Human Risk Management Blog

Social Engineering

Latest social engineering news, analysis, tactics the bad guys are using and what you can do to defend your organization.

Poll: Employees Clueless About Social Engineering

Fresh from Dark reading: "When it comes to social engineering, Pogo, the central character of a long-running American comic strip, said it best. "We have met the enemy and he is us."

New Android Ransomware Strain Locks The Device Twice

Researchers in Russia discovered a new Android ransomware strain which does not lock the device just once but twice. It spreads by using a social engineering trick, disguising itself as a ...

Home Depot, Target Breaches Exploited Old WinXP Flaw

The massive security breaches and theft of credit card information at The Home Depot and Target have something in common. They were both allowed by a vulnerability in XP embedded that was ...

Regular Facebook Users Are More Likely To Fall For Phishing Scams

Techcrunch was the first one to report on some very interesting findings:

New KnowBe4 Whitepaper: A Short History of Ransomware

Cyber Criminals Use AEA-256 Crypto To Obfuscate Phishing Sites

The Register said: "Well, at least someone listened to Snowden about privacy... Phishing fraudsters have begun using industry-standard AES-256 encryption to disguise the content of ...

Five Reasons Why Clicking "Unsubscribe" May Be A Bad Idea

When you get on a mailing list you don't want to be on, it's easy to get off – just click on the "unsubscribe" link. But should you? Sophos Naked Security says maybe not. When you ...

Scam Of The Week: Jennifer Lawrence Nude Pictures Phishing

There is a new (true) Current Event which unfortunately is the ultimate click bait. A hacker got into the Apple iCloud and hacked the account of Jennifer Lawrence and many other celebs.

Chase Is Asking For Phishing Trouble

Chase bank says to click links if you suspect phishing. Huh? Yup, they do. Check out this email from Chase, scratch your head, and do not make this error in your own organization. If you ...

J.P. Morgan Hacked Because Malware Infects Employee PC

This morning, the Wall Street Journal reported on the front page that J.P. Morgan was hacked and suffered a cyberheist called "a significant breach of corporate computer security".

Bitcoin Phishing Click Rate Higher Than Regular Scams

The Proofpoint Threatinsight blog reported on something curious. They called their posting "Curiosity Clicks: Using Bitcoin’s hype for phishing fun" and came up with some interesting ...

Not news: Windows Store is full of scam apps

Paul Thurrott over at WindowsIT Pro wrote:

Workers At U.S. Nuclear Regulator Fooled By Phishing

Antone Gonsalves at CSO reported something that worries me, and this SHOULD NOT BE at this day and age.

Cryptolocker Being Spread On YouTube Ads

VirusBulletin reported that cyber criminals now spread around Cryptolocker / CryptoWall via YouTube. The cyber criminals purchase advertising space and use exploit kits to infect ...

Phishing: 4.5 million Community Health patients records stolen

n">(Reuters) - Community Health Systems Inc, one of the biggest U.S. hospital groups, said it was the victim of a cyber attack that originated in China, resulting in the theft of ...

New CryptoLocker copycat: TorrentLocker

iSIGHT partners discovered a new ransomware strain, which uses components of CryptoLocker and CryptoWall but underneath the surface, the code is completely different from these two ...

As Expected: Robin Williams 'Goodbye Video' Facebook Phishing Message

The scammers are at it, as expected. There is now a Facebook phishing message that invites users to click a link and see an "exclusive" video of Robin Williams saying goodbye through his ...

Scam Of The Week: See Robin Williams Last Words On Video

Last night, news broke that Robin Williams was found dead in his home in Marin County, CA. It is suspected that it was either a suicide or an overdose. This is a celebrity death that the ...

Security Awareness Training blocked Ransomware Infection

ComputerWorld in Australia reported on a very nice success where security awareness training prevented a major ransomware infection. They started out with: "People like to ask the ...

Heads-Up: Second Generation Ransomware In The Wild

Last week, Fedor Sinitisyn, blogger and security researcher for Kaspersky posted something worrisome. He reported that the Angler Exploit Kit was delivering a new second-generation type ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.