

Hacking Humans
N2K Networks
Deception, influence, and social engineering in the world of cyber crime.
Episodes
Mentioned books

Feb 25, 2021 • 33min
How likely are online users to reveal private information?
Guest Professor Lior Fink from Ben Gurion University shares insights from their study on "How We Can Be Manipulated Into Sharing Private Information Online," Dave's story is some good news about a Nigerian man sentenced for phishing the US heavy equipment company Caterpillar, Joe has a story with bad news about a sextortion email scam with a fake Zoom zero day component, and our Catch of the Day is a compelling phishing email a listener named Michael recently received.Links to stories:
Nigerian man sentenced 10 years for $11 million phishing scam
Watch out for sextortion email scams
Have a Catch of the Day you'd like to share? Email it to us at hackinghumans@thecyberwire.com or hit us up on Twitter.

Feb 23, 2021 • 4min
taint analysis (noun) [Word Notes]
The process of software engineers checking the flow of user input in application code to determine if unanticipated input can affect program execution in malicious ways.

Feb 18, 2021 • 41min
Including your passwords in your final arrangements.
Guest Sara Teare who is known as 1Password's Minister of Magic talks with Dave about things that people don't consider like custody of the digital keys to your stuff online, Dave and Joe share some listener feedback from Jonathan about replacing outdated equipment (aka an old phone), Joe's story is about ongoing campaign targeting security researchers working on vulnerability research and development at different companies and organizations, Dave's story has a holiday theme: emails pretending to confirm orders from lingerie and flower shops that are actually spreading malware, and our Catch of the Day is from a listener named Kristian and it's a "legitimate deal" from Colonel Gaddafi's daughter.Links to stories:
New campaign targeting security researchers
Pre-Valentine’s Day Malware Attack Mimics Flower, Lingerie Stores
Have a Catch of the Day you'd like to share? Email it to us at hackinghumans@thecyberwire.com or hit us up on Twitter.

Feb 16, 2021 • 5min
ATM skimming (noun) [Word Notes]
The process of stealing ATM customer credentials by means of physically and covertly installing one or more devices onto a public ATM machine.

Feb 11, 2021 • 37min
In the disinformation and misinformation crosshairs.
Carole Theriault returns with a discussion on disinformation with guest, BBC host, podcaster and author Tim Harford, Dave's got a story about Covid vaccine phishing campaigns, Joe's story talks about data breaches that have increased 50% year over year since 2018, and our Catch of the Day is from a listener named John his wife saw on Facebook who translated it from Lithuanian.Links to stories:
Count Yourself in For a Vaccine Phish
Deep Analysis of More than 60,000 Breach Reports Over Three Years
Have a Catch of the Day you'd like to share? Email it to us at hackinghumans@thecyberwire.com or hit us up on Twitter.

Feb 9, 2021 • 5min
APT side hustle (noun) [Word Notes]
A nation-state hacking group’s practice of funding its town activities through cybercrime or cyber mercenary work.

Feb 4, 2021 • 40min
Understanding human behavior is a key to security.
Guest Nico Popp of Forcepoint joins Dave to discuss why understanding human behavior is a major key to security, Dave & Joe discuss some listener follow-up about a Craigslist posting, Joe's story is about a scam website that is promising refunds to consumers all over the world, Dave shares a story about scam calls coming from call centers in India, and our Catch of the Day is from a listener about an email from former first lady Melania Trump.Links to stories:
FTC warns of scam website that promises refund for victims of online scams
Scam “US Trading Commission” website is not the FTC
Who's Making All Those Scam Calls?
Have a Catch of the Day you'd like to share? Email it to us at hackinghumans@thecyberwire.com or hit us up on Twitter.

Feb 2, 2021 • 6min
endpoint (noun) [Word Notes}
A device connected to a network that accepts communications from other endpoints like laptops, mobile devices, IoT equipment, routers, switches, and any tool on the security stack.

Jan 28, 2021 • 41min
Covid has shifted the way we deal with money and increased fraud.
Guest Eric Solis of MOVO Cash talks with Dave about the increase of fraud attacks on consumers and businesses by not having a body of regulations for digital payments, Dave's story is about his recent pillow purchase prompting him to do online reviews for an extra bonus, Joe shares some details from Verizon's Cyber-Espionage report, and our Catch of the Day is a letter from a listener named Jim who had a bad eBay transaction.Links to stories:
Amazon is trying to crack down on fraudulent reviews. They’re thriving in Facebook groups.
Breach of Trust: How Cyber-Espionage Thrives On Human Nature
Have a Catch of the Day you'd like to share? Email it to us at hackinghumans@thecyberwire.com or hit us up on Twitter.

Jan 26, 2021 • 6min
unified extensible firmware interface (UEFI) (noun) [Word Notes]
An extension of the traditional Basic Input/Output System or BIOS that, during the boot process, facilitates the communication between the computer’s firmware and the computer’s operating system.