Tag Archives: social engineering

Ring! Ring! Yes, This is the I.R.S! NOT!

Criminals have been calling taxpayers and insisting they must “immediately give up their personal information or make a payment,” Don’t fall for it! It’s a scam! The I.R.S. will never call as their method is to send old fashioned mail. … Continue reading

Posted in Security Blog | Tagged , , , , , , , , , | Comments Off on Ring! Ring! Yes, This is the I.R.S! NOT!

Vawtrack Trojan Capabilities

Vawtrak is a banking Trojan that has been spreading in recent months. It infects victims via malware downloaders, exploit kits, or through drive-by downloads (e.g. spam email attachments or links). AVG has a white paper (pdf) full of details. Vawtrak … Continue reading

Posted in Security Blog | Tagged , , , , , , | Comments Off on Vawtrack Trojan Capabilities

Fake Error Message, SSL Cert Invalid

Bad guys are putting up fake error messages with hopes that victims will call them for help. Don’t fall for it!

Posted in Security Blog | Tagged , , , , | Comments Off on Fake Error Message, SSL Cert Invalid

Billion Dollar Bank Hack

Multiple banks to be exact, over the last two years, by an unknown but very organized group. The bank’s internal computers, used by employees who process daily transfers and conduct bookkeeping, had been penetrated by malware, through social engineering/phishing attacks, … Continue reading

Posted in Security Blog | Tagged , , , , , | Comments Off on Billion Dollar Bank Hack

SpearPhishing in Omaha Tricked a Financial Controller to send $17.2 Million to China

The FBI was brought in to investigate The Scoular Company after the controller wired $17.2 million dollars to China through their accounting firm, KPMG. There were emails to the controller from an email address that resembled but was not the … Continue reading

Posted in Security Blog | Tagged , , , , , , , , | Comments Off on SpearPhishing in Omaha Tricked a Financial Controller to send $17.2 Million to China

Phishing Anthem

Since my original posting about the Anthem Health Insurance Breach… Investigators believe the cyber crooks compromised the logins from 5 different tech workers, possibly through a phishing scheme that could have tricked them into unknowingly revealing a password or downloading … Continue reading

Posted in Security Blog | Tagged , , , , , , , | Comments Off on Phishing Anthem

LinkedIn Phishing

There has been a lot of phishing emails claiming to be from LinkedIn Support, designed to fool recipients into giving up their login credentials. The email uses a lowercase I instead of a capital i when spelling ‘Linkedln’ I promote … Continue reading

Posted in Security Blog | Tagged , , , , , , | Comments Off on LinkedIn Phishing

Stuart Varney, Fox Host, Gets Demo-Hacked By John McAfee

This was in the news yesterday, it is proof that social engineering is the master key to unlock many locks. It is also proof that to keep your lock secured, security awareness and training is needed with the end goal … Continue reading

Posted in Security Blog | Tagged , , , , , , , , , , , | Comments Off on Stuart Varney, Fox Host, Gets Demo-Hacked By John McAfee

An Intro To Recon-ng Pushpin

Recon-ng is a full-featured Web Reconnaissance framework written in Python. Complete with independent modules, database interaction, built in convenience functions, interactive help, and command completion, Recon-ng provides a powerful environment in which open source web-based reconnaissance can be conducted quickly … Continue reading

Posted in Security Blog | Tagged , , , , , | Comments Off on An Intro To Recon-ng Pushpin

Harvesting Birthdays

When participating in social media, there are all sorts of fun things to be part of, like “Who would be in your Zombie Apocalypse team?”. Though it’s fun, it’s also easy to give up your personal information. Why the heck … Continue reading

Posted in Security Blog | Tagged , , , , , , | Comments Off on Harvesting Birthdays