Compass IT Compliance Blog / Social Engineering (8)

Microsoft Office Add-ins, Reason for Concern?

The outside of Microsoft headquarters

This question came into Compass IT Compliance from a client the other day: “How risky are 3rd party plugins? Should I be concerned about them?”. I had to stop and think about this for a while. In my years of working on vulnerability and penetration testing projects for Compass IT Comp …

Read Story

What You Can Do to Better Prepare Yourself for Holiday Scams

christmas-1911637_1920

It’s that time of the year again! With the holiday season upon us, many criminals will be attempting to scam people via phishing emails. This time of the year (Black Friday, Christmas) is the most lucrative for attackers due to the fact that stores are having a crazy amount of sales w …

Read Story

Guide to Improving Your Security Awareness Training

workshop-2209239_1920

For the past 3 years that I’ve worked at Compass IT Compliance, I’ve had the opportunity to travel the country and meet with various clients ranging from small businesses with less than 10 people to organizations with offices around the world. The main constant that I have noticed wit …

Read Story

Situational Awareness Starts with You!

agreement-2548138_1920

Having situational awareness can get you out of a lot of jams. Let me elaborate on what I mean by that. Have you ever received that annoying phone call from “Macrosoft Support”? This is known as a vishing attack. It’s the practice of eliciting information or attempting to influence ac …

Read Story

Spear Phishing: Targeted Attacks with Higher Success Rates

mohamed-ahzam-5rVQPPN7fNg-unsplash

Spear phishing is a deadly form of targeted social engineering. The main difference between spear phishing and traditional phishing is that spear phishing targets a certain user or users by using important facets of their life against them, while traditional phishing targets a broad g …

Read Story

Vishing – A Closer Look

mobile-605422_1920

Vishing, a shortened name for voice phishing, is the act of using a telephone to trick an individual into surrendering useful information to a fraudulent caller. Vishing is a form of social engineering, and as in most social engineering attempts, the attacker will create a false ident …

Read Story

Subscribe by email