Resources

Blog

Hacktivism - Top Phishing Attacks of 2016

In this series of blog posts we examine the most common forms of phishing attacks and appropriate countermeasures to protect both individuals and organizations – in this post we explore hacktivism and the growing range of victims.Politically Motivated & HacktivismThe threat of cyber criminals pursuing a political agenda and seeking to disrupt critical infrastructures has been well documented....
Blog

Demystifying Machine Learning: Evaluating Security Claims

In my blog post, Demystifying Machine Learning: Making Informed Security Decisions, I discussed a framework for evaluating Machine Learning claims. Now let’s see how to apply it.I’ve included below a blurb from the website or data sheet of a fictitious security company called Acme Security. While the company is fictitious, the content is derived from looking at similar material from various...
Blog

Agari Honored by Online Trust Alliance

At Agari, we think it's important to "walk the walk", not just "talk the talk" so to speak. To us that means implementing the privacy and security measures on our own website and email that our industry talks about every day. This is why we are proud to be recognized once again as a recipient of the Online Trust Alliance (OTA) Honor Roll award and to be designated as "Top of the Class".This is the...
Blog

Making Email Great Again…with Norwest Venture Partners

We’ve very excited to welcome Norwest Venture Partners to the Agari family! Norwest, the newest investor in Agari, led the Series D funding for $22M we announced earlier this week. Their interest in the Agari Email Trust Platform and its unique ability to stop targeted phishing attacked shouldn’t come as a surprise. They have a long history of investing in the cybersecurity space. Their portfolio...
Blog

10 Shocking Malware and Ransomware Statistics

“Malware Mania” is back with a vengeance creating havoc for organizations of all sizes and in all industries. Cyber criminals have morphed their attack methods with the resurgence of macro malware and encrypting ransomware to evade traditional antivirus and sandbox defenses. As a result, cybersecurity teams are scrambling for a more effective way to deal with these shocking realities:2,500 cases...
Blog

Security Professional Pain Points – and How to Solve Them

Ask any security professional what the number one pain point is within their organization, and chances are they’ll say ‘user behavior’…with ‘malware’ coming in as a very close second. And while these issues are very different on the surface, they do have one thing in common: both are often the cause of high-profile data breaches, largely in part to the increased use of spear phishing email...
Blog

Agari Proud to Join FS-ISAC Again This Year!

We’re looking forward to another great FS-ISAC summit next week in Miami. Twice a year, the Financial Services Information Sharing and Analysis Center (FS-ISAC) holds information sharing events, where industry leaders come together to network and share the latest in combating cyber threats and new technology innovation. During the summit next week, Agari will host various on-site activities,...
Blog

What Does Federal Phishing Look Like?

In a recent blog, where we covered why government bodies are prime targets for phishing, we asked whether you’d be able to recognize a spoofed email from a federal agency. The truth is, a spoofed federal email looks very similar to a legitimate email you would expect to receive from government bodies. With the majority of people receiving regular emails from federal agencies, these emails are...
Blog

Lessons Learned Hiring Software Engineers During a Bubble – Part 3

Now that you've (hopefully!) read my first two blog posts on hiring lessons learned, Step 0: Who Are You? and Step 1: The Prep, you're ready to check out my third - and final - post on the topic:Step 2: The HowFinding the CandidatesIf you ask sales managers what qualities they look for in top performers, they will likely include: tirelessly hunting for prospects and keeping their calendars filled...
Blog

Lessons Learned Hiring Software Engineers During a Bubble - Part 2

As per my previous blog post, hiring software engineers gets more competitive every year. Now that you’ve read the first step in our process, Step 0: Who Are You, here’s the next step: Step 1: The Prep The Pitch Hiring is a lot like sales, and just like a good salesperson, you need a well-honed pitch. For recruiting purposes, you’ll want to break this into two parts: first, the company pitch...
Blog

