Human Risk Management Blog

Security Awareness Training

Read the latest news about security awareness training, best practices, why you need it, and what happens when you don't have it in place.

Passwords and Their Encryption Are Easy Prey for Cyber Criminals in Account Takeover Attacks

Passwords serve as the foundation for most security today. But security vendor SpyCloud have recovered over 3.5 billion credentials, demonstrating just how insecure they really are.

Cyber Criminals use Domino Effect Chain Attacks to Leverage One Compromised Bank to Infect the Next

New details from international security company Group-IB show how cybercriminals are no longer looking to just steal from one bank. Instead they chain their attacks to improve their ...

New Facebook Phishing Scam is So Good It Will Fool Even You

Scams seeking to harvest online credentials have long tried to replicate known logon pages. But this newly found instance is just about perfect.

KnowBe4 Fresh Content & Feature Updates - February 2019

NEW 'TARGETED TRAINING' FILTER IN MODSTORE You can now easily browse the industry and role based training content in the KnowBe4 ModStore.

Healthcare Continues to Prepare in the Face of Growing Cyber Attacks

According to the latest data in the 2019 HIMSS Cybersecurity Survey, the healthcare industry is keenly aware they are a target, and are taking steps to reduce the risk of successful ...

[Scam Of The Week] Robocall scams surge to 85 billion globally

Robocall spam has surged to 85 billion calls globally with bank account, credit card and extortion being common scams, according to Hiya, a company that makes apps to fend off unwanted ...

Discovered: A Whole New Strain Of Voice Phishing Attacks

What if social engineers, instead of calling victims with voice phishing attacks, intercepted phone calls their victims make to legitimate phone numbers? Malicious apps let cybercriminals ...

Friday Afternoon, Monday Morning, and Law Firm Risk

Law firm employees appear to be getting better at avoiding real estate scams, says Toni Ryder-McMullin at Today’s Conveyancer. Conveyance is the act of transferring an ownership interest ...

reCAPTCHA Phishbait Targets Google Users

A phishing campaign is using a phony Google reCAPTCHA system to deliver banking malware, according to researchers at Sucuri. The attackers are sending emails, supposedly from a Polish ...

Identity Theft by Low-Interest Credit Card Offer

Scammers have stolen large amounts of personal and financial information from thousands of Canadians via fraudulent phone calls offering lower interest rates on credit cards, an ...

It's The Season for Tax Scams... Again

America's Internal Revenue Service is warning taxpayers about a surge in phishing emails, links, and phone calls during tax season, according to Toni Birdsong at McAfee. The scammers pose ...

Cyber Espionage Warning: The Most Advanced Hacking Groups Are Getting More Ambitious

Once attackers might have needed the latest zero-days to gain access to corporate networks, but now it's spear-phishing emails using social engineering tactics that are most likely to ...

The NoRelationship Attack Bypasses Office 365 Email Attachment Security

Attackers are bypassing Office 365 email attachment security by editing the relationship files that are included with Office documents, according to Yoav Nathaniel at Avanan. A ...

Hackers take over Tampa Mayor Bob Buckhorn's Twitter account, make bomb threat at Tampa Airport

TAMPA, Fla. (WFLA) - Tampa police are investigating a bomb threat made against Tampa International Airport after hackers took over Tampa Mayor Bob Buckhorn’s Twitter account Thursday ...

Remote Access Credentials Are the Latest Malware Attack Target

The latest iteration of notable banking trojan, Trickbot, now includes a password grabbing module designed to provide cybercriminals with remote access to internal systems.

It’s Time to Have a Security Plan Around Consumer Data Privacy

The growth in both consumer concern and laws seeking to protect consumer data means organizations need to take specific measures to ensure the safeguarding of customer data.

Business Email Compromise, Credential Theft, and Many Other Attack Vectors Surged as High as 5x in Q4 2018

The latest data from Proofpoint shows many types of cyberattacks making massive jumps in comparison to both previous quarters and years.

Cyberheist On Bank Causes Shutdown Of All Operations

Reuters reported that the Bank of Valetta, which accounts for almost half of Malta’s banking transactions, had to shut down all of its operations on Wednesday after hackers broke into its ...

New York State Education Department Proposes New Regulations to Strengthen PII Security

The new proposed amendments seek to protect the personally identifiable information for students and school personnel accessible by both educational agencies and contractors.

Bogus Security Alerts Aren’t From Norton

Con artists are targeting thousands of people with tech support scams that pose as security alerts from Norton Security, researchers at Symantec have found. The phony alerts pop up in the ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.