Cyber threats can be scary, and for good reason.
Monthly Archives: October 2023
[FREE RESOURCES] Celebrate Cybersecurity Awareness Month This October with our Cyber-Monsters!
Malicious URLs In Phishing Emails: Hover, Click and Inspect Again
The most often recommended piece of anti-phishing advice is for all users to “hover” over a URL link before clicking on it. It is great advice.
Senior Executives Beware: The Rise of EvilProxy Phishing Campaigns
Menlo Security warns that a social engineering campaign is using the EvilProxy phishing kit to target senior executives across a range of industries, including banking and financial services, insurance, property management and real estate, and manufacturing.
Open-Source Intelligence (OSINT): Learn the Methods Bad Actors Use to Hack Your Organization
They are out there, watching and waiting for an opportunity to strike; the bad actors who have carefully researched your organization in order to set the perfect trap using easily found public resources. Open-Source Intelligence (OSINT) can provide cybercriminals everything … Read More
[Cybersecurity Awareness Month] Spoofy Steve’s Business Email Compromise Scams You Need to Watch Out For
Like a ghost, most business email compromise (BEC) scams are able to sneak through most technical defenses and end up in end-user inboxes.
Generative AI and the Automation of Social Engineering Increasingly Used By Threat Actors
Threat actors continue to use generative AI tools to craft convincing social engineering attacks, according to Glory Kaburu at Cryptopolitan.
CyberheistNews Vol 13 #40 Why BJ Fogg and Daniel Kahneman Are Big Security Pro Must-Knows
[HEADS UP] Aurora Police Department Warns of Contactless Payment Processors Scams
If you didn’t trust contactless payment processors before, you really won’t after hearing about this recent scam.
Lazarus Attack on Spanish Aerospace Company Started with Messages from Phony Meta Recruiters
A recent attack on an undisclosed Spanish aerospace company all started with messages to the company’s employees that appeared to be coming from Meta recruiters, via LinkedIn Messaging. ESET researchers uncovered the attack and attributed it to the Lazarus group, … Read More
New SMS Phishing Campaign Impersonating The US Postal Service
DomainTools is tracking an increase in SMS phishing (or “smishing”) campaigns impersonating the US Postal Service (USPS). The text messages inform recipients that there’s a problem with their delivery address and they need to click on a link to resolve … Read More