News & Blog

Our stories.

A report in the Wall Street Journal on October 26th described incidences of election officials within the U.S. at the local level being sent suspicious emails which appear to be purposefully targeting them due to their position within their states.

A new post by the Microsoft security team warns about a new type of phishing attack vector targeting users. Consent Phishing, as they refer to it as, targets users by asking for an egregious amount of permissions from Single-Sign-On applications.

Instagram users should be on the lookout for fake copyright notices that have emerged as a new way to try and phish people into handing over the credentials of their accounts.

European users of Office 365 have been targeted with phishing emails sent from seemingly legitimate sources using hijacked Samsung's Adobe Campaign marketing redirect mechanism to send missed voicemail emails appearing to come from Oxford.

A new phishing campaign has been targeting people with a fake email claiming to vote anonymously about Black Lives Matter while it actually spreads the TrickBot information-stealing malware.

GitLab Employees Had a 59% Failure Rate in a Recent Phishing Test

59% of GitLab employees who were tested in a recent phishing campaign and clicked on a suspicious link failed by putting in credentials. Even highly tech focused companies such as GitLab have a severe failure rate that can have a significant impact.

User Credential Theft Prevention

Social engineering is the process of attacking the human, or employee, rather than the technology directly. Through social tactics, an employee is tricked into performing an action, such as installing malicious software or performing a transaction.

Anti-Phishing Security Control Checklist

This anti-phishing checklist outlines key controls that help to prevent phishing, improve phishing detection, and minimize the impact from phishing.

Verizon Data Breach Investigations Report (DBIR) - 2019

The Verizon Data Breach Investigations Report (DBIR) provides valuable information on the threats facing organizations today. The DBIR is produced by Verizon with a collaboration of many security entities.

Ten Steps to Creating a Phishing Awareness Campaign

The following slideshare, authors Christopher Hadnagy and Michele Fincher outline ten steps to creating a phishing awareness campaign for an organization. PhishingBox provides the tools needed to easily implement such a program.

Social Tactics Remain a Significant Threat

Social tactics includes phishing and other related social engineering activities. Basically, social tactics are methods used to penetrate an organization’s cybersecurity defenses by attacking the human.

What is the phishing failure rate by industry?

Employee security awareness should include phishing prevention training. This training should include phishing simulation. However, what is an expected phishing failure rate? The following article outlines phishing failure rates by industry.

Internet Security Threat Report (ISRT) - 2019

The Symantec Internet Security Threat Report (ISRT) for 2019 is continues to provide valuable information for the security professional. This annual security report provides key statistics that outline cybersecurity risks experienced by various orga

Presbyterian Healthcare Services Data Breach Impacts 183,000 Patients

New Mexico-based Presbyterian Healthcare Services is notifying approximately 183,000 patients and health plan members that some of their protected health information (PHI) has been exposed in a recent security breach.

Here’s how to make sure you’re safe after the Capital One hack

The personal information of about 100 million U.S. customers was compromised.

FTC Announces Major Crackdown on Vishing

The Federal Trade Commission and law enforcement plan to file charges against several companies and individuals as part of a major government clampdown on illegal robocalls.