Uploaded August 2019 | Updated September 2026, 1 week ago
Cybercriminals don't always use complicated technical attacks to get around your cybersecurity. Sometimes—probably more often than we care to admit—it's the really simple stuff that works and what's simpler than an email?
Business email compromise is a social engineer technique that raked in over a $1B in the US alone last year. In this scam, the criminals leverage fake business pressures to circumvent normal financial processes.
It's simple and it works.
References;
- a business in North Battleford, Saskatchewan lost $1.4 M in this type of scam, cbc.ca/news/canada/saskatoon/spence-equipment-fraud-sask-1.5256322
- the Ontario Provincial Police warn of an increase in "CEO email scams" province wide, ottawacitizen.com/news/local-news/police-warn-of-ceo-email-scams#click=https://t.co/OYhpIrCS33
- financial reporting on the scam in the US, cyberscoop.com/business-email-compromise-bec-fincen-report-2019
- basic attack facts from Trend Micro, trendmicro.com/vinfo/us/security/definition/business-email-compromise-(bec)
Cybercriminals don't always use complicated technical attacks to get around your cybersecurity. Sometimes—probably more often than we care to admit—it's the really simple stuff that works and what's simpler than an email?
Business email compromise is a social engineer technique that raked in over a $1B in the US alone last year. In this scam, the criminals leverage fake business pressures to circumvent normal financial processes.
It's simple and it works.
References;
- a business in North Battleford, Saskatchewan lost $1.4 M in this type of scam, cbc.ca/news/canada/saskatoon/spence-equipment-fraud-sask-1.5256322
- the Ontario Provincial Police warn of an increase in "CEO email scams" province wide, ottawacitizen.com/news/local-news/police-warn-of-ceo-email-scams#click=https://t.co/OYhpIrCS33
- financial reporting on the scam in the US, cyberscoop.com/business-email-compromise-bec-fincen-report-2019
- basic attack facts from Trend Micro, trendmicro.com/vinfo/us/security/definition/business-email-compromise-(bec)
![Have You Been Bugged by an Apple Device? #shorts
Is someone using an Apple device to track your whereabouts? Not usually the realm of hackers, more likely a relationship turned dark or an operational security issue, an upcoming iOS feature looks to put a stop to this.
Learn more about it in this short...
Index:
- The question [0:00]
- Item Safety Alert [0:06]
- Find My [0:29]
#shorts Have You Been Bugged by an Apple Device? #shorts](https://i.ytimg.com/vi/YpzMi3sN6bc/mqdefault.jpg)
![What AWS re:Inforce 2021 Means for Cloud Security…and Cybersecurity in General
AWS re:Inforce is AWS major security focused event. The 2021 edition was entirely virtual and the shortened program focused on five main areas. Across those sessions and in the keynote, the team was painting a bigger picture.
They were showing—again—how AWS treats security internally. Its a fascinating look, not at the technical aspects of security, but at how a security practice should be setup organizationally and the tenets that drive it.
This is not only how cloud security practices should be setup, but ALL security practices.
Index:
- [00:00] Traditional security teams
- [00:32] AWS re:Inforce 2021
- [01:37] Since 2017...
- [02:36] Distributed knowledge
- [03:45] One simple truth
- [04:18] Some centralization
- [05:14] A practice explained What AWS re:Inforce 2021 Means for Cloud Security…and Cybersecurity in General](https://i.ytimg.com/vi/Z2zO-goGqUI/mqdefault.jpg)



![Microsoft Windows PrinterNightmare Patch Highlight “Unperfect” Security Decisions #shorts
The PrinterNightmare vulnerability was patched out-of-band (on an emergency basis) but the patch doesnt completely address the issue.
Hackers can still easily use this to run their code on your systems if youre using a feature called Point and Print (and a lot of people are). Where does that leave defenders?
More in this short...
