For a more complete picture of employee cyber habits, organizations must creatively track user behaviors related to endpoint, web and data security as well. The data is there, said Living Security CSO Drew Rose at InfoSec World.
The growing usage of QR codes since the COVID-19 pandemic has resulted in cybercriminals abusing them for phishing campaigns and other schemes, says the BBB.
GDPR compliance and privacy concerns an issue as Russian-based ransomware group TA505 targets the financial sector in Europe, Asia and North America with its MirrorBlast phishing campaign.
At ISC2, the director of security program management of Duke Health shared recommendations for an effective phishing simulation and security awareness programs that center around positive enforcement.
In the U.S. alone, there were $6 billion in financial losses last year attributed just to account takeover, according to threat intelligence firm BioCatch.
A member of Google’s Threat Analysis Group confirmed that two Twitter accounts recently shut down were part of a North Korea-backed campaign targeting security researchers.
Financial organizations in the U.S., Canada, Europe, Hong Kong and other countries are being impacted by the novel MirrorBlast phishing campaign launched by Russia-linked threat group Evil Corp, or TA505, since early last month, a Morphisec report revealed in SecurityWeek.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.