Src |
Date (GMT) |
Titre |
Description |
Tags |
Stories |
Notes |
|
2022-05-03 13:36:38 |
CyberheistNews Vol 12 #18 [Heads Up] The 4 Major Tactics: How Hackers Steal Your Passwords and How To Defend Yourself (lien direct) |
|
|
|
|
|
2022-05-03 12:48:59 |
Man Convicted for $23 Million Phishing Scam Against the US DoD (lien direct) |
A man in California has been convicted for stealing $23.5 million from the US Department of Defense in a phishing attack. The Justice Department explained in a press release that the man, Sercan Oyuntur, hijacked payments meant for a jet fuel supplier. |
|
|
|
|
2022-05-02 20:45:24 |
Holding a Great Employee Education Meeting (lien direct) |
I recently attended a customer's annual security awareness training employee event. I have attended a bunch of these over the years and I have loved them all. But this particular customer threw a great one! It included everything I think a security awareness training employee event should have. |
|
|
|
|
2022-05-02 12:52:18 |
Phishing Campaign Uses Simple Email Templates (lien direct) |
A phishing campaign is using short, terse emails to trick people into visiting a credential-harvesting site, according to Paul Ducklin at Naked Security. The email informs recipients that two incoming messages were returned to the sender, and directs the user to visit a link in order to view the messages. Since the emails are so short, the scammers avoid risking typos or grammatical errors that could have tipped off the recipient. |
|
|
|
|
2022-04-28 22:05:02 |
75% of SMBs Would Only Survive Seven Days or less from a Ransomware Attack (lien direct) |
With ransomware attacks on the increase, new data shows a material portion of small and medium business organizations are completely ill-equipped to address an attack. |
Ransomware
|
|
|
|
2022-04-28 22:04:48 |
Half of IT Leaders Say their Non-Technical Staff are Unprepared for a Cyber Attack (lien direct) |
New data shows IT leadership believes users outside of IT create a “continued significant risk to organizations” despite having a layered security strategy to prevent attacks. |
Guideline
|
|
|
|
2022-04-28 19:25:08 |
[EYE OPENER] The Ransom Payment is Only 15% of The Total Cost of Ransomware Attacks (lien direct) |
As the number of ransomware attacks has increased 24% over the previous year, security researchers estimate the total associated attack costs to be just over 7 times higher. |
Ransomware
|
|
|
|
2022-04-28 12:41:31 |
Criminal Gang Impersonates Russian Government in Phishing Campaign (lien direct) |
Researchers at IBM Security X-Force are tracking a financially motivated cybercriminal group called “Hive0117” that's impersonating a Russian government agency to target users in Eastern Europe. |
|
|
|
|
2022-04-26 14:04:10 |
CyberheistNews Vol 12 #17 [EYE OPENER] "Being Annoying" as a Social Engineering Tactic (lien direct) |
|
|
|
|
|
2022-04-26 13:54:16 |
How Hackers Get Your Passwords and How To Defend Yourself (lien direct) |
Despite the world's best efforts to get everyone off passwords and onto something else (e.g., MFA, passwordless authentication, biometrics, zero trust, etc.) for decades, passwords have pervasively persisted. Today, nearly everyone has multiple forms of MFA for different applications and websites AND many, many passwords. |
|
|
|
|
2022-04-26 13:53:55 |
Hacking the Hacker: An Inside Look at the Karakurt Cyber Extortion Group (lien direct) |
By breaking into an attack server, security researchers have uncovered new details that show the connection between the Karakurt group and Conti ransomware. |
|
|
|
|
2022-04-26 13:53:38 |
Nearly all Data Breaches in Q1 2022 Were the Result of a Cyber Attack (lien direct) |
New data from the Identity Theft Resource Center shows rises in the number of data compromises following 2021's record-setting year, all stemming from cyber attacks. |
|
|
|
|
2022-04-26 13:53:19 |
Cyber Attacks on the Global Supply Chain Have Increased by 51% (lien direct) |
