Monthly Archives: November 2022

#CybersecurityAwarenessMonth Mentorship Interview Series: Part 3 – Reverse Mentorship

In the final part of this three-part mentorship series for Cybersecurity Awareness Month we are discussing the advantages and challenges of reverse mentorship. Hear from two members who dared to embark on the complex world of reverse mentorship and shared … Read More

Effective Cybersecurity Board Reporting

By Allen Ari Dziwa, CISSP, CCSP a risk specialist and SME for the Federal Reserve Bank of Cleveland. He has worked in technology and cybersecurity consulting for 15 years. Allen currently serves on the Board of Directors of ISSA North … Read More

Building the Next Generation of Security and Privacy Professionals

The International Association of Privacy Professionals (IAPP) and (ISC)² teamed up to dive into similar challenges facing security and privacy professionals in a constantly evolving world. The latest (ISC)² Workforce Study shows an IT background – either from education or … Read More

Elevating Diverse Voices: (ISC)² Announces Five Key DEI Partnerships

The 2022 (ISC)² Cybersecurity Workforce Study revealed a global workforce gap of 3.4 million professionals. While 55% of respondents believe diversity will increase among their teams within two years, it is no surprise that diversity in the cybersecurity industry is … Read More

LATEST CYBERTHREATS AND ADVISORIES – November 4, 2022

Cyberattacks on Dropbox, Europe’s biggest copper producer and another Australian business make this week’s headlines. Here are the latest threats and advisories for the week of November 4, 2022. Threat Advisories and Alerts Google Chrome Suffers Seventh Zero-Day Vulnerability of … Read More

New LinkedIn-Impersonated Phishing Attack Uses Bad Sign-In Attempts to Harvest Credentials

With compromised LinkedIn credentials providing cybercriminals with ample means to socially engineer business contacts, this campaign is a stark warning for organizations.

DHL Tops the List of Most Impersonated Brand in Phishing Attacks

As scammers shift their campaigns and learn from their successes, new data shows that the global delivery service is the current brand of choice, with equally familiar brands trailing slightly.

KnowBe4 Wins 2022 “Best Software” Awards From TrustRadius in Multiple Categories

KnowBe4 is proud to be recognized by TrustRadius in the first-ever “Best Software” Awards for overall, mid-size, and enterprise in the Security Awareness Training software category.

Number Matching Push-Based MFA Is Only Half the Solution

When push-based multifactor authentication (MFA) first came out, I was a big fan. I promoted it as a strong and safe MFA option in my book, Hacking Multifactor Authentication. That was before I realized that a non-small percentage of users … Read More

Phishing for Feds: Credential-Harvesting Attacks Found in New Study

A study by researchers at Lookout has found that credential-harvesting phishing attacks against US government employees rose by 30% last year. The researchers also found that nearly 50% of US government employees are running older, unpatched versions of iOS and … Read More

CISA Warns of Daxin Team Ransomware Group Targeting the Healthcare and Public Health Sector via VPNs

This new group makes the case that – as with any market – cybercriminals will focus on a niche sector they are experts on in order to improve their chances of success.

CheckPoint Warns of Black Basta Ransomware as the Number of Victim Organizations Increases by 59%

This latest “new kid on the block” is gaining momentum and – according to CheckPoint – seeing successes with their attacks globally, calling their organizational structure “impressive.”

FBI: Watch Out for Student Loan Forgiveness Scams!

Scammers are taking advantage of the victims desire to take advantage of debt cancellation up to $20,000 – with the only one cashing in being the scammer!

Hacking Biometrics: If You Thought Your Fingerprints Were Safe, Think Again!

When you think of using biometric technology as part of your multi-factor authentication process, you assume these attributes are safe. Cybercriminals can’t hack your fingerprints, can they? The answer may surprise you!

Phishing-Resistant Does Not Mean Un-Phishable

Human societies have a bad habit of taking a specific, limited-in-scope fact and turning it into an overly broad generalization that gets incorrectly believed and perpetuated as if it were as comprehensively accurate as the original, more-limited fact it was … Read More

[Scam of The Week] New Phishing Email Exploits Twitter’s Plan to Charge for Blue Checkmark

 Michael Kan at PCMag had the scoop: A hacker is already circulating one phishing email, warning users they’ll need to submit some personal information to keep the blue verified checkmark for free.

CyberheistNews Vol 12 #44 [INFOGRAPHIC] KnowBe4 Top-Clicked Phishing Email Subjects for Q3 2022