Human Risk Management Blog

Social Engineering

Latest social engineering news, analysis, tactics the bad guys are using and what you can do to defend your organization.

Ransomware Beats APT In Terms Of Severe Impact

MalwareBytes Research showed that in the year 2014, 82% of companies were attacked online. Their research also showed that browser vulnerabilities will be the biggest challenge going ...

Phishing Lessons Learned in 2014? Employee Training Matters

Our friends at Wombat created a good summary why security awareness training is a must these days. Why?

Top 10 InfoSec Pain Points

Savvy Hackers Use Spearphishing to steal Wall Street M&A info

What if you knew beforehand about mergers and acquisitions, and could trade with that inside information? Well that's been going on for more than a year.

Homeland Security: Security Education Deterred Cybercrime

Homeland Security Today has a good article which explains that cybersecurity education, including employee training and awareness programs, is vital in deterring cybercrime. The ...

Software Support Cybercrime Scam

This week the FTC shut down a $120M tech support scam that consumer software buyers should be aware of. Two telemarketing firms were at the center of this FTC investigation, but there are ...

STATE DEPT COMPUTERS HACKED, EMAIL SHUT DOWN

Associated Press just reported that the State Department has taken the unprecedented step of shutting down its entire unclassified email system as technicians repair possible damage from ...

New Flavor of Ransomware Is More User Friendly

It's been more than a year since the first vicious ransomware stuck up its ugly head.

SCAM of the Week: Free Pizza Delivers Malware

There is a current, active cybercrime campaign going, using the tempting lure of free pizza, researchers at Cloudmark warned. They spotted new spam emails claiming to be a campaign from ...

PCI Publishes Guidance On Security Awareness Training

The Payment Card Industry Council thinks Security Awareness Training is so important that they just published a 25-page guidance paper that fully explains the why, how and what of ...

Scam Of The Week: Ebola Phishing Grows In Volume

I have been warning here before that Ebola phishing attacks would be more and more prevalent, as a result of the mass-media spending increasing amounts of time covering this threat.

Poll: Employees Clueless About Social Engineering

Fresh from Dark reading: "When it comes to social engineering, Pogo, the central character of a long-running American comic strip, said it best. "We have met the enemy and he is us."

New Android Ransomware Strain Locks The Device Twice

Researchers in Russia discovered a new Android ransomware strain which does not lock the device just once but twice. It spreads by using a social engineering trick, disguising itself as a ...

Home Depot, Target Breaches Exploited Old WinXP Flaw

The massive security breaches and theft of credit card information at The Home Depot and Target have something in common. They were both allowed by a vulnerability in XP embedded that was ...

Regular Facebook Users Are More Likely To Fall For Phishing Scams

Techcrunch was the first one to report on some very interesting findings:

New KnowBe4 Whitepaper: A Short History of Ransomware

Cyber Criminals Use AEA-256 Crypto To Obfuscate Phishing Sites

The Register said: "Well, at least someone listened to Snowden about privacy... Phishing fraudsters have begun using industry-standard AES-256 encryption to disguise the content of ...

Five Reasons Why Clicking "Unsubscribe" May Be A Bad Idea

When you get on a mailing list you don't want to be on, it's easy to get off – just click on the "unsubscribe" link. But should you? Sophos Naked Security says maybe not. When you ...

Scam Of The Week: Jennifer Lawrence Nude Pictures Phishing

There is a new (true) Current Event which unfortunately is the ultimate click bait. A hacker got into the Apple iCloud and hacked the account of Jennifer Lawrence and many other celebs.

Chase Is Asking For Phishing Trouble

Chase bank says to click links if you suspect phishing. Huh? Yup, they do. Check out this email from Chase, scratch your head, and do not make this error in your own organization. If you ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.