As supply chain vendors become a greater target, the businesses reliant upon them don't seem to be responding with the appropriate urgency, according to new data. |
|
|
|
|
2022-04-26 12:49:59 |
More_eggs Malware Distributed Via Spear Phishing (lien direct) |
Threat actors are sending out the stealthy “more_eggs” malware in spear phishing emails that target hiring managers, according to researchers at eSentire's Threat Response Unit (TRU). |
Malware
Threat
|
|
|
|
2022-04-25 12:51:35 |
Community Associations Confront Social Engineering (lien direct) |
It's not just deep-pocketed corporations that prove attractive targets for social engineering. Any organization that holds information that can fetch a good price in the criminal marketplace will draw the attention of social engineers. |
|
|
|
|
2022-04-21 16:26:04 |
If You Got a “Your Bill Is Paid For” Text, You\'re Part of a Massive T-Mobile Texting Scam (lien direct) |
The latest scam targeting T-Mobile customers impersonating T-Mobile and focused on collecting your personal data by tempting you with free “gifts”. |
|
|
|
|
2022-04-21 16:25:45 |
LinkedIn is the Most Impersonated Brand in Phishing Attacks (lien direct) |
Social media companies, particularly LinkedIn, are now the most impersonated brands in phishing campaigns, researchers at Check Point have found. |
|
|
|
|
2022-04-21 15:46:04 |
New Phishing Attack Targets MetaMask Users for their Crypto Wallet Private Keys (lien direct) |
A new phishing campaign impersonates MetaMask, informs victims their cryptocurrency wallets aren't “verified” and threatens suspension. |
|
|
|
|
2022-04-21 15:45:27 |
UK Information Commissioner: Many Cybersecurity Incidents are “Preventable” (lien direct) |
In a recent article about the largest cyberthreats currently facing the UK, John Edwards – the UK's newly-appointed information commissioner- talks about the need for a security culture in the workplace. |
|
|
|
|
2022-04-21 14:14:00 |
Critical: CISA Warns of Potential Attacks on Infrastructure by Russian State-Sponsored and Criminal Cyber Gangs (lien direct) |
In a joint multi-country cybersecurity advisory (CSA), governments are warning their respective critical infrastructure organizations to be vigilant against increased malicious cyber threat activity. |
Threat
|
|
|
|
2022-04-20 12:49:57 |
TraderTraitor: When States do Social Engineering (lien direct) |
North Korea's Lazarus Group is using social engineering attacks to target users of cryptocurrency, according to a joint advisory from the US FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and the US Treasury Department. |
Medical
|
APT 38
APT 28
|
|
|
2022-04-19 14:33:27 |
Ransomware Attacks Show Temporary Slowing but are Expected to Increase in 2022 [Graphs] (lien direct) |
New data from Recorded Future shows how the war in Ukraine is causing a brief slowdown of ransomware attacks on healthcare, governments and schools that is predicted to return to growing levels. |
|
|
★★★
|
|
2022-04-19 14:31:40 |
Only Half of All Organizations Have Refreshed Their Security Strategy Based on the Pandemic (lien direct) |
A new study published by Ponemon Institute shows that a material portion of organizations are still using pre-pandemic security processes and policies, putting the org at risk. |
|
|
★★★
|
|
2022-04-19 14:31:22 |
FBI Warns of Bank Fraud Phishing Campaign (lien direct) |
The FBI has warned of a smishing campaign that's targeting people in the US with phony bank fraud notifications. The text messages inform users that someone has attempted to initiate a money transfer on their account. |
|
|
★★★
|
|
2022-04-19 13:57:22 |
CyberheistNews Vol 12 #16 [Eye Opener] The Costliest Cybercrime: Business Email Compromise (BEC) (lien direct) |
|
|
|
|
|
2022-04-18 13:40:04 |
Social Engineering Campaign against African Banks (lien direct) |
A phishing campaign is targeting African banks with a technique called “HTML smuggling” to bypass security filters, according to threat researchers at HP. |
|
|
|
|
