Computer Security US Blog

Computer Security News and Insights

Security Awareness Training

How to Measure Security Awareness Training ROI

The Program That Looked Great on Paper — Until the Breach A mid-size healthcare company I consulted with had a 98% training completion rate. Every employee had clicked through every module. Leadership was proud. Then a single phishing email — disguised as a benefits enrollment update — compromised credentials for three domain admin

Carl B. Johnson Sep 12, 2026 5 min read
phishing attack

Phishing Attack Trends in 2026: What's Actually Working

The Phishing Attack That Cost One Hospital $65 Million In February 2024, Change Healthcare — one of the largest health payment processors in the U.S. — was hit by a ransomware attack that started with a single compromised credential. No multi-factor authentication on a remote access portal. One phishing attack opened

Carl B. Johnson Sep 11, 2026 5 min read
Adware vs Spyware

Adware vs Spyware: Key Differences You Must Know

That "Harmless" Toolbar Was Anything But A few years back, I helped a small accounting firm figure out why their machines had slowed to a crawl every March — right when they needed them most. The culprit? A browser toolbar that one employee had installed, thinking it was a

Carl B. Johnson Sep 10, 2026 5 min read
Phishing Emails

How to Spot Phishing Emails Before They Cost You

In March 2024, a finance employee at a Hong Kong multinational wired $25 million to threat actors after a single phishing email led to a deepfake video call with what appeared to be the company's CFO. That's not a Hollywood plot — it's a police-confirmed

Carl B. Johnson Sep 10, 2026 5 min read
Cybersecurity for Nonprofits

Cybersecurity for Nonprofits: A Practical Defense Guide

The Breach That Nearly Killed a Children's Charity In 2023, Save the Children International confirmed a cyberattack by the BianLian ransomware group that reportedly compromised nearly 7 GB of sensitive data — including financial records, health data, and personal information. A global nonprofit with dedicated IT resources still got

Carl B. Johnson Sep 09, 2026 5 min read
Cyber Security Definition

Cyber Security Definition: What It Really Means in 2026

In 2023, MGM Resorts lost roughly $100 million after a social engineering phone call lasting just ten minutes gave a threat actor access to internal systems. The attackers didn't exploit some exotic zero-day vulnerability. They manipulated a help desk employee. If your cyber security definition starts and stops

Carl B. Johnson Sep 09, 2026 5 min read
Malware

What Is Malware? A Security Pro's Field Guide for 2026

A Single Employee Click Cost One Hospital $10 Million In 2024, Change Healthcare suffered one of the most devastating ransomware attacks in U.S. history. The breach disrupted pharmacy systems, delayed patient care nationwide, and cost UnitedHealth Group over $870 million in the first quarter alone. The root cause? Compromised

Carl B. Johnson Sep 09, 2026 5 min read
PayPal DocuSign Phishing

PayPal DocuSign Phishing: How This Combo Attack Works

Two Trusted Brands, One Devastating Scam In late 2024, security researchers at Avanan documented a surge in phishing campaigns that combined PayPal and DocuSign branding in a single attack chain. The attackers sent emails that appeared to come from DocuSign, notifying the recipient of a payment document waiting for their

Carl B. Johnson Sep 08, 2026 5 min read