December 9

WEBINAR TAKEAWAY: When the Bad Guys Hide in Plain Sight: Hacking Platforms You Know and Trust



  • already 20 years ago, Kevin Mitnick testified before US Senate and highlighted social engineering and the need for training. Still today changing human behaviour is most times the weakest point.
  • threat actors have almost unlimited time to do extensive research before an attack, so they are extremly good at buidling the trust factor
  • Kevin recommends: trust your gut! If it sounds too good to be true, it possibly is.
  • A crafty attacker tries to push the victim into system 1 thinking. To force yourself to remain in system 2, is a very effective defense mechanism against social engineering.
  • While Trump was in hospital with COVID19, it created an information vaccum = working phish bait
  • Common phishing tactic: link to trusted sources like Google Docs or O365. Document might contain hyperlink to malware.
  • Having a good and tested(!) desaster recovery plan is cruicial with more and more ransomware attacks

Demo time

  • Demo of a bad USB cable attack
  • Demo a lot of phishing mail examples and red flags
  • Demo of CVE-2020-1472 "zerologon " :fearful:



awareness training, phishing, social engineering

You may also like

Ethical considerations in phishing tests: to inform employees or not?

TL;DR This article delves into the ethical considerations in phishing tests, highlighting the balance needed between conducting realistic simulations and maintaining fairness in cybersecurity training. This article explores the complexities of conducting phishing simulations in the workplace. Key takeaways include the importance of transparency in fostering a positive security culture, building trust through clear communication,

Read More

Summary of a LinkedIn Post Series: Ideas and Insights for Effective Security Awareness in Cybersecurity Awareness Month

Introduction Welcome to a summary overview of my LinkedIn posts published during the Cybersecurity Awareness Month in October 2023. Throughout this month, I delved deeply into the topic of security awareness, sharing valuable insights and strategies to enhance awareness in businesses. This article summarizes the key aspects of my discussions and highlights the importance of

Read More