2022-04-18 12:42:15 |
“Being Annoying” as a Social Engineering Approach (lien direct) |
Attackers are spamming multifactor authentication (MFA) prompts in an attempt to irritate users into approving the login, Ars Technica reports. Both criminal and nation-state actors are using this technique. Researchers at Mandiant observed the Russian state-sponsored actor Cozy Bear launching repeated MFA prompts until the user accepted the request. |
|
APT 29
APT 29
|
|
|
2022-04-15 14:49:24 |
Q1 2022 Report: Holiday-Themed Phishing Emails Get Employees to Click (lien direct) |
KnowBe4's latest quarterly report on top-clicked phishing email subjects is here. We analyze the top categories, general subjects (in both the United States and globally), and 'in the wild' attacks. |
|
|
|
|
2022-04-15 14:00:00 |
Storytelling to Improve Your Organization\'s Security Culture [PODCAST] (lien direct) |
The latest podcast episode of Security Masterminds features our special guest Jim Shields, Creative Director at KnowBe4. He sat down with our hosts, Erich Kron and Jelle Wieringa to discuss storytelling to improve an organization's security culture. |
|
|
|
|
2022-04-14 15:38:26 |
Reduce Your Chances of Getting Scammed (lien direct) |
In today's connected world, nearly everyone has a story where they have been targeted by a scam and either that person or someone they know have lost money to scams. |
|
|
|
|
2022-04-14 15:35:04 |
Strategies to Achieve Compliance and Real Risk Reduction at the Same Time (lien direct) |
Organizations like yours use regulatory guides and compliance frameworks as the foundation of their list of controls. You can easily have many hundreds to thousands of controls to create and manage. |
|
|
|
|
2022-04-13 20:44:27 |
Small and Medium Businesses Account for Nearly Half of all Ransomware Victim Organizations (lien direct) |
As ransomware costs increase, along with the effectiveness and use of extortions, smaller businesses are paying the price, according to new data from Webroot. |
Ransomware
|
|
|
|
2022-04-13 20:43:29 |
One in Three U.K. Businesses Experience Cyber Attacks Weekly (lien direct) |
New data from the U.K. Government's Cyber Security Breaches Survey 2022 report shows that a material portion of businesses and charities are being attacked and feeling the repercussions. |
|
|
|
|
2022-04-13 20:43:06 |
Meta Stops Three Cyber Espionage Groups Targeting Critical Industries (lien direct) |
Impersonating legitimate companies and using a complex mix of fake personas across Facebook, Telegram, and other platforms, these groups used social engineering to gain network access. |
|
|
|
|
2022-04-13 13:54:14 |
Smishing Scams Abuse Name of Legitimate Ukrainian Charity (lien direct) |
Researchers at Trend Micro have spotted yet another scam taking advantage of the crisis in Ukraine by impersonating a legitimate charity. In this case, the scammers are posing as the relief organization Mercury One, attempting to steal money and personal information. We wrote about a "Help Ukraine" cryptocurrency scam and a Ukranian charity phishing scam last month, this is just the latest variety. |
|
|
|
|
2022-04-12 13:31:43 |
(Déjà vu) CyberheistNews Vol 12 #15 [Heads Up] Hard-boiled Social Engineering by a Fake "Emergency Data Request" (lien direct) |
|
|
|
|
|
2022-04-12 12:52:35 |
Business Email Compromise (BEC): the Costliest Cybercrime (lien direct) |
Organizations in the US lost $2.4 billion to business email compromise (BEC) scams (also known as CEO fraud) last year, according to Alan Suderman at Fortune. |
|
|
|
|
2022-04-11 19:15:00 |
Microsoft Azure\'s Static Web Apps Service Becomes the New Home for Phishing Attacks (lien direct) |
Taking advantage of the value of a legitimate web service, along with a valid SSL certificate, a new campaign of phishing attack targeting online Microsoft credentials is leveraging Azure. |
|
|
|
|
2022-04-11 12:00:00 |
(Déjà vu) KnowBe4 Named a Leader in the Spring 2022 G2 Grid Report for Security Awareness Training (lien direct) |
