brainer, and yet most organizations aren’t taking advantage of this protective service to stop phishing attacks.

Ransomware Attacks Costs Nearly Triple in 2019 to over $36K Per Attack

The latest data from ransomware recovery vendor, Coveware, outlines the current state of the cost, duration, and recovery rate of ransomware attacks today.


Get the latest insights, trends and security news. Subscribe to CyberheistNews.