Lessons learned hiring software engineers during a bubble

Hiring software engineers gets more competitive every year. There is now a service - hired.com - that provides an efficient, but disturbingly Tinder-like, interface for evaluating potential candidates. Traditional businesses like banks, healthcare providers and automotive shops are hiring software engineers too. This is creating so much demand that talent is being pulled from other fields. We see...
Blog

Enhance Data Protection By Restoring Trust in the Inbox

When it comes to cyber-resilience, a one size approach does not fit all. The threat level is rising as attacks become more frequent and complex. Cyber criminals use multiple attack vectors to gain the intelligence and access necessary to penetrate a company’s defenses. In particular, sophisticated, targeted email attacks that are aimed at specific employees are one of the most commonly used...
Blog

Phishing Federal Agencies: Why Government Bodies are Prime Targets

With cyber warfare increasingly dominating headlines, the digital security measures of governments have come under growing scrutiny. The US government is one that constantly makes the news for being a prime target for cybercriminals and other nation-states. Recently, it was reported that a hacker accessed an employee’s email account at the Department of Justice and stole 200GB of files including...
Blog

Gmail User? Your Email is About to Get Safer

Your email is about to get safer if you are a Gmail user! This week in the Gmail Blog, Product Manager John Rae-Grant talked about a couple of changes to Gmail on the web that will allow users to see if an email might not be as secure as it should be. First, Gmail will display a broken lock symbol in the upper right of the email window if it is not encrypted in transit with TLS. And second, Gmail...
Blog

What Happens When Your CEO’s Email is Compromised?

What would you do if you received a confidential email from your CEO asking you to wire money to an attorney as part of an acquisition? This is what happened to Texas manufacturing firm, Ameriforge Group Inc., whose director of accounting wired $480,000 to the Agricultural Bank of China, before realizing that it was an email scam. Unfortunately, these kinds of highly targeted phishing scams, known...
Blog

8 Reasons Why DLP is Now Practical for SMB, Education and Local Government Organizations

While SMBs and public sector organizations were not the primary target for cyber-attacks and data breaches when DLP solutions were first brought to market, newer automated threats via malware and data theft monetization strategies (i.e. identify theft, ransomware, etc.) have made it more efficient and profitable to focus on smaller organizations that were apparently in the clear. As a result, the likes of SMBs, educational institutions and local county and city government organizations are faced to deal with an ever increasing set of information-borne threats and compliance regulations without a practical DLP option. Until now...
Blog

USBs: The Inconspicuous Enemy

At around three centimetres in length and weighing less than 30 grams on average, the USB flash drive would appear to be a relatively innocuous storage device, but losing or inserting an unknown USB into a personal or company computer could have devastating consequences. With over 22,000 USB sticks being left in the pockets of clothing sent to Britain’s dry cleaners, alone last year, we thought it valuable to outline the dangers of the simple USB and how individuals and organizations alike can protect against the potential cyber weaknesses they can bring about.
Blog

DANE vs DMARC: The Email Authentication Landscape

Lately, the question of DANE vs DMARC has been coming up quite a bit. While both DANE and DMARC involve “authentication”, there are significantly different things meant by each. Let’s start by addressing the underlying technologies. DANE, or RFC6698, is intended to mitigate the threat of a man-in-the-middle intercepting encrypted communications by posing as one of the end points. A common vector...
Blog

Don’t Let Your Customers Be Fooled By Cousin Domains

In the last five years, we’ve all become far too familiar with it – hackers spoofing a company’s domain and therefore tarnishing the brand, bad actors attempting to infect our computers with malware, and criminals sending millions of spam messages. As if this isn’t enough, now there is a whole group of people working to outsmart companies AND their customers by using cousin domains to fool...
Blog

New Email-Embedded Malware Getting Through Major AV Scans

Clearswift has recently been approached by a number of top cybersecurity teams and organizations to help them address an increasing threat of ongoing attempts to deliver embedded malware hidden in email attachments that is automatically activated by malicious scripting code. The sophistication and continuous morphing of delivery methods have made it so these new malware variants go undetected and pass right by major AV scanning solutions.