Are you Hiring? Resume Malware Trying to Get to You!

SCMagazine has the story “Hiring? New scam campaign means ‘resume’ downloads may contain malware” “Requiring the victim to copy and paste the malicious domain name increases the likelihood the emails will make it past secure email gateways. Plus, with unassuming domain names like “wlynch[.]com” for a candidate named William Lynch and “annetterawlings[.]com” for a candidate … Read more

How to Defend Against AI Spam Email?

So have you been assuming all spam to have spelling mistakes? Or just bad grammar? What if the email has impeccable grammar? How to defend against the bad guys using AI in their spam emails? NIST (National Institute of Science and Technology) has a definition of phishing:  https://csrc.nist.gov/glossary/term/phishing Phishing Definition: ”  A technique for attempting … Read more

Cybersecurity Practitioners Must Get More Boring?

DanielMiessler.com website Unsupervised Learning has a post SEC vs Solar Winds Cybersecurity’s Enron moment.     The problem is that Cybersecurity is still ‘magic’ to many people and it should not be. It has to be made into a boring endeavor which will make the defense of a company more likely. Making a company secure … Read more

How Fast to Disclose a Breach?

What are the rules (or regulations) that state how fast to disclose and where? SC Magazine has an article on the new rule by the SEC that says a public company should make a disclosure. SEC’s 4-day breach disclosure rule hits opposition in Congress One of the problems was that there was an attacker that … Read more

Phishing by Text Using Post Office Logo & Wording

fake post office text smish attack

I am receiving (just got another one) the following image text is the full size version: As you can see I got this text on Wednesday November 8th at 9:10 am the text says  “The USPS package has arrived at the warehouse and cannot be delivered due to incomplete address information.” Please confirm your address … Read more