We are thrilled to announce that KnowBe4 has been named a leader in the latest G2 Grid Report that compares Security Awareness Training (SAT) vendors based on user reviews, customer satisfaction, popularity and market presence. |
Guideline
|
|
|
|
2022-04-08 13:06:44 |
(Déjà vu) KnowBe4\'s PhishER Platform Named a Leader in the Spring 2022 G2 Grid Report for Security Orchestration, Automation, and Response (SOAR) (lien direct) |
We are excited to announce that KnowBe4 has been named a leader in the Spring 2022 G2 Grid Report for Security Orchestration, Automation, and Response (SOAR) for the fourth consecutive quarter! |
Guideline
|
|
|
|
2022-04-08 12:30:51 |
The Ransomware Hostage Rescue Checklist: Your Step-by-Step Guide to Preventing and Surviving an Ransomware Attack (lien direct) |
Skyrocketing attack rates, double and triple extortion, increasing ransom demands… cybercriminals are inflicting pain in every way imaginable when it comes to today's ransomware attacks. And you need to be prepared to protect your network, NOW. |
Ransomware
|
|
|
|
2022-04-07 12:52:18 |
Phishbait Invokes Russia\'s Ministry of Internal Affairs (Road Safety Division) (lien direct) |
A phishing campaign impersonating WhatsApp has targeted more than 27,000 mailboxes, according to researchers at Armorblox. It's not clear who the attackers were, but they used an old version of a road safety operations website belonging to Russia's Ministry of Internal Affairs, which helped the emails to bypass authentication checks. |
|
|
|
|
2022-04-07 12:28:50 |
“Human Error” Ranked as the Top Cybersecurity Threat While Budgets Remain Misaligned (lien direct) |
New insights into the state of data security show a clear focus on the weakest part of your security stance – your users – and organizations doing little to address it. |
Threat
|
|
|
|
2022-04-07 12:28:16 |
Multi-Million Dollar Scam Call Center Shut Down by Multinational Police Efforts (lien direct) |
Last month, Latvian and Lithuanian police – in conjunction with Europol – coordinated a raid on 3 call centers responsible for an international effort to defraud victims worldwide. |
|
|
|
|
2022-04-06 13:32:36 |
Mailchimp Phishing Attack Results in Potential Hit on 100K Trezor Crypto Wallets (lien direct) |
Stolen client data from Mailchimp put customers of the cryptocurrency hardware wallets on notice of potential social engineering attacks claiming to be Trezor. |
|
|
|
|
2022-04-06 12:55:09 |
“Europol Calling” (Not Necessarily) (lien direct) |
Scammers are impersonating Europol with fraudulent phone calls in an attempt to steal personal and financial information, according to Kristina Ohr at Avast. The German Federal Criminal Police Office (Bundeskriminalamt, BKA) recently warned of this campaign as well. |
|
|
|
|
2022-04-05 18:38:15 |
Microsoft Warns of Lapsus$ “Targeting Organizations for Data Exfiltration and Destruction” (lien direct) |
The group behind the recent attacks on Okta, NVIDIA, and Microsoft may be moving on to less-prominent organizations, using their data destruction extortion model on new victims. |
|
|
|
|
2022-04-05 18:37:54 |
Info Stealer Malware Vidar Uses Microsoft Help Files to Launch Attacks (lien direct) |
It appears that the use of Microsoft CHM files is gaining popularity, and from the way this latest attack works, it's a rather ingenious and flexible method that could become more prevalent. |
Malware
|
|
|
|
2022-04-05 18:36:44 |
Ransomware Victims See Ransom Demands and Payments Increase as The Number of Published Data Victims Spikes (lien direct) |
Cybercriminals Groups and “as a Service” threat actor affiliates alike seem to be doing well, according to a new report on the state of ransomware from Palo Alto Networks' Unit42. |
Threat
|
|
|
|
2022-04-05 18:35:39 |
Social Engineering from Tehran (lien direct) |
Social engineering continues to be a core component of the Iranian government's hacking operations, according to researchers at Recorded Future. |
|
|
|