Read articles about security awareness, risk management, behavior change, and more
How quishing is being used in attacks, what these threats look like in the wild and best practices for avoiding them.
Phishing is a cybercrime where attackers want to lure information from you. Learn about the most common phishing schemes and attacks and how to detect it.
Learn how to recognize even the most advanced phishing attacks, and avoid exposing your own or your company's sensitive information.
Let's learn about OSINT gathering and discover how information can be exploited by the 'bad guys' to gain access to the corporate information system.
Security awareness training is often half-hearted and inefficient – but it doesn’t have to be. Here's our key points on making it work
Learn what spear-phishing is, how it works, and how it's different from regular phishing. Read how you can recognize spear-phishing attacks?
We train our users to always hover over links in emails and to validate the domain where the links points to. This can’t be trusted if you are using Microsoft Edge to view your emails in Office 365.
This article focuses on how cybersecurity awareness training helps entities achieve and maintain ISO/IEC 27001 compliance under ongoing audits
This guide to the DoD Phishing Awareness Challenge gives 9 key takeaways from the training to help determine if it’s right for you and your organization
Positive phishing awareness training lowers data breach risk and builds cybersecurity culture; CISOs are moving on from traditional punitive models.
Phishing training can be an effective tool in building a human firewall to shield your company from phishing attacks targeting employees.
When your password is not long and complicated enough, attackers can easily hack it. See what methods they use and how you can protect yourself.
To make sure that your employees are willingly participating in your phishing training, you need to communicate to them why they should do it.
This NIS 2 Checklist gives the compliance basics for the CxO and Board of Directors to satisfy this European cybersecurity regulation.
The top 10 costs of phishing are direct, indirect, and far reaching.
Noora Ahmed-Moshe's presentation to an exclusive group of CIOs at Kocho View in London explains why building a security culture is vital to reducing human risk.
How to measure and drive behavior change that shields your organization from cyber-attacks.
In the world of cybersecurity, the unknown represents your biggest risk. A miss today is a phish tomorrow.
Cybersecurity awareness training has become crucial to getting cyber insurance and lowering premiums in 2021. That trend will continue to grow.
Empower your team to be a human firewall. Discover how training, vigilance, and smart habits protect against cyber threats.
Here's how integrating Yu-kai Chou's Octalysis Gamification and Behavioral Design Framework into cybersecurity training can dramatically improve user engagement and resilience.
Wondering which attack simulation training is best for your team? Get a full breakdown of Hoxhunt vs. Microsoft Defender to make an informed decision.
Maxime Cartier recaps the webinar series, "The Human Element: The Science Behind Influencing Security Behaviors" and key learnings of the intricacies of human behavior in reducing cybersecurity risk.
The differences between old school awareness training and modern security behavior change are revealed in measuring true risk managing human risk
Gamification helps the end user understand that their actions matter, and that every click they make can have an effect.
TikTok's open redirection vulnerability is being used in phishing emails. Here's what we know and how to prevent successful attacks.
Your ultimate guide to deepfake attacks to keep your organization safe. Includes video examples and case studies.
Looking for genuinely engaging Cybersecurity Awareness Month ideas? Here are some of the best ones we've collected over the years here at Hoxhunt.
Your guide to the kinds of threats out there, what to look out for and the measures you can take to prevent invoice fraud.
Here are the 10 major phishing red flags that your employees should already be aware of.
Your SaaS suite is leaving your backdoor open. Here's how to fix it.
Log4J Log4Shell vulnerability explained to help you understand what it is and how to stay protected
A security vulnerability was recently reported in the default guest permissions of Microsoft Azure Active Directory. Here’s how to fix it and stay safe from attackers.
This phishing email was sent from outside the organization but is replacing the Caution! External Sender banner with a safe sender banner.
Apple just recently confirmed the most significant vulnerability in iOS history after ZecOps made a public announcement about their discovery of a security flaw.
According to security researchers, the iOS mail app, which is the email client that can be found on most Apple iPhones and iPads, has a severe security flaw making it vulnerable to attacks.
Your ultimate guide to the process behind social engineering training and all of the tips and know-how you need to ensure your training successfully changes behavior.
From Spear-Phishing, to Credential Harvesting, To Possible Ad Fraud. Keep Reading To Find Out How This Story Unfolded and How You Can Avoid Getting Caught.
We're seeing an uptick in social engineers targeting social media accounts
Now that cookies are on their way out, a much sneakier way of identifying you is on its way in.
Years later, pop-ups are back, this time serving a different purpose... stealing your info.
The more digital money you make, the more digital problems you get. Here's some tips to keep your crypto wallet safe.