In a shocking turn of events, an unnamed company based in the UK has fallen victim to a sophisticated cyber attack after inadvertently hiring a North Korean hacker as a remote IT worker.
Monthly Archives: October 2024
Phishing Attacks Are Abusing Legitimate Services to Avoid Detection
Microsoft warns that threat actors are abusing legitimate file-hosting services to launch phishing attacks. These attacks are more likely to bypass security filters and appear more convincing to employees who frequently use these services.
AI-Enhanced Cyber Attacks Top the List of Potential Threats Facing Data Security
AI is quickly becoming the basis for more cyber attacks, leading organizations to realize the risk it presents. A new report now shows that AI-enhanced cyber attacks are now the top concern of security leaders.
The Number of Malicious Emails Reaching Inboxes Is Declining
New research shows that less malicious emails are getting past security scanners to the inbox, but also provides details about how phishing emails are becoming increasingly dangerous.
Chinese Threat Actor Targets OpenAI With Spear-Phishing Attacks
OpenAI has disclosed that its employees were targeted by spear-phishing attacks launched by a suspected Chinese state-sponsored threat actor.
KnowBe4 Named a Leader in the Fall 2024 G2 Grid Report for Security Orchestration, Automation, and Response (SOAR) Software
We are excited to announce that KnowBe4 has been named a leader in the Fall 2024 G2 Grid Report for Security Orchestration, Automation, and Response (SOAR) for the PhishER platform for the 14th consecutive quarter!
North Korean Hackers Continue to Target Job Seekers
A North Korean threat actor is launching social engineering attacks against job seekers in the tech industry, according to researchers at Palo Alto Networks’ Unit 42.
44% of U.S. Organizations Experienced One or More Ransomware Attacks in the Last Year
As ransomware becomes more pervasive, new data provides insight into how well organizations are responding and the attack vector being used most.
What Spending 3 Hours in IKEA Taught Me About Cybersecurity Awareness
It was a Saturday morning, and I had grand plans. By “grand plans,” I mean sitting on the sofa, watching reruns of “The IT Crowd,” and pretending I didn’t hear the lawn mower calling my name.
KnowBe4 Named a Leader in the Fall 2024 G2 Grid Report for Security Awareness Training
We are thrilled to announce that KnowBe4 has been named a leader in the latest G2 Grid Report that compares security awareness training (SAT) vendors based on user reviews, customer satisfaction, popularity and market presence.
CyberheistNews Vol 14 #42 [Heads Up] Majority of U.S. Execs Now Rank Cyber Threats as #1 Risk
Meet SmartRisk Agent™: Unlock Your New Human Risk Management
Depending on who you ask, between 70 and 90 percent of cyber risk has human error as the root cause. That’s why Human Risk Management (HRM) is so important. And here is the next major advance in HRM. We’re thrilled … Read More
Sextortion Scammers Attempt to Hit “Close to Home”
We live in a world where, despite the sharing of information online, we feel like those interactions will never reach home. But a new scam – covered on WTSP Tampa Bay’s Channel 10 news – demonstrates how scammers will use personal details … Read More
“Operation Kaerb” Takes Down Sophisticated Phishing-as-a-Service Platform “iServer”
A partnering of European and Latin American law enforcement agencies took down the group behind the mobile phone credential theft of 483,000 victims.
Google App Scripts Become the Latest Way to Establish Credibility and Automate Phishing Attacks
Cybercriminals have found a new way of leveraging legitimate web services for malicious purposes, this time with the benefit of added automation of campaign actions.
Trinity Ransomware Targets the Healthcare Sector
The Trinity ransomware gang is launching double-extortion attacks against organizations in the healthcare sector, according to an advisory from the US Department of Health and Human Services (HHS). The ransomware gains initial access via phishing emails or software vulnerabilities.
Hurricane Deepfakes Flood Social Media
As the recent hurricane Helene caused major damage and as hurricane Milton is expected to make landfall in Florida soon, deepfakes are spreading misinformation on social media.
[Cybersecurity Awareness Month] Keeping Your Mobile Devices Secure from the ‘Inside’ Out
As remote work and connecting while traveling has become the norm, mobile device security responsibilities have also increased.
Attackers Abuse URL Rewriting to Evade Security Filters
Attackers continue to exploit URL rewriting to hide their phishing links from email security filters, according to researchers at Abnormal Security.