The US Cybersecurity and Infrastructure Security Agency (CISA) has found that compromise of valid accounts and spear phishing attacks were the two most common vectors of initial access in 2022, Decipher reports. Valid accounts were compromised in 54% of successful … Read More
Monthly Archives: July 2023
CISA Discovers Spear Phishing and Valid Account Compromise Are the Most Common Attack Vectors
Amazon Sends Email to Customers on Common Scam Tactics
We’ve reported on several Amazon scams, but for once, there is positive news. Amazon sent an email Thursday morning highlighting the top scams your users should watch out for:
Heads Up: Google Inactive Account Deletion Notifications
Google announced an update to their inactive account policies in May. Accounts that have been inactive for a period of two years or more will start being deleted in December 2023, at the earliest.
Researchers uncover surprising method to hack the guardrails of LLMs
Researchers from Carnegie Mellon University and the Center for A.I. Safety have discovered a new prompt injection method to override the guardrails of large language models (LLMs). These guardrails are safety measures designed to prevent AI from generating harmful content.
Your KnowBe4 Fresh Content Updates from July 2023
Check out the 28 new pieces of training content added in July, alongside the always fresh content update highlights, events and new features.
SEC Implements New Rule Requiring Firms to Disclose Cybersecurity Breaches in 4 Days
What happened? The SEC (Securities and Exchange Commission) has introduced new rules that require public companies to be more transparent about their cybersecurity risks and any breaches they experience.
Phishing Email Attack Numbers “Decline” While Malware Volumes Increase 15%
New data focused on the first half of the year shows some anomalies. Phishing attacks are slowing down… that is, until you dive into the details.
Russia-Based Global Cybersecurity Vendor Group-IB Exits the Russian Market
Amid potential concerns by governments, customers, and prospects about ties with the Russian government, the cybersecurity vendor Group-IB continues in its promise to separate itself from Russia.
Facebook Scams Impersonate AI Tools
Fraudsters are spreading scams on Facebook that pose as ads for legitimate AI tools, according to researchers at Check Point. The Facebook pages impersonate ChatGPT, Google Bard, Midjourney, Jasper, and more.
[Live Demo] Customizing Your Compliance Training to Increase Effectiveness
Linking compliance training to specific outcomes is hard. Compliance training has a reputation for being challenging for organizations to offer, difficult to do right and employees are not engaged.
How KnowBe4 Can Help You Fight Spear Phishing
This blog was co-written by KnowBe4’s Data-Driven Defense Evangelist Roger A. Grimes and Chief Learning Officer John Just. Social engineering is involved in 70% to 90% of successful compromises. It is the number one way that hackers and malware successfully … Read More
New IBM report reveals the cost of a data breach now tops $4.45 million
IBM Security has released its annual Cost of a Data Breach Report, revealing that the global average cost of a data breach reached $4.45 million in 2023. This marks a significant increase of 15% over the past 3 years, making … Read More
[Live Demo] Ridiculously Easy Security Awareness Training and Phishing
Old-school awareness training does not hack it anymore. Your email filters have an average 7-10% failure rate; you need a strong human firewall as your last line of defense.
Barbie-Related Scams Emerge After Recent Movie Release
Scammers are taking advantage of the popularity of the Barbie movie, according to researchers at McAfee.
The Secret’s Out: Researchers Reveal Backdoor in Emergency Radio Encryption
For over 25 years, a technology utilized for vital data and voice radio communications globally has remained under wraps, preventing in-depth testing for potential vulnerabilities. However, a small group of researchers in the Netherlands has now shed light on it, … Read More
Phony Browser Updates Deliver NetSupport Trojan Using Social Engineering Tactics
A new social engineering campaign tracked as “FakeSG” is distributing the NetSupport remote access Trojan (RAT) via phony browser updates, according to researchers at Malwarebytes. The campaign is similar but distinct from the widespread “SocGholish” campaign, which also uses fake … Read More
CyberheistNews Vol 13 #30 [IN MEMORIAM] Kevin David Mitnick (Aug 6, 1963 – July 16, 2023)
FBI Warns of Increased Tech Support Scams Using Snail Mail
The US Federal Bureau of Investigation (FBI) has warned of an increase in tech support scams that attempt to trick users into sending cash via snail mail.
Save $200 on Your Security Awareness and Culture Professional (SACP) Certification
H Layer Credentialing is launching an updated exam form with new content and they need YOUR help! They are looking for professionals interested in earning their SACP Certification to complete the exam between August 14th and September 30th. This will … Read More
The Number of Data Compromises Jumps 50% in H1 2023, Outpacing Every Year on Record
New data from the Identity Theft Resource Center (ITRC) covering the first half of this year shows a significant rise in the number of successful cyber attacks focused on stealing corporate data.