Monthly Archives: September 2022

Retail is in Trouble: 77% Of Retail Organizations Have Been Hit by Ransomware

With Retail seeing and feeling the impact of more ransomware attacks than nearly every other industry, a new report focuses in on what the repercussions look like for this sector… and it’s not good.

[New Feature] Managing Your Risk and Compliance Tasks Just Got Easier with KCM’s Jira Integration

We’re thrilled to announce that Atlassian Jira integration support is now available with KnowBe4’s KCM GRC platform.

Phishing Campaign Targets GitHub Users

GitHub has issued an alert warning of a phishing campaign targeting users by impersonating the popular DevOps tool CircleCI, BleepingComputer reports. The phishing emails inform users that they’ll need to click on a link and log into their GitHub account … Read More

LATEST CYBERTHREATS AND ADVISORIES – SEPTEMBER 23, 2022

Cyberattacks on the video game industry, big-name brand data breaches and the Tea Pot gangster make headlines this week. Here are the latest threats and advisories for the week of September 23, 2022. Threat Advisories and Alerts Iranian Cybercriminals Target … Read More

YOUR CYBERSECURITY EXPERIENCE IS NEEDED FOR CREATING NEW U.S. FTC REGULATIONS

The Deadline is Approaching, Your Voice Can Make a Difference in Protecting Privacy The U.S. Federal Trade Commission (FTC) is looking for public input regarding new cybersecurity regulations. (ISC)² members and trained cybersecurity professionals can provide valuable insight into best … Read More

Security Practices Are Improving, But Cybercriminals Are Keeping Up

A survey by GetApp has found that the number of organizations using phishing simulations has risen from 30% in 2019 to 70% in 2022. Despite this positive trend, however, attackers continue to increase both the sophistication and volume of their … Read More

Phishing Attacks Reach an All-Time High, Quadrupling That of Early 2020

New quarterly data from the Anti-Phishing Working Group shows unprecedented phishing activity with increases in BEC, use of social media, vishing, and smishing.

Do Not Use Easily Phishable MFA and That Is Most MFA!

Everyone should use multifactor authentication (MFA), where they can, to protect valuable information. Everyone!

#ISC2CONGRESS – EMPOWERING NEW CONNECTIONS

This year’s (ISC)² Security Congress will feature increased opportunities to network with your peers and will be engaging whether you are joining in-person or virtually. We are looking forward to our first ever hybrid Security Congress where we will be … Read More

CyberheistNews Vol 12 #38 [HEADS UP] New Uber Security Breach ‘Looks Bad’, Caused by Social Engineering

Social Engineering Targets Healthcare Payment Processors

The US Federal Bureau of Investigation (FBI) has issued an alert warning of an increase in phishing and other social engineering attacks against healthcare payment processors.

[HEADS UP] Bank of America Warns About Recent Scams That Request Zelle Payment Due to ‘Suspicious Activity’

Bank of America recently sent a customer service email warning users to watch out for this new phishing attack.

Latest Cyberthreats and Advisories – September 16, 2022

Vulnerabilities in popular tech, major WordPress plugin attacks and phishing, highlight this week’s cybersecurity news. Here are the latest threats and advisories for the week of September 16, 2022. Threat Advisories and Alerts Security Updates Released for Apple Zero-Day Vulnerabilities … Read More

Uber security breach ‘looks bad’, caused by social engineering

iIt was all over the news, but ZDNet’s Eileen Yu was one of the first. — “Hacker is believed to have breached Uber’s entire network in a social engineering attack, which one security vendor says is more extensive than the … Read More

(ISC)² CEO Clar Rosso Honored by SC Media’s Women in IT Security Program

Closing the gender and diversity gap in cybersecurity is critical if the profession is serious about addressing its current workforce crisis. (ISC)² estimates that the Cybersecurity Workforce Gap currently stands at 2.72 million professionals globally, but women only make up … Read More

Phishing from a French Government Career Website

Attackers are exploiting a legitimate French government website to send phishing messages, according to researchers at Vade. The website, Pôle Emploi, is a career site for companies looking for job recruits. The attackers are responding to job postings with phony … Read More

[MSP News] Manage Your Multiple KnowBe4 Accounts Faster with Managed Training and Phishing Rolled Into One

You wanted the ability to manage both phishing and training campaigns across multiple KnowBe4 accounts, and we listened!

Unconventional Security Awareness Advice

October is Cybersecurity Awareness Month, and you are undoubtedly being bombarded with some fantastic advice on how to stay cyber safe. 

Cisco Attempt Attributed to Lapsus$ Group

Security researchers at Cisco Talos have issued an update on the cyberattack Cisco sustained earlier this year. The attack began with a phishing attack against a Cisco employee, which led to the attackers stealing data and attempting to extort the … Read More

#ISC2Congress: Empowering Partnerships

We look forward to seeing you in the Exhibit Hall, the heart of Security Congress. On-site, we will be filling up the Octavius Ballroom at Caesars Palace with 30+ partners, sponsors and exhibitors and can’t miss events.  Kick off your … Read More