References:
- Brian Krebs has a post on the out-of-band patch; Microsoft Issues Emergency Patch for Windows Flaw, https://krebsonsecurity.com/2021/07/microsoft-issues-emergency-patch-for-windows-flaw/
- From BleepingComputer, Microsofts incomplete PrintNightmare patch fails to fix vulnerability, https://www.bleepingcomputer.com/news/microsoft/microsofts-incomplete-printnightmare-patch-fails-to-fix-vulnerability/
- Security Update Guide from the Microsoft Security Response Center, https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527
- Introduction to Point and Print - Windows drivers from the Microsoft docs, https://docs.microsoft.com/en-us/windows-hardware/drivers/print/introduction-to-point-and-print
Index:
- [0:00] The vulnerability
- [0:17] Point and Print
- [0:29] Make a choice
#shorts Microsoft Windows PrinterNightmare Patch Highlight “Unperfect” Security Decisions #shorts](https://i.ytimg.com/vi/ZmmoIMYMlVQ/mqdefault.jpg)
![Nation State Hackers Are Targeting Email Servers, Is It Time To Panic? #shorts
Microsoft warned that a nation state actor called HAFNIUM is actively targeting users of its Microsoft Exchange email server. Thankfully there are patches out for the four issues involved.
Problem solved, right?
Maybe not. We explore in this short...
Index;
- The question [0:00]
- Microsoft Exchange issue [0:05]
- Just patch [0:16]
#shorts Nation State Hackers Are Targeting Email Servers, Is It Time To Panic? #shorts](https://i.ytimg.com/vi/_jlM33jHwdY/mqdefault.jpg)
![Microsoft Edge Experiment “Super Duper Secure Mode” Aims To Reduce Openings for Hackers #shorts
The Microsoft Edge browser team is conducting an experiment in an attempt to increase the cybersecurity of the browser and how it handles javascript. At stake? One of the major performance features.
Learn more in this short...
References:
- coverage from TheRecord, Microsoft announces new Super Duper Secure Mode for Edge
, https://therecord.media/microsoft-announces-new-super-duper-secure-mode-for-edge/
- the research note from the team, Super Duper Secure Mode, https://microsoftedge.github.io/edgevr/posts/Super-Duper-Secure-Mode/
- more on the V8 (JavaScript engine) from Wikipedia, https://en.wikipedia.org/wiki/V8_(JavaScript_engine)
Index:
- [0:00] The experiment
- [0:12] Why?
- [0:33] Computing platform
#shorts Microsoft Edge Experiment “Super Duper Secure Mode” Aims To Reduce Openings for Hackers #shorts](https://i.ytimg.com/vi/_xppPCiTaRM/mqdefault.jpg)
![Update Your iPhone Now (iOS 14.4.1) #shorts
Apple has issued an out-of-band or unexpected update to iOS (and macOS) to address a cybersecurity issue.
No need to panic but it is time to update before hackers take advantage.
This short shows you how...
Index:
- The update [0:00]
- Details [0:06]
- How to update [0:08]
#shorts Update Your iPhone Now (iOS 14.4.1) #shorts](https://i.ytimg.com/vi/a1qrg2D67GM/mqdefault.jpg)
![REvil-ed Ransomware Group Goes Kaput? #shorts
REvil has been one of the top ransomware groups for the past few months but theyre suddenly offline. No note, no warning, just gone.
More in this short...
References:
- Tweet from Lawrence Abrams, https://twitter.com/LawrenceAbrams/status/1414929050729074714?s=20
- Kevin Beaumont on the issue, https://twitter.com/GossiTheDog/status/1414947622633279493?s=20
- Coverage from the NY Times, https://www.nytimes.com/2021/07/13/us/politics/russia-hacking-ransomware-revil.html
- Bank Info Security on the list of Kaseya victims, https://www.bankinfosecurity.com/list-victims-kaseya-ransomware-attack-grows-a-17013
- The Avaddon shutdown where keys were made available, https://www.bleepingcomputer.com/news/security/avaddon-ransomware-shuts-down-and-releases-decryption-keys/
Index:
- [0:00] ⏰
- [0:09] Gone for good?
- [0:17] Keys
- [0:29] Why?
- [0:43] 🔦
#shorts REvil-ed Ransomware Group Goes Kaput? #shorts](https://i.ytimg.com/vi/aYbeyNKCALk/mqdefault.jpg)
